Senior PKI Engineer
HCC, Inc..
United States
20 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$145,600.0 - $176,800.0
Working hours
Regular working hours
Job source
Tech stack
Active Directory
Amazon Web Services
User Authentication
Automation of Tests
Cloud Computing
CompTIA Security+
Cyber Security
Information Systems
Digital Signature
Disaster Recovery
Domain Name System (DNS)
Federal Information Processing Standards (FIPS)
+17 more
Hardware Security Module
Identity and Access Management
Python (Programming Language)
Key Management
Lightweight Directory Access Protocols (LDAP)
Microsoft Software
Windows Servers
Multi-Purpose Internet Mail Extensions (MIME)
Public Key Infrastructure
X.509
Windows PowerShell
Azure Active Directory
Zero Trust Network Access
Scripting
Transport Layer Security
Enterprise Software Applications
Information Technology
Job description
HCC Consulting is seeking a Senior PKI Engineer to support the modernization, administration, and optimization of enterprise Public Key Infrastructure (PKI) services for a federal customer. The successful candidate will be responsible for maintaining secure certificate services, improving PKI resiliency, implementing modern cryptographic solutions, and supporting enterprise identity and authentication services.
Responsibilities
- Design, implement, and administer enterprise PKI environments.
- Manage Root and Issuing Certificate Authorities (CAs), Online Certificate Status Protocol (OCSP) Responders, Certificate Revocation Lists (CRLs), and Registration Authorities.
- Administer certificate lifecycle management, including certificate issuance, renewal, revocation, recovery, and expiration monitoring.
- Configure and maintain Hardware Security Modules (HSMs) and cryptographic key management solutions.
- Support TLS/SSL certificates, code-signing certificates, S/MIME, client authentication, server authentication, and digital signature services.
- Integrate PKI services with Active Directory, Microsoft Entra ID, cloud platforms, enterprise applications, and identity management solutions.
- Monitor PKI health, troubleshoot certificate trust issues, and resolve authentication and encryption problems.
- Implement certificate lifecycle automation using PowerShell, Python, or other scripting tools.
- Support disaster recovery, backup, restoration, and high-availability configurations for PKI infrastructure.
- Develop and maintain PKI architecture documentation, standard operating procedures, and technical implementation guides.
- Ensure compliance with applicable federal cybersecurity standards, including NIST and FIPS requirements.
- Collaborate with cybersecurity, infrastructure, network, and application teams to support secure enterprise operations.
Requirements
- Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, Engineering, or equivalent experience.
- Minimum of 8 years of IT infrastructure or cybersecurity experience.
- Minimum of 5 years of enterprise PKI engineering experience.
- Experience administering Microsoft Active Directory Certificate Services (AD CS) or comparable enterprise PKI platforms.
- Strong understanding of X.509 certificates, Certificate Authorities, OCSP, CRLs, TLS/SSL, digital certificates, and cryptographic key management.
- Experience with Hardware Security Modules (HSMs).
- Experience with Windows Server, Active Directory, DNS, LDAP, and enterprise authentication.
- Experience developing PowerShell or Python automation scripts.
- Strong troubleshooting and analytical skills.
- Excellent written and verbal communication skills.
- U.S. Citizenship., * Experience supporting federal civilian or DoD agencies.
- Experience with Federal PKI (FPKI), PIV/CAC authentication, and enterprise identity management.
- Experience with AWS Certificate Manager, AWS Private CA, Azure Key Vault, AWS CloudHSM, or similar technologies.
- Familiarity with Zero Trust Architecture and Identity, Credential, and Access Management (ICAM).
- Relevant certifications such as CISSP, Security+, CCSP, Microsoft, AWS, or PKI-related certifications.
Benefits & conditions
$70 - $85 an hour - Full-time, Contract
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
LM
Luis Minvielle
about 2 years ago
KD
Krissy Davis
Best Paying Jobs in Technology
about 3 years ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
6 months ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
almost 2 years ago
LM
Luis Minvielle
Why Upskilling And Reskilling is Important For Developers
over 2 years ago
LM
Luis Minvielle
Fully Remote Software Engineer Jobs
about 2 years ago