Senior Public Key Infrastructure (PKI) Engineer in Washington

Energy Jobline
Washington, DC, United States
15 days ago
Apply on www.energyjobline.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Windows Active Directory Application Programming Interfaces (APIs) Amazon Web Services Microsoft Azure Bash Shell Cloud Computing Cyber Security Linux Federal Information Processing Standards (FIPS) Hardware Security Module Python (Programming Language)
+18 more
Key Management Windows Servers Public Key Infrastructure X.509 Windows PowerShell Ansible Zero Trust Network Access Virtualization Technology Web Services Transport Layer Security Load Balancing Istio HybridCloud SC Clearance Kubernetes Restful APIs Terraform Devsecops

Job description

  • Architect, deploy, administer, and maintain enterprise PKI environments and Certificate Authority (CA) infrastructure, including Microsoft Active Directory Certificate Services (AD CS).
  • Design and manage enterprise server certificate strategies across Windows, Linux, virtualization, cloud, web services, APIs, and load balancers.
  • Automate certificate lifecycle management (issuance, renewal, revocation, expiration monitoring, key rotation, reporting) using ACME, SCEP/EST, REST APIs, PowerShell, Python, Bash, Ansible, or Terraform.
  • Deploy, manage, and troubleshoot TLS/SSL certificates, trust chains, and certificate validation across the enterprise.
  • Integrate PKI services with Active Directory, Azure, AWS, virtualization platforms, and DevSecOps pipelines.
  • Support Zero Trust initiatives through machine and certificate-based trust.
  • Support planning for post-quantum cryptography and CNSA 2.0 migration.
  • Ensure PKI environments comply with NIST, FIPS, DISA STIGs, and RMF requirements.
  • Participate in incident response for certificate compromise or trust-related events.
  • Maintain technical documentation, architecture diagrams, SOPs, and configuration baselines.
  • Provide technical leadership and mentorship to junior engineers.

Requirements

  • U.S. with an active Secret clearance; eligible for Top Secret (ZTI sponsors processing).
  • Hybrid: up to 3 days/week onsite in Fairfax, VA.
  • DoD 8140 IAT Level II certification (Security+ CE or higher), or ability to obtain within 90 days.
  • 8+ years of systems/security engineering experience with 4+ years focused on enterprise PKI (or 12 years total without a degree).
  • Experience administering AD CS or comparable enterprise PKI platforms.
  • Experience automating certificate lifecycle management at scale.
  • Experience administering Windows Server and/or Linux.
  • Strong understanding of X.509, CRL/OCSP, enterprise trust models, cryptographic algorithms, and key management.
  • Excellent analytical, problem-solving, and communication skills., * CISSP, Azure Security Engineer Associate, or AWS Certified Security - Specialty.
  • Experience with Entrust, DigiCert, EJBCA, Keyfactor, Venafi, or similar platforms.
  • Hardware Security Module (HSM) experience.
  • Azure Government, AWS GovCloud, or hybrid cloud environments.
  • PKI integration with Kubernetes, containers, or service mesh.
  • Experience supporting DoD RMF, FedRAMP, or CMMC compliance initiatives.

Benefits & conditions

This position focuses on enterprise server PKI, certificate lifecycle automation, and infrastructure trust services, not end-user certificate administration. You will modernize CA infrastructure, automate certificate management at scale, support post-quantum cryptography transition planning, and help shape Zero Trust initiatives in mission-critical DoD environments. ZTI will sponsor Top Secret clearance processing. Benefits include 100% company-paid medical, dental, and vision for you and your family, 4 weeks PTO, and certification reimbursement., * 4 weeks PTO plus all federal holidays paid.

  • 100% company-paid medical, dental, and vision for employees and their families.
  • 4% matching 401(k).
  • Professional training and certification reimbursement.
  • Flexible hybrid work environment.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.energyjobline.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

2:53 min

Configuring dynamic proxy updates with Istio Pilot

Jan Mensch Jan Mensch · World Congress 2026 Europe

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

7:15 min

Installing Istio programmatically with bash scripts

Thomas Südbröcker · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all