> Markdown version of [/jobs/ext/2830642-senior-public-key-infrastructure-pki-engineer-in-washington](https://www.wearedevelopers.com/jobs/ext/2830642-senior-public-key-infrastructure-pki-engineer-in-washington). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Public Key Infrastructure (PKI) Engineer in Washington - **Company:** Energy Jobline - **Location:** Washington, DC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Application Programming Interfaces (APIs), Amazon Web Services, Microsoft Azure, Bash Shell, Cloud Computing, Cyber Security, Linux, Federal Information Processing Standards (FIPS), Hardware Security Module, Python (Programming Language), Key Management, Windows Servers, Public Key Infrastructure, X.509, Windows PowerShell, Ansible, Zero Trust Network Access, Virtualization Technology, Web Services, Transport Layer Security, Load Balancing, Istio, HybridCloud, SC Clearance, Kubernetes, Restful APIs, Terraform, Devsecops - **Published:** September 10, 2026 - **Apply:** https://www.energyjobline.com/job/senior-public-key-infrastructure-pki-engineer-washington-31596602 ## About the Role * U.S. with an active Secret clearance; eligible for Top Secret (ZTI sponsors processing). * Hybrid: up to 3 days/week onsite in Fairfax, VA. * DoD 8140 IAT Level II certification (Security+ CE or higher), or ability to obtain within 90 days. * 8+ years of systems/security engineering experience with 4+ years focused on enterprise PKI (or 12 years total without a degree). * Experience administering AD CS or comparable enterprise PKI platforms. * Experience automating certificate lifecycle management at scale. * Experience administering Windows Server and/or Linux. * Strong understanding of X.509, CRL/OCSP, enterprise trust models, cryptographic algorithms, and key management. * Excellent analytical, problem-solving, and communication skills., * CISSP, Azure Security Engineer Associate, or AWS Certified Security - Specialty. * Experience with Entrust, DigiCert, EJBCA, Keyfactor, Venafi, or similar platforms. * Hardware Security Module (HSM) experience. * Azure Government, AWS GovCloud, or hybrid cloud environments. * PKI integration with Kubernetes, containers, or service mesh. * Experience supporting DoD RMF, FedRAMP, or CMMC compliance initiatives. ## Description * Architect, deploy, administer, and maintain enterprise PKI environments and Certificate Authority (CA) infrastructure, including Microsoft Active Directory Certificate Services (AD CS). * Design and manage enterprise server certificate strategies across Windows, Linux, virtualization, cloud, web services, APIs, and load balancers. * Automate certificate lifecycle management (issuance, renewal, revocation, expiration monitoring, key rotation, reporting) using ACME, SCEP/EST, REST APIs, PowerShell, Python, Bash, Ansible, or Terraform. * Deploy, manage, and troubleshoot TLS/SSL certificates, trust chains, and certificate validation across the enterprise. * Integrate PKI services with Active Directory, Azure, AWS, virtualization platforms, and DevSecOps pipelines. * Support Zero Trust initiatives through machine and certificate-based trust. * Support planning for post-quantum cryptography and CNSA 2.0 migration. * Ensure PKI environments comply with NIST, FIPS, DISA STIGs, and RMF requirements. * Participate in incident response for certificate compromise or trust-related events. * Maintain technical documentation, architecture diagrams, SOPs, and configuration baselines. * Provide technical leadership and mentorship to junior engineers. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Securing Secrets in the GitOps era](https://www.wearedevelopers.com/videos/546-securing-secrets-in-the-gitops-era) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries)