> Markdown version of [/jobs/ext/2402402-pki-governance-and-configuration-manager](https://www.wearedevelopers.com/jobs/ext/2402402-pki-governance-and-configuration-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # PKI Governance and Configuration Manager - **Company:** System One - **Location:** Springfield, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Active Directory, Amazon Web Services, JIRA, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Computing Security, Configuration Management, Federal Information Processing Standards (FIPS), Identity and Access Management, NIPRNet, Public Key Infrastructure, X.509, Information Technology, Nessus, Scap Compliance Checker, Plan of Action and Milestones - **Published:** August 7, 2026 - **Apply:** https://www.juju.com/job/00000000gm089x ## About the Role + Bachelor's degree with at least 9 years of experience, or Master's degree with at least 7 years of experience; additional experience may be considered in lieu of degree. + 8+ years in cybersecurity, with at least 5 years focused on PKI and Federal Governance (GRC). + Deep understanding of X.509 certificates, HSMs, CRLs, and OCSP. + Mastery of NIST SP 800-53, NIST SP 800-37 (RMF), FIPS 140-2/3, NIST SP 800-157 (Rev-1), NIST SP 800-63, and FedRAMP Moderate/High standards. + Proven experience leading systems through the full Assessment and Authorization (A&A) process for ATO. + Certifications such as CISSP, CISM, GSLC, ITIL, PMP, or specialized PKI certifications are preferred. + Proficiency in Identity Systems (Active Directory Certificate Services, Entrust, EJBCA), Cloud Security (FedRAMP OSCAL, AWS/Azure Government Cloud controls), and tools like STIG Viewer, SCAP Compliance Checker, Nessus/ACAS, JIRA for configuration management. ## Description + Oversee the integrity, security, and compliance of Department of State's PKI and Credential hosting systems. + Manage the governance lifecycle for multiple PKI systems and Credential Hosting environments, including enforcing adherence to Certificate Policy (CP) and Certification Practice Statements (CPS). + Lead all NIST SP 800-53 security compliance assessments and maintain comprehensive security artifacts (SSP, SAR, POA&M, etc.). + Manage the FedRAMP certification process for SaaS offerings and ensure continuous monitoring to maintain Authority to Operate (ATO). + Establish and manage configuration management baselines and lead the Change Advisory Board (CAB) to evaluate security impacts of system modifications. + Coordinate security posture synchronization across Unclassified (NIPR), Classified (SIPR), and Cloud/SaaS environments and ensure seamless identity management and credential interoperability., System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan., System One, and its subsidiaries including Joulé, ALTA IT Services, CM Access, TPGS, and MOUNTAIN, LTD., are leaders in delivering workforce solutions and integrated services across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible full-time employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan. ## Related Videos - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Integrate your Cognitive Assistant with 3rd-party DBs and software](https://www.wearedevelopers.com/videos/249-integrate-your-cognitive-assistant-with-3rd-party-dbs-and-software) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)