> Markdown version of [/jobs/ext/1182614-pki-engineer-active-ts-sci-with-ci-poly](https://www.wearedevelopers.com/jobs/ext/1182614-pki-engineer-active-ts-sci-with-ci-poly). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # PKI Engineer - Active TS/SCI With CI Poly - **Company:** ENS Solutions, LLC - **Location:** College Park, MD, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Public-Key Cryptography, User Authentication, Backup Devices, Bash Shell, DevOps, Disaster Recovery, Hardware Security Module, Identity and Access Management, Lightweight Directory Access Protocols (LDAP), Linux System Administration, Linux Security Modules, Public Key Infrastructure, Ansible, Zero Trust Network Access, Systems Integration, SSL Certificate Management, Transport Layer Security, Infrastructure Automation Frameworks - **Published:** July 4, 2026 - **Apply:** https://www.juju.com/job/00000000gdcg1t ## About the Role We are seeking an experienced PKI Engineer/IAM Engineer to support enterprise Identity and Access Management (IAM), PKI, and Zero Trust initiatives. In this role, you will design, implement, automate, and maintain secure identity and cryptographic infrastructure solutions for large-scale enterprise environments. You will work closely with stakeholders, security teams, and infrastructure engineers to support authentication, authorization, certificate management, and credential lifecycle processes. The ideal candidate will have strong Linux administration skills, deep understanding of certificate lifecycle management, and experience building secure PKI solutions in enterprise environments., + 5+ years of experience in PKI engineering, infrastructure security, or systems administration + 8570/8140 Certification + Strong Linux system administration experience + Hands-on experience with: + Public Key Infrastructure (PKI) + Certificate Authority design, setup, and operations + LDAP administration and integrations + Ansible automation + Bash scripting + Experience with certificate lifecycle management and automation + Knowledge of certificate policies, certificate profiles, and certificate contents/extensions + Strong understanding of: + Asymmetric cryptography concepts + TLS/SSL certificates and trust models + Linux security principles and system hardening + Experience troubleshooting certificate and authentication-related issues in enterprise environments + Strong written and verbal communication skills Preferred Qualifications + Experience working with Hardware Security Modules (HSMs) + Familiarity with ACME protocol and automated certificate enrollment solutions + Knowledge of compliance frameworks and security standards related to cryptography and certificate management + Experience with DevOps or Infrastructure-as-Code practices + Experience with Amazon Web Services (AWS) + Familiarity with enterprise identity and access management solutions ## Description + Design, implement, configure, and maintain enterprise PKI environments + Administer and support Linux-based systems hosting PKI services and related infrastructure + Manage certificate lifecycle operations including issuance, renewal, revocation, validation, and expiration monitoring + Develop and maintain automation for certificate deployment and lifecycle management using Ansible and Bash scripting + Configure and manage LDAP integrations and directory services related to PKI environments + Define and maintain policies, standards, and operational procedures + Troubleshoot PKI-related issues involving certificates, trust chains, TLS/SSL configurations, and cryptographic services + Collaborate with security and infrastructure teams to ensure compliance with enterprise security standards and best practices + Implement monitoring, auditing, backup, and disaster recovery procedures for PKI systems + Support asymmetric cryptography implementations and secure communications across enterprise platforms + Create and maintain technical documentation, architecture diagrams, and operational playbooks ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Old tools, new tricks](https://www.wearedevelopers.com/videos/1916-old-tools-new-tricks) - [Dev & Test in the Cloud? Deploy your cloud environments with Ansible & Terraform](https://www.wearedevelopers.com/videos/1607-dev-test-in-the-cloud-deploy-your-cloud-environments-with-ansible-terraform) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [#90DaysOfDevOps - The DevOps Learning Journey](https://www.wearedevelopers.com/videos/548-90daysofdevops-the-devops-learning-journey) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)