Sr. Engineer, PKI & Identity Infrastructure

Tesla Motors
Palo Alto, CA, United States
6 days ago
Apply on jobs.localjobnetwork.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$140,000.0 - $300,000.0
Working hours
Regular working hours

Tech stack

Microsoft Access Active Directory Build Automation Unix Cloud Computing Cyber Security Databases Continuous Integration Linux Failover Federal Information Processing Standards (FIPS) Hardware Security Module
+18 more
Identity and Access Management Python (Programming Language) Kerberos (Protocol) Key Management OAuth OpenID Public Key Infrastructure Windows PowerShell Role-Based Access Control Zero Trust Network Access Security Assertion Markup Language (SAML) System Availability Grafana Git Flow Kubernetes Information Technology SailPoint Splunk

Job description

In this role, you will own the design, implementation, and evolution of our encryption and identity infrastructure, including enterprise certificate authorities, the Teleport access platform (database, Kubernetes, Linux, and application access), cloud and HSM-backed key management, and the integration of PKI with IAM systems. You will ensure secure identity management, access, and encryption across the organization while maintaining high availability, auditability, and compliance., As a Senior Engineer, you will set technical direction for these platforms, lead cross-functional initiatives from design to production, mentor engineers, and represent the team in vendor, architecture, and leadership discussions. What You’ll Do

  • Own enterprise PKI architecture and operations (CA hierarchy, issuance/revocation policy, HA/scale) on EJBCA and/or ADCS
  • Operate and scale Teleport for secure access to databases, Kubernetes, Linux hosts, and applications (RBAC, access requests, SSO, WebAuthn/passkeys, mTLS, audit)
  • Design and operate key management at scale (hierarchies, envelope encryption, rotation) across cloud KMS and HSM-backed services for encryption and signing use cases
  • Manage production HSMs: key ceremonies, token provisioning/rotation, clustering/failover, FIPS 140-2/140-3 posture, and crypto DR
  • Own digital certificate lifecycle at fleet scale, including automated issuance (e.g., ACME), renewal, and revocation
  • Integrate PKI and access platforms with IAM (Active Directory, Entra ID, and other IdPs) for authentication, authorization, and encryption workflows
  • Implement strong access control patterns (RBAC/ABAC, zero-trust access, mTLS/SPIFFE where applicable) with partner security teams
  • Build automation and platform engineering for cert/key lifecycle using Python and/or PowerShell, CI/CD, and GitOps
  • Own monitoring, compliance, and incident response for PKI/KMS/HSM/Teleport (Splunk/Grafana observability, audits, 24/7 on-call, postmortems)
  • Lead and mentor: set standards/runbooks, drive cross-functional delivery, and manage vendor relationships (e.g., Thales, DigiCert, Teleport, SailPoint)

Requirements

We are seeking a Senior Engineer with deep expertise in Public Key Infrastructure (PKI), Key Management Services (KMS), Hardware Security Modules (HSM), and Identity and Access Management (IAM) platforms. The ideal candidate has a strong background operating enterprise PKI (EJBCA and/or Active Directory Certificate Services (ADCS)), key management and HSM services, and infrastructure access platforms such as Teleport, along with hands-on experience managing digital certificates, symmetric and asymmetric keys, and related security technologies., * Degree in Computer Science, Information Security, or related field; or equivalent experience

  • 8+ years in security infrastructure, including 5+ years focused on enterprise PKI and IAM
  • Proven experience designing and operating enterprise PKI with EJBCA and/or ADCS (hierarchy, policy, revocation, scale)
  • Production experience with key management at scale (AWS KMS, Azure Key Vault, or equivalent, and/or HSM-backed services), including rotation and lifecycle
  • Experience managing HSMs (Thales, Entrust, or equivalent), including FIPS environments, key ceremonies, and clustering/failover
  • Experience operating Teleport or a comparable infrastructure access / zero-trust platform (DB/K8s/Unix access with mTLS, RBAC, audit)
  • Strong PKI fundamentals plus IAM platform experience (AD, Entra ID) and identity protocols (SAML, OIDC, OAuth, Kerberos)
  • Proficiency in PowerShell and/or Python for PKI/KMS/access automation; experience with CI/CD (GitOps preferred)
  • Experience supporting 24/7 global mission-critical environments; cloud/hybrid security experience preferred (Kubernetes a plus)
  • Track record leading cross-functional security initiatives and mentoring engineers, with strong stakeholder communication and documentation skills

Benefits & conditions

Along with competitive pay, as a full-time Tesla employee, you are eligible for the following benefits at day 1 of hire:

  • Medical plans > plan options with $0 payroll deduction
  • Family-building, fertility, adoption and surrogacy benefits
  • Dental (including orthodontic coverage) and vision plans, both have options with a $0 paycheck contribution
  • Company Paid (Health Savings Accounts) HSA Contribution when enrolled in the High-Deductible medical plan with HSA
  • Healthcare and Dependent Care Flexible Spending Accounts (FSA)
  • 401(k) with employer match, Employee Stock Purchase Plans, and other financial benefits
  • Company paid Basic Life, AD&D
  • Short-term and long-term disability insurance (90 day waiting period)
  • Employee Assistance Program
  • Sick and Vacation time (Flex time for salary positions, Accrued hours for Hourly positions), and Paid Holidays
  • Back-up childcare and parenting support resources
  • Voluntary benefits to include: critical illness, hospital indemnity, accident insurance, theft & legal services, and pet insurance
  • Weight Loss and Tobacco Cessation Programs
  • Tesla Babies program
  • Commuter benefits
  • Employee discounts and perks program

Expected Compensation $140,000 - $300,000/annual salary + cash and stock awards + benefits

Pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. The total compensation package for this position may also include other elements dependent on the position offered. Details of participation in these benefit plans will be provided if an employee receives an offer of employment. Tesla is an Equal Opportunity / Affirmative Action employer committed to diversity in the workplace. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, age, national origin, disability, protected veteran status, gender identity or any other factor protected by applicable federal, state or local laws.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.localjobnetwork.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:03 min

Microsoft integrating native Unix coreutils into Windows environments

Chris Heilmann +2 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

2:04 min

Defining timestamps and the international standard format

Denny Biasiolli Denny Biasiolli · Europe 2026 Virtual

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all