PKI/Security Architect
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+31 more
Job description
Provided technical leadership for the design and delivery of a centralised enterprise PKI capability., Acted as the primary Keyfactor technical SME throughout the delivery life cycle.
Designed the Keyfactor architecture and integration model supporting enterprise-wide certificate life cycle management.
Developed certificate onboarding and migration strategies for business applications, infrastructure and services.
Established certificate ownership and life cycle responsibilities across application and infrastructure teams.
Designed automated certificate issuance and renewal workflows.
Integrated Keyfactor with enterprise technologies and certificate authorities.
Conducted discovery of existing certificates and PKI services across a complex technology estate.
Identified unmanaged, expired, duplicated and non-compliant certificates.
Developed a structured approach to migrating Legacy certificates into the centralised PKI/CLM capability.
Defined PKI security controls, operational processes and governance requirements.
Worked with security teams to define appropriate certificate policies and standards.
Provided technical input into PKI-related risk assessments and security architecture reviews.
Produced HLDs, LLDs, architecture diagrams, technical specifications and implementation documentation.
Supported technical workshops with infrastructure, application, security and architecture teams.
Provided technical guidance to engineering teams during implementation.
Supported testing, validation and operational acceptance.
Developed technical documentation and knowledge-transfer materials for internal support teams., Designed and implemented enterprise PKI services supporting large-scale business and infrastructure environments.
Developed centralised certificate management strategies to replace fragmented application-specific PKI arrangements.
Performed detailed assessment of existing certificate authorities and trust relationships.
Developed PKI rationalisation and consolidation roadmaps.
Designed secure CA hierarchies and certificate trust models.
Defined requirements for HSM-backed CA private keys.
Developed certificate life cycle management processes covering issuance, renewal, revocation and retirement.
Supported integration of PKI with:
o Microsoft Active Directory
o Active Directory Certificate Services
o Windows infrastructure
o Linux
o Network infrastructure
o Load balancers
o Web Servers
o Databases
o Application platforms
o Cloud services
Developed certificate automation approaches to reduce manual certificate-management activities.
Worked with application owners to identify certificate dependencies and renewal requirements.
Supported migration from Legacy certificate-management approaches to centrally governed services.
Developed operational procedures covering certificate incidents, compromised keys and certificate expiry., Designed and delivered a centralised enterprise PKI architecture across a complex technology estate.
Led the technical architecture for Keyfactor Certificate Lifecycle Management implementation.
Established enterprise-wide certificate discovery and inventory capability.
Developed automated certificate issuance and renewal processes.
Supported migration away from fragmented and Legacy certificate-management arrangements.
Designed secure CA hierarchies incorporating offline Root CA and HSM-backed key protection.
Reduced operational risk associated with unmanaged and expiring certificates through centralised monitoring and life cycle management.
Established governance and ownership models for enterprise certificates.
Provided technical leadership across security, infrastructure, application and architecture teams.
Requirements
Senior PKI Security Architect and Keyfactor SME with extensive experience designing, implementing and delivering enterprise-scale Public Key Infrastructure solutions across complex and highly regulated environments.
Strong technical expertise across full central PKI architecture, including offline Root CA, issuing CAs, certificate life cycle management, HSM integration, certificate policy, trust models, automation, monitoring, renewal and revocation.
Highly experienced with Keyfactor and associated Certificate Lifecycle Management (CLM) capabilities, supporting organisations through PKI transformation, centralisation, rationalisation and migration programmes.
Combines deep technical PKI expertise with strong security architecture and stakeholder-management capabilities, providing the ability to operate effectively across architecture, design, engineering, implementation and technical governance.
Experienced working within security-sensitive environments and comfortable engaging with senior architects, security teams, infrastructure teams, application owners and third-party technology providers.
SC Cleared, with experience delivering security architecture and PKI programmes within complex enterprise and government/defence environments.
