> Markdown version of [/jobs/ext/1457574-cyber-security-engineer-pki-ut](https://www.wearedevelopers.com/jobs/ext/1457574-cyber-security-engineer-pki-ut). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Engineer - PKI - UT - **Company:** Grant Leading Technology, LLC - **Location:** Riverdale Park, MD, United States - **Experience:** Expert - **Salary:** $120,000.0 - $150,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Public-Key Cryptography, Microsoft Azure, Cloud Computing, Cyber Security, Middleware, Firmware, Monitoring of Systems, Hardware Security Module, Identity and Access Management, Interoperability, Key Management, Windows Servers, NIPRNet, Public Key Infrastructure, Windows PowerShell, Zero Trust Network Access, Service Pack, Web Applications, Enterprise Software Applications, Cloud Platform System, HybridCloud, Information Technology, Enterprise Integration, Network Server, Wsus, Key Vault - **Published:** July 27, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=8585e7b9b86de224 ## About the Role * Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Engineering, or a related field * Minimum seven (7) years supporting enterprise PKI or cybersecurity engineering * Must possess a Secret Security Clearance including High Risk, Critical Sensitive, Tier 5 (SSBI) investigation * Must possess a current DOD Approved 8570/8140 Baseline Certification (CASP+, CISSP, CCNP Security (as applicable under DOD guidance), GCED, GCIH, or Other DOD-approved IAT Level III certifications * Must possess one of the following current certifications: * Microsoft Certified Solutions Expert (MCSE): Cloud Platform and Infrastructure * Microsoft Certified: Windows Server Hybrid Administrator Associate * Microsoft Certified: Azure Solutions Architect Expert (or equivalent Microsoft Azure certification meeting contract requirements) * Must live in a commutable distance of Richmond, Virginia or Ogden, Utah and be authorized to work in the United States Preferred Skills: * Experience supporting DLA environments * Experience supporting Federal Bridge Certification Authority (FBCA) integration * Experience supporting SIPRNet and NIPRNet PKI implementations * Experience administering Hardware Security Modules (Entrust, Thales, Luna, or equivalent) * Experience with PowerShell automation and scripting * Familiarity with Zero Trust Architecture and modern identity management solutions ## Description Grant Leading Technology is seeking a candidate for an Intermediate Cyber Security Engineer Public Key Infrastructure (PKI) to join our dynamic team. The candidate will provide advanced engineering, administration, and operational support for a large-scale Department of Defense (DOD) PKI environment supporting the Defense Logistics Agency (DLA). This position is responsible for engineering secure PKI solutions, maintaining trusted operating system baselines, implementing cryptographic technologies, and supporting enterprise certificate lifecycle management across on-premises and cloud environments. The engineer will support the design, implementation, testing, deployment, and maintenance of PKI infrastructure while ensuring compliance with DOD cybersecurity requirements. The position requires collaboration with cybersecurity, infrastructure, cloud, and application teams to ensure secure identity management and certificate services across enterprise systems. This position is located at DLA facilities in Ogden, Utah and requires on-site support for classified DOD PKI environments. Candidates must possess an active Secret Security Clearance and a High Risk, Critical Sensitive Tier 5 (SSBI) investigation prior to start. This position will be onsite, and the hours are 8 am to 5 pm EST., * Engineer, implement, administer, and maintain enterprise PKI environments supporting DLA mission systems * Design, configure, and maintain Certificate Authorities (CAs), Registration Authorities (RAs), Online Certificate Status Protocol (OCSP), Certificate Revocation Lists (CRLs), and related PKI components * Support enterprise deployment, migration, and lifecycle management of PKI applications and services * Configure, test, deploy, and troubleshoot Hardware Security Modules (HSMs) supporting certificate authorities and cryptographic operations * Support Enterprise Key Management activities utilizing two-person integrity controls * Support Key Ceremonies utilizing multi-person integrity procedures in accordance with Trusted Operating System requirements * Develop and maintain Server-Based Certificate Validation Protocol (SCVP) policies and certificate validation services * Install, configure, secure, and maintain Windows Server 2019 through current supported versions supporting PKI services * Develop, test, deploy, and maintain FDCC Windows 11 and FSCC Windows Server baselines * Perform operating system installations, upgrades, migrations, and system hardening * Test and deploy operating system patches, service packs, and application updates * Maintain enterprise test environments supporting PKI engineering and validation activities * Monitor system performance, conduct tuning activities, and implement engineering best practices * Configure, deploy, and manage enterprise certificates supporting users, applications, servers, and non-person entities (NPE) * Support Device Certificates for NIPRNet and SIPRNet Non-Key Terrain systems * Maintain Windows Trust Stores and Untrusted Certificate Stores * Support Public Key Enablement (PKE) for enterprise web applications and services * Support Federal Bridge interoperability and integration of PKI services into enterprise applications * Configure, administer, and maintain cloud-based Key Management Systems including: o Microsoft Azure Key Vault o AWS Key Management Service (KMS) o Future approved cloud cryptographic services * Integrate cloud-based certificate management with enterprise PKI services * Support secure hybrid cloud identity and certificate architecture * Review and analyze hardware, software, firmware, and operating system changes for security impacts * Evaluate security alerts, vulnerabilities, and vendor advisories affecting PKI infrastructure * Apply CERT-directed patches using Windows Server Update Services (WSUS) * Ensure compliance with: o DISA STIGs o DOD Cybersecurity requirements o FDCC o FSCC o Trusted Operating System standards * Participate in PKI compliance assessments and security audits * Research, evaluate, test, and recommend emerging PKI technologies * Conduct proof-of-concept testing for new cryptographic products and capabilities * Develop engineering documentation, implementation guides, standard operating procedures, and technical recommendations * Provide Tier III engineering support for enterprise PKI infrastructure * Troubleshoot complex PKI, certificate, middleware, and cryptographic issues * Support production, development, and test PKI environments * Collaborate with cybersecurity, cloud, infrastructure, and application teams to ensure secure integration of PKI services ## Related Videos - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [When Agents Meet Legacy: Never Change a Running System](https://www.wearedevelopers.com/videos/100320-when-agents-meet-legacy-never-change-a-running-system) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)