PKI/Security Architect

CASTILLO, REYES, & DEL RIO LAW GROUP, LLC
United States
8 days ago
Apply on computerjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Microsoft Windows Active Directory Application Integration Architecture Computing Platforms Microsoft Azure Business Software Cloud Computing Cyber Security Databases Software Design Documents Linux Digital Signature
+31 more
Disaster Recovery High-Level Architecture Web Servers Identity and Access Management Information Systems Security Architecture Professional Key Management Microsoft Security Essentials Windows Servers Network Architecture Public Key Infrastructure X.509 Windows PowerShell Cloud Services Zero Trust Network Access RSA (Cryptosystem) Runbook Sherwood Applied Business Security Architecture Smart Cards Strategies of Testing Workflow Management Systems Enterprise Application Integration SSL Certificate Management Transport Layer Security Enterprise Software Applications Load Balancing System Availability Togaf Information Technology CIS Benchmarks Restful APIs Vmware

Job description

Provided technical leadership for the design and delivery of a centralised enterprise PKI capability., Acted as the primary Keyfactor technical SME throughout the delivery life cycle.

Designed the Keyfactor architecture and integration model supporting enterprise-wide certificate life cycle management.

Developed certificate onboarding and migration strategies for business applications, infrastructure and services.

Established certificate ownership and life cycle responsibilities across application and infrastructure teams.

Designed automated certificate issuance and renewal workflows.

Integrated Keyfactor with enterprise technologies and certificate authorities.

Conducted discovery of existing certificates and PKI services across a complex technology estate.

Identified unmanaged, expired, duplicated and non-compliant certificates.

Developed a structured approach to migrating Legacy certificates into the centralised PKI/CLM capability.

Defined PKI security controls, operational processes and governance requirements.

Worked with security teams to define appropriate certificate policies and standards.

Provided technical input into PKI-related risk assessments and security architecture reviews.

Produced HLDs, LLDs, architecture diagrams, technical specifications and implementation documentation.

Supported technical workshops with infrastructure, application, security and architecture teams.

Provided technical guidance to engineering teams during implementation.

Supported testing, validation and operational acceptance.

Developed technical documentation and knowledge-transfer materials for internal support teams., Designed and implemented enterprise PKI services supporting large-scale business and infrastructure environments.

Developed centralised certificate management strategies to replace fragmented application-specific PKI arrangements.

Performed detailed assessment of existing certificate authorities and trust relationships.

Developed PKI rationalisation and consolidation roadmaps.

Designed secure CA hierarchies and certificate trust models.

Defined requirements for HSM-backed CA private keys.

Developed certificate life cycle management processes covering issuance, renewal, revocation and retirement.

Supported integration of PKI with:

o Microsoft Active Directory

o Active Directory Certificate Services

o Windows infrastructure

o Linux

o Network infrastructure

o Load balancers

o Web Servers

o Databases

o Application platforms

o Cloud services

Developed certificate automation approaches to reduce manual certificate-management activities.

Worked with application owners to identify certificate dependencies and renewal requirements.

Supported migration from Legacy certificate-management approaches to centrally governed services.

Developed operational procedures covering certificate incidents, compromised keys and certificate expiry., Designed and delivered a centralised enterprise PKI architecture across a complex technology estate.

Led the technical architecture for Keyfactor Certificate Lifecycle Management implementation.

Established enterprise-wide certificate discovery and inventory capability.

Developed automated certificate issuance and renewal processes.

Supported migration away from fragmented and Legacy certificate-management arrangements.

Designed secure CA hierarchies incorporating offline Root CA and HSM-backed key protection.

Reduced operational risk associated with unmanaged and expiring certificates through centralised monitoring and life cycle management.

Established governance and ownership models for enterprise certificates.

Provided technical leadership across security, infrastructure, application and architecture teams.

Requirements

Senior PKI Security Architect and Keyfactor SME with extensive experience designing, implementing and delivering enterprise-scale Public Key Infrastructure solutions across complex and highly regulated environments.

Strong technical expertise across full central PKI architecture, including offline Root CA, issuing CAs, certificate life cycle management, HSM integration, certificate policy, trust models, automation, monitoring, renewal and revocation.

Highly experienced with Keyfactor and associated Certificate Lifecycle Management (CLM) capabilities, supporting organisations through PKI transformation, centralisation, rationalisation and migration programmes.

Combines deep technical PKI expertise with strong security architecture and stakeholder-management capabilities, providing the ability to operate effectively across architecture, design, engineering, implementation and technical governance.

Experienced working within security-sensitive environments and comfortable engaging with senior architects, security teams, infrastructure teams, application owners and third-party technology providers.

SC Cleared, with experience delivering security architecture and PKI programmes within complex enterprise and government/defence environments.

