Senior Public Key Infrastructure (PKI) Engineer

ZTI Solutions LLC
Fairfax, VA, United States
26 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Compensation
$150,000.0 - $190,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Active Directory Application Programming Interfaces (APIs) Amazon Web Services Microsoft Azure Bash Shell Cloud Computing Cyber Security Linux Federal Information Processing Standards (FIPS) Hardware Security Module Python (Programming Language)
+19 more
Key Management Windows Servers Public Key Infrastructure X.509 Windows PowerShell Ansible Zero Trust Network Access Virtualization Technology Web Services SSL Certificate Management Transport Layer Security Load Balancing Istio HybridCloud SC Clearance Kubernetes Restful APIs Terraform Devsecops

Job description

ZTI Solutions is seeking a Senior Public Key Infrastructure (PKI) Engineer to architect, automate, and modernize enterprise PKI supporting Department of Defense and Federal customers. This position focuses on enterprise server PKI, certificate lifecycle automation, and infrastructure trust services, not end-user certificate administration. You will modernize CA infrastructure, automate certificate management at scale, support post-quantum cryptography transition planning, and help shape Zero Trust initiatives in mission-critical DoD environments. ZTI will sponsor Top Secret clearance processing. Benefits include 100% company-paid medical, dental, and vision for you and your family, 4 weeks PTO, and certification reimbursement., * Architect, deploy, administer, and maintain enterprise PKI environments and Certificate Authority (CA) infrastructure, including Microsoft Active Directory Certificate Services (AD CS).

  • Design and manage enterprise server certificate strategies across Windows, Linux, virtualization, cloud, web services, APIs, and load balancers.
  • Automate certificate lifecycle management (issuance, renewal, revocation, expiration monitoring, key rotation, reporting) using ACME, SCEP/EST, REST APIs, PowerShell, Python, Bash, Ansible, or Terraform.
  • Deploy, manage, and troubleshoot TLS/SSL certificates, trust chains, and certificate validation across the enterprise.
  • Integrate PKI services with Active Directory, Azure, AWS, virtualization platforms, and DevSecOps pipelines.
  • Support Zero Trust initiatives through machine identity and certificate-based trust.
  • Support planning for post-quantum cryptography and CNSA 2.0 migration.
  • Ensure PKI environments comply with NIST, FIPS, DISA STIGs, and RMF requirements.
  • Participate in incident response for certificate compromise or trust-related events.
  • Maintain technical documentation, architecture diagrams, SOPs, and configuration baselines.
  • Provide technical leadership and mentorship to junior engineers.

Requirements

  • U.S. Citizen with an active Secret clearance; eligible for Top Secret (ZTI sponsors processing).
  • Hybrid: up to 3 days/week onsite in Fairfax, VA.
  • DoD 8140 IAT Level II certification (Security+ CE or higher), or ability to obtain within 90 days.
  • 8+ years of systems/security engineering experience with 4+ years focused on enterprise PKI (or 12 years total without a degree).
  • Experience administering AD CS or comparable enterprise PKI platforms.
  • Experience automating certificate lifecycle management at scale.
  • Experience administering Windows Server and/or Linux.
  • Strong understanding of X.509, CRL/OCSP, enterprise trust models, cryptographic algorithms, and key management.
  • Excellent analytical, problem-solving, and communication skills., * CISSP, Azure Security Engineer Associate, or AWS Certified Security - Specialty.
  • Experience with Entrust, DigiCert, EJBCA, Keyfactor, Venafi, or similar platforms.
  • Hardware Security Module (HSM) experience.
  • Azure Government, AWS GovCloud, or hybrid cloud environments.
  • PKI integration with Kubernetes, containers, or service mesh.
  • Experience supporting DoD RMF, FedRAMP, or CMMC compliance initiatives.

Benefits & conditions

Pulled from the full job description

  • 401(k) 4% Match
  • Health insurance
  • 401(k) matching
  • Paid time off
  • Vision insurance
  • Dental insurance
  • Paid holidays, * 4 weeks PTO plus all federal holidays paid.
  • 100% company-paid medical, dental, and vision for employees and their families.
  • 4% matching 401(k).
  • Professional training and certification reimbursement.
  • Flexible hybrid work environment.

About the company

ZTI Solutions, LLC was founded in 1997 in Virginia and is classified as a small business. The company is owned and operated by its founder, Rudy Zadnik, who emphasizes moral and business excellence over increasing company profits. This results in a more customer-oriented attitude towards mission accomplishment, as opposed to growing profits or sales.Our approach to consulting and engineering centers around using only highly skilled personnel who are seasoned industry veterans. All employees hold high-level industry and vendor certifications. We offer a comprehensive set of consulting and staff augmentation services, primarily focused on networking and security consulting in the classified space.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

2:53 min

Configuring dynamic proxy updates with Istio Pilot

Jan Mensch Jan Mensch · WWC Europe 2026

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

7:15 min

Installing Istio programmatically with bash scripts

Thomas Südbröcker · LIVE

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

Videos

See all

Related articles

See all