Senior PKI Engineer

HCC, Inc..
United States
20 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$145,600.0 - $176,800.0
Working hours
Regular working hours
Job source

Tech stack

Active Directory Amazon Web Services User Authentication Automation of Tests Cloud Computing CompTIA Security+ Cyber Security Information Systems Digital Signature Disaster Recovery Domain Name System (DNS) Federal Information Processing Standards (FIPS)
+17 more
Hardware Security Module Identity and Access Management Python (Programming Language) Key Management Lightweight Directory Access Protocols (LDAP) Microsoft Software Windows Servers Multi-Purpose Internet Mail Extensions (MIME) Public Key Infrastructure X.509 Windows PowerShell Azure Active Directory Zero Trust Network Access Scripting Transport Layer Security Enterprise Software Applications Information Technology

Job description

HCC Consulting is seeking a Senior PKI Engineer to support the modernization, administration, and optimization of enterprise Public Key Infrastructure (PKI) services for a federal customer. The successful candidate will be responsible for maintaining secure certificate services, improving PKI resiliency, implementing modern cryptographic solutions, and supporting enterprise identity and authentication services.

Responsibilities

  • Design, implement, and administer enterprise PKI environments.
  • Manage Root and Issuing Certificate Authorities (CAs), Online Certificate Status Protocol (OCSP) Responders, Certificate Revocation Lists (CRLs), and Registration Authorities.
  • Administer certificate lifecycle management, including certificate issuance, renewal, revocation, recovery, and expiration monitoring.
  • Configure and maintain Hardware Security Modules (HSMs) and cryptographic key management solutions.
  • Support TLS/SSL certificates, code-signing certificates, S/MIME, client authentication, server authentication, and digital signature services.
  • Integrate PKI services with Active Directory, Microsoft Entra ID, cloud platforms, enterprise applications, and identity management solutions.
  • Monitor PKI health, troubleshoot certificate trust issues, and resolve authentication and encryption problems.
  • Implement certificate lifecycle automation using PowerShell, Python, or other scripting tools.
  • Support disaster recovery, backup, restoration, and high-availability configurations for PKI infrastructure.
  • Develop and maintain PKI architecture documentation, standard operating procedures, and technical implementation guides.
  • Ensure compliance with applicable federal cybersecurity standards, including NIST and FIPS requirements.
  • Collaborate with cybersecurity, infrastructure, network, and application teams to support secure enterprise operations.

Requirements

  • Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, Engineering, or equivalent experience.
  • Minimum of 8 years of IT infrastructure or cybersecurity experience.
  • Minimum of 5 years of enterprise PKI engineering experience.
  • Experience administering Microsoft Active Directory Certificate Services (AD CS) or comparable enterprise PKI platforms.
  • Strong understanding of X.509 certificates, Certificate Authorities, OCSP, CRLs, TLS/SSL, digital certificates, and cryptographic key management.
  • Experience with Hardware Security Modules (HSMs).
  • Experience with Windows Server, Active Directory, DNS, LDAP, and enterprise authentication.
  • Experience developing PowerShell or Python automation scripts.
  • Strong troubleshooting and analytical skills.
  • Excellent written and verbal communication skills.
  • U.S. Citizenship., * Experience supporting federal civilian or DoD agencies.
  • Experience with Federal PKI (FPKI), PIV/CAC authentication, and enterprise identity management.
  • Experience with AWS Certificate Manager, AWS Private CA, Azure Key Vault, AWS CloudHSM, or similar technologies.
  • Familiarity with Zero Trust Architecture and Identity, Credential, and Access Management (ICAM).
  • Relevant certifications such as CISSP, Security+, CCSP, Microsoft, AWS, or PKI-related certifications.

Benefits & conditions

$70 - $85 an hour - Full-time, Contract

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:41 min

Protecting etcd databases using Key Management System plugins

Alex Soto Alex Soto · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

1:24 min

Evaluating formal AWS certifications versus raw practical engineering experience

Jan Giacomelli · LIVE

3:03 min

Balancing robust code verification with user liability paradigms

John Woods John Woods · LIVE

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

Videos

See all

Related articles

See all