Core Expertise
Public Key Infrastructure
Enterprise PKI architecture and design
Centralised PKI architecture
Root Certificate Authority architecture
Offline Root CA
Intermediate/Issuing Certificate Authorities
Subordinate CA design
Certificate Policy (CP)
Certification Practice Statement (CPS)
Certificate life cycle management
Certificate issuance, renewal and revocation
CRL and OCSP architecture
Trust hierarchy and trust-store management
Certificate discovery and inventory
PKI migration and consolidation
Legacy PKI rationalisation
PKI resilience and disaster recovery
Key management and cryptographic controls
Keyfactor
Keyfactor Certificate Lifecycle Management
Keyfactor Command
Certificate discovery and inventory
Certificate issuance and renewal
Automated certificate life cycle management
Certificate policy and governance
Keyfactor integrations
Enterprise application onboarding
Certificate automation
PKI workflow design
Keyfactor API integration
Certificate monitoring and alerting
Keyfactor platform architecture
Migration to centralised CLM
Cryptography & Security
X.509 certificates
RSA/ECC
TLS/SSL
Digital signatures
Encryption and key management
HSM technologies
Cryptographic key life cycle management
Certificate-based authentication
mTLS
Smart cards/PIV/CAC technologies
Cryptographic policy
Certificate trust models
Crypto-agility
Post-Quantum Cryptography considerations
Architecture
Security Architecture
Enterprise Architecture
High-Level Design
Low-Level Design
Technical Architecture
Security Architecture Principles
Architecture governance
Threat modelling
Security risk assessment
Technology standards
Integration architecture
Cloud and hybrid architecture
Identity and access management, Extensive experience supporting Keyfactor CLM implementations, including:
Keyfactor platform architecture
Enterprise certificate discovery
Certificate inventory and classification
Certificate ownership models
Certificate life cycle workflows
Automated certificate issuance
Automated renewal
Certificate revocation
CA integration
Application onboarding
Certificate policy enforcement
API integration
Monitoring and alerting
Certificate expiry management
PKI governance
Legacy PKI migration
Operational handover
Particular focus on establishing a single, centrally governed certificate life cycle capability across a complex enterprise environment.
PKI Architecture Experience
Central PKI
Designed centralised PKI services incorporating:
Offline Root CA ? Intermediate CA ? Issuing CA ? Keyfactor CLM ? Enterprise Applications/Infrastructure
Including appropriate segregation, security controls, trust relationships and operational processes.
Certificate Lifecycle
Experienced across the complete certificate life cycle:
Discovery ? Registration ? Approval ? Issuance ? Deployment ? Monitoring ? Renewal ? Revocation ? Retirement
High Availability & Resilience
Experience designing resilient PKI environments, including:
CA redundancy
HSM resilience
Key backup and recovery
Disaster recovery
Certificate database resilience
CRL availability
OCSP availability
Geographic resilience
Recovery procedures
Business continuity considerations
Architecture & Documentation
Strong experience producing:
High-Level Designs
Low-Level Designs
Solution Architecture Documents
Security Architecture Documents
Architecture Decision Records
PKI Architecture Diagrams
Certificate Policy
Certification Practice Statements
Technical Specifications
Integration Designs
Migration Strategies
Test Strategies
Operational Runbooks
Support Models
Technical Risk Assessments
Security & Compliance
Experienced working within highly regulated and security-sensitive environments, with strong understanding of:
ISO 27001
NIST Cybersecurity Framework
CIS Controls
Security architecture principles
Zero Trust principles
Cryptographic standards
Certificate security
Key management
Secure system design
Risk management
Security governance
Data protection
Operational resilience
Technical Environment
PKI/CLM
Keyfactor
Microsoft AD CS
Enterprise PKI
X.509
Certificate Authorities, mTLS
Digital certificates
HSM
Key management
Digital signatures
Infrastructure
Microsoft Windows Server
Active Directory
Linux
VMware
Network infrastructure
Load balancers
Web infrastructure
Enterprise applications
Cloud
Microsoft Azure
AWS
Cloud PKI
Cloud certificate management
Hybrid PKI architectures
Integration
REST APIs
Automation
PowerShell
Certificate automation
Enterprise application integration, Relevant degree or equivalent professional experience in Cyber Security, Computer Science, Engineering or related discipline.
Security Architecture qualifications desirable.
PKI/Cryptography certifications desirable.
Keyfactor certification/accreditation desirable.
CISSP/CISM/SABSA/TOGAF or equivalent desirable.
Microsoft security/PKI certifications desirable., The successful candidate must hold UK Security Check (SC) clearance and be able to work on security-sensitive environments. “, “industry”: “IT”, “baseSalary”: {“@type”: “MonetaryAmount”, “currency”: “GBP”, “value”: {“@type”: “QuantitativeValue”, “value”: “\u00a3550 - \u00a3600 OUTSIDE IR35”}}, “identifier”: {“@type”: “PropertyValue”, “name”: “[[BRANDNAME]]”, “value”: “[[IDENTIFIER]]”}, “datePosted”: “2026-09-29T09:06+00:00”, “validThrough”: “2026-10-13T09:06+00:00”, “hiringOrganization”: {“@type”: “Organization”, “name”: “Costello & Reyes Group Limited”, “logo”: “https://cjassets-fabkerfbaaayfhdm.z02.azurefd.net/images/jobbranding/ae601c3a131427bd/images/ae601c3a131427bd_detail.png”}, “jobLocation”: {“@type”: “Place”, “address”: {“@type”: “PostalAddress”, “addressRegion”: “Derbyshire”, “addressLocality”: “Derby”, “addressCountry”: “United Kingdom”}, “geo”: {“@type”: “GeoCoordinates”, “latitude”: “52.915”, “longitude”: “-1.472”}}, “url”
About the company
Costello & Reyes Group Limited has been engaged by its client, a global defence contractor, to identify a Senior PKI Security Architect for an initial 6 month engagement.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Loading talks and stories from around this role…