PKI Security Services Engineer

Apex Systems LLC
Dearborn, MI, United States
4 days ago
Apply on jobs.mitalent.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Working hours
Regular working hours

Tech stack

Testing (Software) Clean Code Principles Java (Programming Language) .NET Framework Application Programming Interfaces (APIs) Agile Methodology Applications Architecture Business Logic Application Testing C Sharp (Programming Language) Cloud Computing Software Documentation
+38 more
Software Quality Cyber Security Databases Computer Engineering Continuous Delivery Continuous Integration Disaster Recovery Hardware Security Module Human-Computer Interaction Python (Programming Language) Key Management PostgreSQL MongoDB MySQL OAuth Object-Oriented Software Development Oracle (Applications) Public Key Infrastructure X.509 Software Architecture RSA (Cryptosystem) Secure Coding Software Deployment Software Engineering Web Services Google Cloud Data Storage Technologies Test-Driven Development (TDD) .NET Core Build Server Backend Kubernetes Performance Monitor Restful APIs Static Application Security Testing Web Api Microservices Dynamic Application Security Testing

Job description

The Product Cybersecurity PKI & Key Mgmt Security Services team generates, distributes, stores, and manages lifecycle for the cryptographic keys and certificates in the vehicle product ecosystem. This includes developing and maintaining in-house APIs and web services to provide confidentiality, integrity and authenticity protection for various use cases and features in the product ecosystem. We are seeking an exceptional Software Engineer specializing in Public Key Infrastructure (PKI) and secure API services to own the end-to-end lifecycle of mission-critical cryptographic systems. You will design, build, deploy, and maintain high-assurance PKI and security service APIs that power certificate issuance, lifecycle management, revocation, and integration for the connected vehicle product ecosystem. Employees in this job function develop and maintain the back-end/ server-side parts of an application, typically consisting of APIs, databases and other services containing business logic. They work with various languages and tools to create and maintain services on-prem or in the cloud., * Engage with customers to understand their use-cases and requirements

  • Solve complex problems by designing, developing, and delivering using various tools, languages, frameworks, and technologies
  • Align with architecture guidelines for unified and coherent approach to development
  • Design, develop, and deliver new code using various tools, languages, frameworks, and technologies
  • Develop and maintain back-end applications like APIs and microservices using server-side languages like Java, Python, C#, etc.
  • Collaborate with front-end developers to integrate user interface elements and with cross functional teams like product owners, designers, architects etc.
  • Manage application deployment to the cloud or on-prem, health and performance monitoring, security hardening and disaster recovery for deployed applications
  • Manage data storage and retrievals in applications by utilizing database technologies such as Oracle, MySQL, MongoDB, etc.
  • Promote improvements in programming practices, such as test-driven development, continuous integration, and continuous delivery
  • Optimize back-end infrastructure and deployment practices to improve application resiliency and reliability
  • Support security practices to safeguard user data including encryption and anonymization
  • Write and manage code that interfaces with HSMs to apply cryptography and issue certificates
  • End-to-End Ownership: Lead the full lifecycle of PKI and Key Management services supporting our vehicle products and ecosystem - lead customer requirements gathering, architecture design, implementation, testing, deployment, monitoring, and post-launch support.
  • Design and develop robust, secure, and scalable RESTful APIs and web services for various features and use cases: CRL/OCSP, ACME, Certificate Issuance, message encryption/decryption, software signing, key rotation and certificate lifecycle management, HSM integration with PKCS11.
  • Implement access control methods that enforce least privilege access principles using OAuth or mTLS.
  • Cryptographic Engineering: Implement and harden PKI and key services with deep knowledge of PKI industry standards, X.509, PKCS standards, elliptic curve cryptography (ECC) and RSA, post-quantum readiness, and hardware security module CSP integration. Apply hybrid encryption techniques with AES. Define and enforce PKI certificate policies and certificate profiles.
  • Infrastructure and CI/CD Integration: Release and Deploy your apps through build server, CI/CD pipeline, and infrastructure involving on-premises and cloud Kubernetes
  • Security & Compliance: Monitor and address findings regularly in code base through SAST, DAST, software quality and security vulnerability scanning.
  • Drive and support testing at each stage of the development process.

Requirements

  • Computer engineering
  • Software Development Lifecycle
  • Software Testing
  • PostgreSQL
  • Software Documentation
  • Application Development
  • Bouncy Castle Cryptographic
  • Cloud Infrastructure
  • Google Cloud Platform
  • .NET Core
  • .NET Developer
  • Cyber Security
  • C#
  • Application Testing
  • Agile Software Development

Skills Preferred:

Kubernetes, Technical Communication, Technical Requirements, Technical Documentation, Application Architect, Technical Analysis

Experience Required:

  • Engineer 3 Exp: Prac. In 2 coding lang. or adv. Prac. in 1 lang. 6+ years in IT; 4+ years in software engineering/development and secure coding practices using object oriented programming
  • Strong knowledge and applicability of software architecture, development, methodologies and design principles including test-driven development Strong understanding and ability to apply cryptographic algorithms and standards in software, including RSA, ECC, AES, X.509
  • Proven track record of owning customer-facing products from ideation to general acceptance, and flexibility to manage multiple projects and deliverables throughout lifecycle

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.mitalent.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:18 min

Scaling MySQL databases for massive user growth

Johannes Nicolai Johannes Nicolai +1 · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

1:48 min

Analyzing network packets with database protocol tools

Daniël van Eeden Daniël van Eeden · World Congress 2026 Europe

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all