> Markdown version of [/jobs/ext/2309592-pki-cryptography-and-zero-trust-architect](https://www.wearedevelopers.com/jobs/ext/2309592-pki-cryptography-and-zero-trust-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # PKI, Cryptography and Zero Trust Architect - **Company:** Iron Bow Technologies - **Location:** Herndon, VA, United States (Remote available) - **Contract:** Permanent contract - **Skills:** Federal Information Processing Standards (FIPS), Information Systems Security Architecture Professional, Public Key Infrastructure, Zero Trust Network Access, Sherwood Applied Business Security Architecture, Togaf - **Published:** August 30, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88193358/1 ## About the Role The position requires demonstrated experience designing and operating enterprise PKI and key-management architectures and working knowledge of FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA). The candidate should be able to demonstrate prior work involving hybrid classical/PQC architectures and Zero Trust designs consistent with NIST SP 800-207. Primarily remote. Limited travel to customer facility., * Demonstrated enterprise PKI architecture and operations experience. * Demonstrated enterprise KMS and HSM architecture experience. * Strong understanding of Zero Trust architecture and NIST SP 800-207. * Experience with HSM-backed roots of trust and enterprise ICAM integration. * Working knowledge of FIPS 203, 204, and 205 and their HSM implementation implications. * Demonstrated experience designing hybrid classical/PQC architectures or cryptographic modernization strategies. WHAT SETS YOU APART * CISSP-ISSAP, SABSA, TOGAF, or comparable security/architecture credentials. * Experience with Federal ICAM/FICAM and PIV/CAC environments. * Experience with Microsoft ADCS and enterprise certificate services. * Experience designing PQC migration strategies for large enterprise environments., * You will be a key contributor to Iron Bow's transformational shift in how we deliver value to both customers and employees. * You will have the pleasure of working with passionate professionals in a culture that fosters a workplace where everyone feels respected, supported and empowered to succeed. ## Description * Develop enterprise PKI, KMS, cryptographic, and HSM architecture supporting VA operational and cybersecurity requirements. * Architect HSM-backed roots of trust and integration with enterprise Certificate Authorities and KMS platforms. * Design Zero Trust cryptographic controls aligned with NIST SP 800-207 and VA Critical Security Controls. * Integrate HSM architecture with enterprise ICAM services, machine identity, authentication, authorization, and least-privilege controls. * Design hybrid classical/post-quantum cryptographic architectures supporting phased PQC adoption. * Architect parallel PQC/hybrid CA hierarchies to enable transition without disruption to production PKI. * Develop approaches for cross-certification, new trust-anchor distribution, certificate issuance/validation, revocation, OCSP, and enrollment. * Support development of the Zero Trust Implementation Plan and define measurable Zero Trust maturity targets. * Design management-plane segmentation, mutually authenticated communications, machine identity, privileged-access controls, quorum control, and tamper-evident audit capabilities. * Support development and maintenance of the Crypto Agility Plan and Cryptographic Bill of Materials. * Evaluate architectural impacts of evolving NIST, IETF, CNSA 2.0, and Federal cryptographic standards. ## Related Videos - [An alternative approach to digital sovereignty: Confidential Computing](https://www.wearedevelopers.com/videos/100043-an-alternative-approach-to-digital-sovereignty-confidential-computing) - [Startup Presentation: IgniSign - Sign for Real](https://www.wearedevelopers.com/videos/1168-startup-presentation-ignisign-sign-for-real) - [Developing ASP.NET Core Microservices with Dapr: A practical guide](https://www.wearedevelopers.com/videos/1528-developing-asp-net-core-microservices-with-dapr-a-practical-guide) - [Trust as the Key Concept in Future Mobility](https://www.wearedevelopers.com/videos/581-trust-as-the-key-concept-in-future-mobility) - [Small, Secure, Interconnected: The next Internet Protocol](https://www.wearedevelopers.com/videos/100062-small-secure-interconnected-the-next-internet-protocol) - [Trust Issues: Because Zero-Trust Isn’t Optional Anymore](https://www.wearedevelopers.com/videos/100089-trust-issues-because-zero-trust-isn-t-optional-anymore) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)