PKI Engineer

The Intersect Group
United States
4 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Active Directory Amazon Web Services Microsoft Azure Cloud Computing CompTIA Security+ Cyber Security Hardware Security Module Virtual Private Networks (VPN) Key Management Automation of Marketing Microsoft Security Essentials Network Architecture
+14 more
Public Key Infrastructure X.509 Windows PowerShell Cloud Services Zero Trust Network Access Software Vulnerability Management SSL Certificate Management Scripting Transport Layer Security Google Cloud Software Troubleshooting Infrastructure Automation Frameworks Information Technology Network Server

Job description

We are seeking a skilled and motivated PKI Engineer to join our Infrastructure and Security team. This individual will be responsible for designing, administering, securing, and maintaining Public Key Infrastructure (PKI) environments. The role includes managing the lifecycle of digital certificates, certificate authorities, cryptographic services, and related security controls to ensure the confidentiality, integrity, and availability of enterprise systems and applications., * Manage and maintain enterprise PKI platforms, including Certificate Authorities (CAs), Registration Authorities (RAs), Hardware Security Modules (HSMs), OCSP responders, and certificate enrollment services.

  • Oversee certificate lifecycle management, including issuance, renewal, revocation, and replacement of digital certificates for users, devices, applications, servers, cloud services, and network infrastructure.
  • Implement and enforce PKI security controls, certificate policies, certificate practice statements, and cryptographic standards.
  • Design, deploy, and support automated certificate management solutions using tools and technologies such as Microsoft AD CS, Venafi, Keyfactor, DigiCert, ACME, and scripting/automation platforms.
  • Manage cryptographic key generation, storage, rotation, escrow, and retirement processes.
  • Troubleshoot and resolve certificate-related issues affecting applications, websites, VPNs, and authentication services.
  • Develop and maintain PKI architecture documentation, operational procedures, governance standards, and technical diagrams.
  • Participate in security assessments, incident investigations, vulnerability remediation efforts, and infrastructure modernization initiatives.

Requirements

  • 3-5+ years of experience in PKI engineering, information security, cybersecurity, or infrastructure security.
  • Hands-on experience administering Microsoft Active Directory Certificate Services (AD CS) or similar enterprise PKI solutions.
  • Strong understanding of PKI concepts, certificate lifecycle management, SSL/TLS, X.509 certificates, and cryptographic principles.
  • Experience with certificate enrollment, issuance, renewal, revocation, and validation processes.
  • Knowledge of Hardware Security Modules (HSMs) and cryptographic key management practices.
  • Experience with PowerShell or other scripting and automation tools.
  • Strong troubleshooting, analytical, and technical documentation skills., * Experience with enterprise certificate management platforms such as Venafi, Keyfactor, or DigiCert.
  • Familiarity with cloud-based certificate management services in Azure, AWS, or Google Cloud Platform.
  • Knowledge of Zero Trust security principles and modern authentication technologies.
  • Understanding of security compliance frameworks and risk management practices.
  • Experience supporting large-scale enterprise infrastructure environments., * Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or a related field, or equivalent professional experience.
  • Security certifications such as Security+, CISSP, GSEC, or equivalent preferred.
  • Microsoft security, identity, or cloud certifications are a plus.

Key Skills

  • Public Key Infrastructure (PKI) Administration
  • Certificate Lifecycle Management
  • Cryptography & Key Management
  • SSL/TLS Security
  • Certificate Automation & Governance
  • Security Compliance & Risk Management
  • Technical Documentation
  • Incident Analysis & Troubleshooting
  • PowerShell Scripting & Automation

Additional Information

  • Ability to participate in planned maintenance windows, certificate renewals, and incident response activities as needed.
  • Occasional after-hours support may be required.
  • Experience working in complex enterprise environments is highly preferred.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:10 min

Unlocking free learning credits via Google Cloud Innovators

Asrar Asrar · World Congress 2024

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

4:42 min

Container hosting options available on Google Cloud Platform

Federico Fregosi · World Congress 2022

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

Videos

See all

Related articles

See all