Core Expertise

Public Key Infrastructure

Enterprise PKI architecture and design

Centralised PKI architecture

Root Certificate Authority architecture

Offline Root CA

Intermediate/Issuing Certificate Authorities

Subordinate CA design

Certificate Policy (CP)

Certification Practice Statement (CPS)

Certificate life cycle management

Certificate issuance, renewal and revocation

CRL and OCSP architecture

Trust hierarchy and trust-store management

Certificate discovery and inventory

PKI migration and consolidation

Legacy PKI rationalisation

PKI resilience and disaster recovery

Key management and cryptographic controls

Keyfactor

Keyfactor Certificate Lifecycle Management

Keyfactor Command

Certificate discovery and inventory

Certificate issuance and renewal

Automated certificate life cycle management

Certificate policy and governance

Keyfactor integrations

Enterprise application onboarding

Certificate automation

PKI workflow design

Keyfactor API integration

Certificate monitoring and alerting

Keyfactor platform architecture

Migration to centralised CLM

Cryptography & Security

X.509 certificates

RSA/ECC

TLS/SSL

Digital signatures

Encryption and key management

HSM technologies

Cryptographic key life cycle management

Certificate-based authentication

mTLS

Smart cards/PIV/CAC technologies

Cryptographic policy

Certificate trust models

Crypto-agility

Post-Quantum Cryptography considerations

Architecture

Security Architecture

Enterprise Architecture

High-Level Design

Low-Level Design

Technical Architecture

Security Architecture Principles

Architecture governance

Threat modelling

Security risk assessment

Technology standards

Integration architecture

Cloud and hybrid architecture

Identity and access management, Extensive experience supporting Keyfactor CLM implementations, including:

Keyfactor platform architecture

Enterprise certificate discovery

Certificate inventory and classification

Certificate ownership models

Certificate life cycle workflows

Automated certificate issuance

Automated renewal

Certificate revocation

CA integration

Application onboarding

Certificate policy enforcement

API integration

Monitoring and alerting

Certificate expiry management

PKI governance

Legacy PKI migration

Operational handover

Particular focus on establishing a single, centrally governed certificate life cycle capability across a complex enterprise environment.

PKI Architecture Experience

Central PKI

Designed centralised PKI services incorporating:

Offline Root CA ? Intermediate CA ? Issuing CA ? Keyfactor CLM ? Enterprise Applications/Infrastructure

Including appropriate segregation, security controls, trust relationships and operational processes.

Certificate Lifecycle

Experienced across the complete certificate life cycle:

Discovery ? Registration ? Approval ? Issuance ? Deployment ? Monitoring ? Renewal ? Revocation ? Retirement

High Availability & Resilience

Experience designing resilient PKI environments, including:

CA redundancy

HSM resilience

Key backup and recovery

Disaster recovery

Certificate database resilience

CRL availability

OCSP availability

Geographic resilience

Recovery procedures

Business continuity considerations

Architecture & Documentation

Strong experience producing:

High-Level Designs

Low-Level Designs

Solution Architecture Documents

Security Architecture Documents

Architecture Decision Records

PKI Architecture Diagrams

Certificate Policy

Certification Practice Statements

Technical Specifications

Integration Designs

Migration Strategies

Test Strategies

Operational Runbooks

Support Models

Technical Risk Assessments

Security & Compliance

Experienced working within highly regulated and security-sensitive environments, with strong understanding of:

ISO 27001

NIST Cybersecurity Framework

CIS Controls

Security architecture principles

Zero Trust principles

Cryptographic standards

Certificate security

Key management

Secure system design

Risk management

Security governance

Data protection

Operational resilience

Technical Environment

PKI/CLM

Keyfactor

Microsoft AD CS

Enterprise PKI

X.509

Certificate Authorities, mTLS

Digital certificates

HSM

Key management

Digital signatures

Infrastructure

Microsoft Windows Server

Active Directory

Linux

VMware

Network infrastructure

Load balancers

Web infrastructure

Enterprise applications

Cloud

Microsoft Azure

AWS

Cloud PKI

Cloud certificate management

Hybrid PKI architectures

Integration

REST APIs

Automation

PowerShell

Certificate automation

Enterprise application integration, Relevant degree or equivalent professional experience in Cyber Security, Computer Science, Engineering or related discipline.

Security Architecture qualifications desirable.

PKI/Cryptography certifications desirable.

Keyfactor certification/accreditation desirable.

CISSP/CISM/SABSA/TOGAF or equivalent desirable.

Microsoft security/PKI certifications desirable., The successful candidate must hold UK Security Check (SC) clearance and be able to work on security-sensitive environments. “, “industry”: “IT”, “baseSalary”: {“@type”: “MonetaryAmount”, “currency”: “GBP”, “value”: {“@type”: “QuantitativeValue”, “value”: “\u00a3550 - \u00a3600 OUTSIDE IR35”}}, “identifier”: {“@type”: “PropertyValue”, “name”: “[[BRANDNAME]]”, “value”: “[[IDENTIFIER]]”}, “datePosted”: “2026-09-29T09:06+00:00”, “validThrough”: “2026-10-13T09:06+00:00”, “hiringOrganization”: {“@type”: “Organization”, “name”: “Costello & Reyes Group Limited”, “logo”: “https://cjassets-fabkerfbaaayfhdm.z02.azurefd.net/images/jobbranding/ae601c3a131427bd/images/ae601c3a131427bd_detail.png”}, “jobLocation”: {“@type”: “Place”, “address”: {“@type”: “PostalAddress”, “addressRegion”: “Derbyshire”, “addressLocality”: “Derby”, “addressCountry”: “United Kingdom”}, “geo”: {“@type”: “GeoCoordinates”, “latitude”: “52.915”, “longitude”: “-1.472”}}, “url”

About the company

Costello & Reyes Group Limited has been engaged by its client, a global defence contractor, to identify a Senior PKI Security Architect for an initial 6 month engagement.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on computerjobs.com
Prepare application

Good distractions

Loading talks and stories from around this role…