The Senior PKI Engineer is responsible for designing, implementing, securing, and maintaining enterprise Public Key Infrastructure (PKI) services that support mission-critical authentication, encryption, digital signature, and certificate lifecycle operations. This role requires a general understanding of PIV implementation in the government space.
Key Responsibilities
Administer enterprise PKI systems, including Certificate Authorities (CAs), Online Certificate Status Protocol (OCSP) responders, Hardware Security Modules (HSMs), and certificate lifecycle service products.
Deep understanding and application of PKCS standards.
Implement PKI in hybrid or cloud-based environments such as Azure, AWS, and Google Cloud Platform (GCP).
Manage and configure Microsoft Active Directory Certificate Services (ADCS).
Automation & Integration
Support the automation of certificate issuance, renewal, monitoring, and compliance reporting processes.
Operations & Troubleshooting
Provide Tier III support for PKI, certificate-based authentication, TLS/SSL, smart cards, and identity management systems.
Troubleshoot issues such as certificate chain validation, revocation, OCSP/CRL failures, and integration challenges.
Ensure high availability, redundancy, and disaster recovery readiness for PKI services.
Modernization & Emerging Technologies
Support for post-quantum cryptography (PQC) transitions and compliance with emerging NIST standards.
Integrate cost-efficient open-source cryptographic libraries and JRE/JDK solutions.
Support zero-trust architecture strategies and cloud migration efforts.
Explore and evaluate new technologies to enhance scalability, automation, and security.
Required Qualifications
Education: Bachelors degree in Computer Science, Cybersecurity, Engineering, or equivalent experience.
Experience:
7+ years of hands-on experience in PKI engineering, certificate services, and cryptographic system management.
Deep expertise with:
Microsoft Active Directory Certificate Services (ADCS)
Various HSMs (Thales, SafeNet, AWS CloudHSM, etc.)