> Markdown version of [/jobs/ext/1608071-lead-pki-technical-engineer](https://www.wearedevelopers.com/jobs/ext/1608071-lead-pki-technical-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead, Pki Technical Engineer - **Company:** Schneider Electric - **Location:** Barcelona, Spain (Remote available) - **Contract:** Permanent contract - **Skills:** Microsoft Access, Active Directory, Amazon Web Services, Automation of Tests, Microsoft Azure, Bash Shell, CompTIA Security+, Cyber Security, Linux, Hardware Security Module, Identity and Access Management, Python (Programming Language), Key Management, OpenSSL, Public Key Infrastructure, X.509, Windows PowerShell, Azure Active Directory, RSA (Cryptosystem), Scripting, Cloud Platform System, Cyberark, Firewalls (Computer Science), Information Technology, Performance Monitor, Network Server - **Published:** July 31, 2026 - **Apply:** https://www.buscojobs.com.es/lead-pki-technical-engineer-en-barcelona-ID-364186766 ## About the Role Bachelor's degree in computer science, engineering, or equivalent experience. At least 3 years of experience in PKI engineering and certificate services, AWS Cloud, and Microsoft Identity and Access services such as AD/AAD. Deep understanding of X.509, RSA, certificate chains, key usage, CRL/OCSP. Strong experience with Linux and/or Windows administration and troubleshooting. Proficient in scripting with PowerShell, Bash, or Python. Practical experience implementing and troubleshooting HSMs. Experience with cryptographic tools such as OpenSSL. Ability to work directly with teams and vendors to resolve complex PKI or platform issues. Experience working in enterprise environments with strong security and compliance requirements. Fluent in English and strong communication and documentation skills. Preferred Qualifications Experience with Keyfactor EJBCA and Keyfactor Command. Knowledge of AWS, Microsoft Active Directory and Azure certificate integration mechanisms. Experience with CyberArk for secure credential or key management. Relevant certifications such as Microsoft Identity, Azure, AWS, CyberArk, CISSP, Security+. Basic knowledge of networking and firewalls. Experience with cloud environments (Azure and AWS). Personal Attributes Strong analytical and problem?solving capabilities. High attention to detail and a security?first mindset. Ability to prioritize tasks and collaborate effectively in cross?functional teams. Proactive, motivated, and committed to continuous improvement of PKI and security operations. Passionate, energetic, and positive attitude. ## Description Tech Engineer - Public Key Infrastructure (PKI) and Hardware Security Modules (HSM)Se anima a todos los posibles solicitantes a que se desplacen y lean la descripción completa del puesto antes de presentar su candidatura.We are seeking a Tech Engineer experienced in PKI and HSM to manage the enterprise PKI environment, ensuring secure certificate lifecycle management and robust key protection.This role will operate within a team of identity and access management engineers, maintain platform health, support break/fix, upgrades, patches, and coordinate with architecture on proofs of concept.Key ResponsibilitiesAdminister and maintain enterprise PKI components, focusing on Keyfactor EJBCA, Keyfactor Command, or similar platforms.Design, configure, and manage certificate profiles, CA hierarchies, enrollment processes, and certificate lifecycle workflows.Ensure secure key generation, storage, and management leveraging HSMs.Conduct proactive monitoring, health checks, maintenance, upgrades and patching of PKI systems.Troubleshoot certificate?related issues across servers, applications, and infrastructure components.Perform cryptographic operations and validation using tools like OpenSSL.Ensure PKI compliance with internal policies, security standards, and audit requirements.Develop and maintain automation scripts (Bash, Python, PowerShell) for operational efficiency.Provide L3 engineering support for PKI and related cryptographic services.Produce periodic operational reports and assist in remediation of audit and compliance findings.Document technical procedures, architecture, and operational runbooks.QualificationsBachelor's degree in computer science, engineering, or equivalent experience.At least 3 years of experience in PKI engineering and certificate services, AWS Cloud, and Microsoft Identity and Access services such as AD/AAD.Deep understanding of X.509, RSA, certificate chains, key usage, CRL/OCSP.Strong experience with Linux and/or Windows administration and troubleshooting.Proficient in scripting with PowerShell, Bash, or Python.Practical experience implementing and troubleshooting HSMs.Experience with cryptographic tools such as OpenSSL.Ability to work directly with teams and vendors to resolve complex PKI or platform issues.Experience working in enterprise environments with strong security and compliance requirements.Fluent in English and strong communication and documentation skills.Preferred QualificationsExperience with Keyfactor EJBCA and Keyfactor Command.Knowledge of AWS, Microsoft Active Directory and Azure certificate integration mechanisms.Experience with CyberArk for secure credential or key management.Relevant certifications such as Microsoft Identity, Azure, AWS, CyberArk, CISSP, Security+.Basic knowledge of networking and firewalls.Experience with cloud environments (Azure and AWS).Personal AttributesStrong analytical and problem?solving capabilities.High attention to detail and a security?first mindset.Ability to prioritize tasks and collaborate effectively in cross?functional teams.Proactive, motivated, and committed to continuous improvement of PKI and security operations.Passionate, energetic, and positive attitude.BenefitsFlexible schedule to adjust work hours to accommodate personal needs.Option to work from home with a hybrid work plan.Additional vacation days through a custom holiday purchase program.Floating holidays that can be exchanged for other days.Up to two months of unpaid sabbatical leave.Global family leave policy with flexible paid conditions for family life events.Access to health and wellness platform offering wellbeing content, nutrition counseling, fitness classes, and more.Access to a network of gyms and sports centres through Wellhub.On?site medical services.Professional development platform to connect with opportunities and mentors.Stock ownership program for employee shareholders.Recognition program for celebrating talent and success.Life insurance.Flexible remuneration plan with options such as health insurance, meal vouchers, childcare vouchers, transportation vouchers, and training.Discounts at partner stores, restaurants, travel agencies, and other services.Company?subsidised volunteer program.Schneider Electric is an Equal Opportunity Employer.xcskxlj We provide equal employment and advancement opportunities for all qualified individuals regardless of race, religion, color, gender, disability, national origin, age, military status, sexual orientation, marital status, or any other legally protected characteristic.#J-*****-Ljbffr ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Robots Run Wild, Massive Crime Data Leak and AI Replaces Models - David Benson](https://www.wearedevelopers.com/videos/1849-robots-run-wild-massive-crime-data-leak-and-ai-replaces-models-david-benson) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Post-Quantum Cryptography: Preparing for Q-Day](https://www.wearedevelopers.com/videos/100179-post-quantum-cryptography-preparing-for-q-day) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Top Characteristics of a Software Engineer](https://www.wearedevelopers.com/magazine/166-top-characteristics-of-a-software-engineer)