> Markdown version of [/jobs/ext/2295426-sr-engineer-pki-identity-infrastructure](https://www.wearedevelopers.com/jobs/ext/2295426-sr-engineer-pki-identity-infrastructure). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Engineer, PKI & Identity Infrastructure - **Company:** Tesla Motors - **Location:** Palo Alto, CA, United States - **Experience:** Expert - **Salary:** $140,000.0 - $300,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Access, Active Directory, Build Automation, Unix, Cloud Computing, Cyber Security, Databases, Continuous Integration, Linux, Failover, Federal Information Processing Standards (FIPS), Hardware Security Module, Identity and Access Management, Python (Programming Language), Kerberos (Protocol), Key Management, OAuth, OpenID, Public Key Infrastructure, Windows PowerShell, Role-Based Access Control, Zero Trust Network Access, Security Assertion Markup Language (SAML), System Availability, Grafana, Git Flow, Kubernetes, Information Technology, SailPoint, Splunk - **Published:** August 29, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88165634/1 ## About the Role We are seeking a Senior Engineer with deep expertise in Public Key Infrastructure (PKI), Key Management Services (KMS), Hardware Security Modules (HSM), and Identity and Access Management (IAM) platforms. The ideal candidate has a strong background operating enterprise PKI (EJBCA and/or Active Directory Certificate Services (ADCS)), key management and HSM services, and infrastructure access platforms such as Teleport, along with hands-on experience managing digital certificates, symmetric and asymmetric keys, and related security technologies., * Degree in Computer Science, Information Security, or related field; or equivalent experience * 8+ years in security infrastructure, including 5+ years focused on enterprise PKI and IAM * Proven experience designing and operating enterprise PKI with EJBCA and/or ADCS (hierarchy, policy, revocation, scale) * Production experience with key management at scale (AWS KMS, Azure Key Vault, or equivalent, and/or HSM-backed services), including rotation and lifecycle * Experience managing HSMs (Thales, Entrust, or equivalent), including FIPS environments, key ceremonies, and clustering/failover * Experience operating Teleport or a comparable infrastructure access / zero-trust platform (DB/K8s/Unix access with mTLS, RBAC, audit) * Strong PKI fundamentals plus IAM platform experience (AD, Entra ID) and identity protocols (SAML, OIDC, OAuth, Kerberos) * Proficiency in PowerShell and/or Python for PKI/KMS/access automation; experience with CI/CD (GitOps preferred) * Experience supporting 24/7 global mission-critical environments; cloud/hybrid security experience preferred (Kubernetes a plus) * Track record leading cross-functional security initiatives and mentoring engineers, with strong stakeholder communication and documentation skills ## Description In this role, you will own the design, implementation, and evolution of our encryption and identity infrastructure, including enterprise certificate authorities, the Teleport access platform (database, Kubernetes, Linux, and application access), cloud and HSM-backed key management, and the integration of PKI with IAM systems. You will ensure secure identity management, access, and encryption across the organization while maintaining high availability, auditability, and compliance., As a Senior Engineer, you will set technical direction for these platforms, lead cross-functional initiatives from design to production, mentor engineers, and represent the team in vendor, architecture, and leadership discussions. What You'll Do * Own enterprise PKI architecture and operations (CA hierarchy, issuance/revocation policy, HA/scale) on EJBCA and/or ADCS * Operate and scale Teleport for secure access to databases, Kubernetes, Linux hosts, and applications (RBAC, access requests, SSO, WebAuthn/passkeys, mTLS, audit) * Design and operate key management at scale (hierarchies, envelope encryption, rotation) across cloud KMS and HSM-backed services for encryption and signing use cases * Manage production HSMs: key ceremonies, token provisioning/rotation, clustering/failover, FIPS 140-2/140-3 posture, and crypto DR * Own digital certificate lifecycle at fleet scale, including automated issuance (e.g., ACME), renewal, and revocation * Integrate PKI and access platforms with IAM (Active Directory, Entra ID, and other IdPs) for authentication, authorization, and encryption workflows * Implement strong access control patterns (RBAC/ABAC, zero-trust access, mTLS/SPIFFE where applicable) with partner security teams * Build automation and platform engineering for cert/key lifecycle using Python and/or PowerShell, CI/CD, and GitOps * Own monitoring, compliance, and incident response for PKI/KMS/HSM/Teleport (Splunk/Grafana observability, audits, 24/7 on-call, postmortems) * Lead and mentor: set standards/runbooks, drive cross-functional delivery, and manage vendor relationships (e.g., Thales, DigiCert, Teleport, SailPoint) ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [WeAreDevelopers LIVE - Node and Package Security](https://www.wearedevelopers.com/videos/2138-wearedevelopers-live-node-and-package-security) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)