Lead, Pki Technical Engineer

Schneider Electric
Barcelona, Spain
13 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
3 years minimum
Working hours
Shift work
Languages
English

Tech stack

Microsoft Access Active Directory Amazon Web Services Automation of Tests Microsoft Azure Bash Shell CompTIA Security+ Cyber Security Linux Hardware Security Module Identity and Access Management Python (Programming Language)
+14 more
Key Management OpenSSL Public Key Infrastructure X.509 Windows PowerShell Azure Active Directory RSA (Cryptosystem) Scripting Cloud Platform System Cyberark Firewalls (Computer Science) Information Technology Performance Monitor Network Server

Job description

Tech Engineer - Public Key Infrastructure (PKI) and Hardware Security Modules (HSM)Se anima a todos los posibles solicitantes a que se desplacen y lean la descripción completa del puesto antes de presentar su candidatura.We are seeking a Tech Engineer experienced in PKI and HSM to manage the enterprise PKI environment, ensuring secure certificate lifecycle management and robust key protection.This role will operate within a team of identity and access management engineers, maintain platform health, support break/fix, upgrades, patches, and coordinate with architecture on proofs of concept.Key ResponsibilitiesAdminister and maintain enterprise PKI components, focusing on Keyfactor EJBCA, Keyfactor Command, or similar platforms.Design, configure, and manage certificate profiles, CA hierarchies, enrollment processes, and certificate lifecycle workflows.Ensure secure key generation, storage, and management leveraging HSMs.Conduct proactive monitoring, health checks, maintenance, upgrades and patching of PKI systems.Troubleshoot certificate?related issues across servers, applications, and infrastructure components.Perform cryptographic operations and validation using tools like OpenSSL.Ensure PKI compliance with internal policies, security standards, and audit requirements.Develop and maintain automation scripts (Bash, Python, PowerShell) for operational efficiency.Provide L3 engineering support for PKI and related cryptographic services.Produce periodic operational reports and assist in remediation of audit and compliance findings.Document technical procedures, architecture, and operational runbooks.QualificationsBachelor’s degree in computer science, engineering, or equivalent experience.At least 3 years of experience in PKI engineering and certificate services, AWS Cloud, and Microsoft Identity and Access services such as AD/AAD.Deep understanding of X.509, RSA, certificate chains, key usage, CRL/OCSP.Strong experience with Linux and/or Windows administration and troubleshooting.Proficient in scripting with PowerShell, Bash, or Python.Practical experience implementing and troubleshooting HSMs.Experience with cryptographic tools such as OpenSSL.Ability to work directly with teams and vendors to resolve complex PKI or platform issues.Experience working in enterprise environments with strong security and compliance requirements.Fluent in English and strong communication and documentation skills.Preferred QualificationsExperience with Keyfactor EJBCA and Keyfactor Command.Knowledge of AWS, Microsoft Active Directory and Azure certificate integration mechanisms.Experience with CyberArk for secure credential or key management.Relevant certifications such as Microsoft Identity, Azure, AWS, CyberArk, CISSP, Security+.Basic knowledge of networking and firewalls.Experience with cloud environments (Azure and AWS).Personal AttributesStrong analytical and problem?solving capabilities.High attention to detail and a security?first mindset.Ability to prioritize tasks and collaborate effectively in cross?functional teams.Proactive, motivated, and committed to continuous improvement of PKI and security operations.Passionate, energetic, and positive attitude.BenefitsFlexible schedule to adjust work hours to accommodate personal needs.Option to work from home with a hybrid work plan.Additional vacation days through a custom holiday purchase program.Floating holidays that can be exchanged for other days.Up to two months of unpaid sabbatical leave.Global family leave policy with flexible paid conditions for family life events.Access to health and wellness platform offering wellbeing content, nutrition counseling, fitness classes, and more.Access to a network of gyms and sports centres through Wellhub.On?site medical services.Professional development platform to connect with opportunities and mentors.Stock ownership program for employee shareholders.Recognition program for celebrating talent and success.Life insurance.Flexible remuneration plan with options such as health insurance, meal vouchers, childcare vouchers, transportation vouchers, and training.Discounts at partner stores, restaurants, travel agencies, and other services.Company?subsidised volunteer program.Schneider Electric is an Equal Opportunity Employer.xcskxlj We provide equal employment and advancement opportunities for all qualified individuals regardless of race, religion, color, gender, disability, national origin, age, military status, sexual orientation, marital status, or any other legally protected characteristic.#J-*****-Ljbffr

Requirements

Bachelor’s degree in computer science, engineering, or equivalent experience. At least 3 years of experience in PKI engineering and certificate services, AWS Cloud, and Microsoft Identity and Access services such as AD/AAD. Deep understanding of X.509, RSA, certificate chains, key usage, CRL/OCSP. Strong experience with Linux and/or Windows administration and troubleshooting. Proficient in scripting with PowerShell, Bash, or Python. Practical experience implementing and troubleshooting HSMs. Experience with cryptographic tools such as OpenSSL. Ability to work directly with teams and vendors to resolve complex PKI or platform issues. Experience working in enterprise environments with strong security and compliance requirements. Fluent in English and strong communication and documentation skills. Preferred Qualifications Experience with Keyfactor EJBCA and Keyfactor Command. Knowledge of AWS, Microsoft Active Directory and Azure certificate integration mechanisms. Experience with CyberArk for secure credential or key management. Relevant certifications such as Microsoft Identity, Azure, AWS, CyberArk, CISSP, Security+. Basic knowledge of networking and firewalls. Experience with cloud environments (Azure and AWS). Personal Attributes Strong analytical and problem?solving capabilities. High attention to detail and a security?first mindset. Ability to prioritize tasks and collaborate effectively in cross?functional teams. Proactive, motivated, and committed to continuous improvement of PKI and security operations. Passionate, energetic, and positive attitude.

Benefits & conditions

Flexible schedule to adjust work hours to accommodate personal needs. Option to work from home with a hybrid work plan. Additional vacation days through a custom holiday purchase program. Floating holidays that can be exchanged for other days. Up to two months of unpaid sabbatical leave. Global family leave policy with flexible paid conditions for family life events. Access to health and wellness platform offering wellbeing content, nutrition counseling, fitness classes, and more. Access to a network of gyms and sports centres through Wellhub. On?site medical services. Professional development platform to connect with opportunities and mentors. Stock ownership program for employee shareholders. Recognition program for celebrating talent and success. Life insurance. Flexible remuneration plan with options such as health insurance, meal vouchers, childcare vouchers, transportation vouchers, and training. Discounts at partner stores, restaurants, travel agencies, and other services. Company?subsidised volunteer program. Schneider Electric is an Equal Opportunity Employer. xcskxlj We provide equal employment and advancement opportunities for all qualified individuals regardless of race, religion, color, gender, disability, national origin, age, military status, sexual orientation, marital status, or any other legally protected characteristic. #J-*****-Ljbffr

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

31 sec

Predictive brain models and simulated cryptographic implementation flaws

Chris Heilmann +2 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

2:23 min

Cross-compiling end-to-end encrypted client libraries with WebCrypto

Paweł Aniszewski Paweł Aniszewski · Europe 2026 Virtual

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all