> Markdown version of [/jobs/ext/2846398-pki-engineer](https://www.wearedevelopers.com/jobs/ext/2846398-pki-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # PKI Engineer - **Company:** TEKSYSTEMS INC. - **Location:** Denver, CO, United States - **Experience:** Expert - **Salary:** $156,000.0 - $176,800.0 - **Contract:** Temporary contract - **Skills:** IEEE 802.1X, Active Directory, Application Programming Interfaces (APIs), BitLocker Drive Encryption, Linux, Disaster Recovery, Federal Information Processing Standards (FIPS), Virtual Private Networks (VPN), Key Management, Microsoft Security Essentials, Windows Servers, Multi-Purpose Internet Mail Extensions (MIME), Public Key Infrastructure, X.509, Windows PowerShell, Migration Manager, Zero Trust Network Access, RSA (Cryptosystem), Secure Hash Algorithm, SSL Certificate Management, Microsoft InTune, Enterprise Integration - **Published:** September 11, 2026 - **Apply:** https://www.thejobnetwork.com/job/c1ef96fe-3442-4e08-9cf8-75daea0bc876/sr-pki-engineer ## About the Role 1. ADCS (Active Directory Certificate Services), Pki, ADCS, Certificate Management, Vault Management, Security, * 8+ years in Security Engineering/Identity Infrastructure, including 5+ years hands-on with Microsoft AD CS and enterprise Active Directory with managing CA infra * Proven experience designing, deploying, and operating multi-tier Microsoft PKI (offline root, issuing CAs) in large/complex environments. * Deep knowledge of X.509, CRL/OCSP, EKU/KU, SANs, key algorithms and sizes (RSA/ECC), hashing (SHA-2), and certificate validation paths. * Strong PowerShell and Windows Server administration; GPOs, autoenrollment, templates, AIA/CDP configuration. * Experience with 802.1X/EAP-TLS, TLS/mTLS, VPN auth, and device/user certificate issuance at scale. * HSM experience (e.g., nCipher/Entrust/Thales) for CA key management. ## Description PKI Engineer to design, implement, and operate enterprise-grade Public Key Infrastructure (PKI) services with a strong focus on Microsoft Active Directory Certificate Services (AD CS) and Active Directory (AD) integration. Handson implementation and integration knowledge of certificate lifecycle management, CA hierarchy governance, enrollment automation, HSM-backed key protection, CA backup restore, migration and integration with platforms such as Windows Server, Linux, network/security devices, cloud providers, MDM/EPP, and zero-trust tooling. Subject matter expert for cryptographic standards, certificate-based authentication, and PKI security controls across the organization., 2. Integrate PKI with Active Directory (AD forests/domains, ADCS, AIA/CDP locations, GPOs) 3. Deploy, Configure, Implement, Install, Architecture & Design * Design and maintain enterprise PKI architectures (Root CA, Policy CA, Issuing CA) with offline/air gapped roots, secure key ceremonies, key usage, and issuance workflows and robust CRL/OCSP distribution. * Engineer solutions for mutual TLS, 802.1X (wired/wireless/VPN), device identity, code signing, S/MIME, BitLocker, and disk/volume encryption certs. * Key sizes, algorithms (RSA, ECC and PQC) encryption and hashing. * Implement HSM-backed key storage for CAs and code signing; lead key ceremonies, disaster recovery designs. Operations & Automation * Own certificate lifecycle management (issuance, renewal, revocation) including automation via Intune, GPO/Autoenrollment, SCEP/NDES, ACME, or MDM connectors. * Manage CRL/OCSP publication, monitoring, and availability, design highly available, geo-distributed revocation endpoints. * Implement scripting/automation (PowerShell, APIs) for bulk issuance, inventory, renewal, and drift detection. Enabling separation of duties for secure operation of PKI infrastructure * CA backup, restore renewal and migration strategy Security & Compliance * Apply strong key management practices (FIPS 140-2/140-3), certificate assurance levels, and secure CA hardening baselines. * Regularly perform PKI risk assessments, access reviews, and control testing (e.g., template permissions, EKU misuse, issuance constraints). * Lead root cause analysis and incident response for certificate/PKI-related outages or security events. * Maintain alignment with NIST, CAB Forum, Microsoft Security Baselines, and internal compliance frameworks (e.g., SOX, PCI, HIPAA, ISO 27001) as applicable. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Post-Quantum Cryptography: Preparing for Q-Day](https://www.wearedevelopers.com/videos/100179-post-quantum-cryptography-preparing-for-q-day) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems) - [Dev Digest 234: How X's Feed Works, Top 10 CI/CD Risks & Meat Proxies](https://www.wearedevelopers.com/magazine/755-dev-digest-234-how-x-s-feed-works-top-10-ci-cd-risks-meat-proxies)