Cloud Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+7 more
Job description
This is a senior hands-on engineering role within Chevron’s Digital Identity organization responsible for designing, operating, and modernizing enterprise-scale Public Key Infrastructure (PKI) and cryptographic services across cloud and hybrid environments. The role enables secure certificate lifecycle management, key protection, and identity-driven security controls, supporting Zero Trust adoption, phishing-resistant authentication, and protection of critical business workloads.
Responsibilities for this position may include but are not limited to:
-
PKI & Certificate Services
- Design, deploy, and manage enterprise PKI platforms (Microsoft ADCS, DigiCert, NDES, cloud-integrated services)
- Own certificate lifecycle management (issuance, renewal, revocation, compliance, automation)
- Implement post-quantum cryptography capabilities aligned to business and regulatory requirements
- Manage HSM-backed key protection and integration with key management systems
-
Cloud & Hybrid Identity Integration
- Integrate PKI with Active Directory and Microsoft Entra ID for hybrid identity scenarios
- Enable certificate-based authentication for workloads, APIs, devices, VPN, and service accounts
- Align PKI services with Azure and multi-cloud security architectures
-
Security Engineering & Zero Trust
- Implement phishing-resistant authentication using FIDO2, PIV, and certificate-based methods
- Support Conditional Access policies leveraging identity, device posture, and risk signals
- Advance Zero Trust maturity and continuous security posture improvement
-
Privileged Access & Operational Security
- Integrate PKI with PAM solutions (e.g., Delinea) for secure service account authentication
- Support privileged access workstations and hardened admin environments
- Lead break-glass and recovery scenarios using secure access controls
-
Automation, Reliability & Operations
- Drive automation using scripting, APIs, and orchestration to reduce manual processes
- Lead disaster recovery exercises, upgrades, and PKI platform modernization
- Provide advanced engineering support, incident response, and root cause analysis
-
Leadership & Stakeholder Engagement
- Serve as a PKI subject matter expert within Digital Identity - Protection
- Collaborate across security, cloud, and operations teams
- Mentor engineers and contribute to standards and operational excellence
Requirements
- Bachelor’s degree in computer science, Information Security, Engineering, or related field (or equivalent experience)
- 12-15 years in Identity & Access Management, PKI, or security infrastructure engineering
- Proven experience operating large-scale enterprise PKI environments
- Strong understanding of cryptography, authentication, and trust models
- Hands-on expertise with PKI platforms, HSM, key management, automation, Active Directory, and Microsoft Entra ID, * Industry certifications in security or cloud (e.g., CISSP, Azure Security)
- Experience in regulated industries such as oil & gas or energy
- Knowledge of Zero Trust architecture, Conditional Access, and identity security engineering
- Familiarity with ITIL and operational processes in regulated environments
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
7 Cloud Computing Trends Coming in 2025 for Developers
Highest Paying Tech Companies for Developers
Everything a Developer Needs to Know About MCP with Neo4j