PKI Governance and Configuration Manager

System One
Springfield, VA, United States
30 days ago
Apply on www.juju.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Active Directory Amazon Web Services JIRA Microsoft Azure Software as a Service Cloud Computing Cloud Computing Security Configuration Management Federal Information Processing Standards (FIPS) Identity and Access Management NIPRNet Public Key Infrastructure
+5 more
X.509 Information Technology Nessus Scap Compliance Checker Plan of Action and Milestones

Job description

  • Oversee the integrity, security, and compliance of Department of State’s PKI and Credential hosting systems.

  • Manage the governance lifecycle for multiple PKI systems and Credential Hosting environments, including enforcing adherence to Certificate Policy (CP) and Certification Practice Statements (CPS).

  • Lead all NIST SP 800-53 security compliance assessments and maintain comprehensive security artifacts (SSP, SAR, POA&M, etc.).

  • Manage the FedRAMP certification process for SaaS offerings and ensure continuous monitoring to maintain Authority to Operate (ATO).

  • Establish and manage configuration management baselines and lead the Change Advisory Board (CAB) to evaluate security impacts of system modifications.

  • Coordinate security posture synchronization across Unclassified (NIPR), Classified (SIPR), and Cloud/SaaS environments and ensure seamless identity management and credential interoperability., System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan., System One, and its subsidiaries including Joulé, ALTA IT Services, CM Access, TPGS, and MOUNTAIN, LTD., are leaders in delivering workforce solutions and integrated services across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible full-time employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.

Requirements

  • Bachelor’s degree with at least 9 years of experience, or Master’s degree with at least 7 years of experience; additional experience may be considered in lieu of degree.

  • 8+ years in cybersecurity, with at least 5 years focused on PKI and Federal Governance (GRC).

  • Deep understanding of X.509 certificates, HSMs, CRLs, and OCSP.

  • Mastery of NIST SP 800-53, NIST SP 800-37 (RMF), FIPS 140-2/3, NIST SP 800-157 (Rev-1), NIST SP 800-63, and FedRAMP Moderate/High standards.

  • Proven experience leading systems through the full Assessment and Authorization (A&A) process for ATO.

  • Certifications such as CISSP, CISM, GSLC, ITIL, PMP, or specialized PKI certifications are preferred.

  • Proficiency in Identity Systems (Active Directory Certificate Services, Entrust, EJBCA), Cloud Security (FedRAMP OSCAL, AWS/Azure Government Cloud controls), and tools like STIG Viewer, SCAP Compliance Checker, Nessus/ACAS, JIRA for configuration management.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.juju.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:05 min

Integrating an assistant application with Jira software

Felix Augenstein · LIVE

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · World Congress 2023

5:47 min

Integrating user stories and test automation via Jira tools

Christoph Ruggenthaler · LIVE

1:13 min

Structuring a comprehensive corporate security organization

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · World Congress 2026 Europe

1:37 min

Mapping team collaboration networks using jira metadata

Dmitry Yanter Dmitry Yanter · World Congress 2025

Videos

See all

Related articles

See all