> Markdown version of [/jobs/ext/3137774-pki-security-architect](https://www.wearedevelopers.com/jobs/ext/3137774-pki-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # PKI/Security Architect - **Company:** CASTILLO, REYES, & DEL RIO LAW GROUP, LLC - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Application Integration Architecture, Computing Platforms, Microsoft Azure, Business Software, Cloud Computing, Cyber Security, Databases, Software Design Documents, Linux, Digital Signature, Disaster Recovery, High-Level Architecture, Web Servers, Identity and Access Management, Information Systems Security Architecture Professional, Key Management, Microsoft Security Essentials, Windows Servers, Network Architecture, Public Key Infrastructure, X.509, Windows PowerShell, Cloud Services, Zero Trust Network Access, RSA (Cryptosystem), Runbook, Sherwood Applied Business Security Architecture, Smart Cards, Strategies of Testing, Workflow Management Systems, Enterprise Application Integration, SSL Certificate Management, Transport Layer Security, Enterprise Software Applications, Load Balancing, System Availability, Togaf, Information Technology, CIS Benchmarks, Restful APIs, Vmware - **Published:** September 29, 2026 - **Apply:** https://computerjobs.com/us/en/mob/job/FE70C45A2ABDF47104 ## About the Role Senior PKI Security Architect and Keyfactor SME with extensive experience designing, implementing and delivering enterprise-scale Public Key Infrastructure solutions across complex and highly regulated environments. Strong technical expertise across full central PKI architecture, including offline Root CA, issuing CAs, certificate life cycle management, HSM integration, certificate policy, trust models, automation, monitoring, renewal and revocation. Highly experienced with Keyfactor and associated Certificate Lifecycle Management (CLM) capabilities, supporting organisations through PKI transformation, centralisation, rationalisation and migration programmes. Combines deep technical PKI expertise with strong security architecture and stakeholder-management capabilities, providing the ability to operate effectively across architecture, design, engineering, implementation and technical governance. Experienced working within security-sensitive environments and comfortable engaging with senior architects, security teams, infrastructure teams, application owners and third-party technology providers. SC Cleared, with experience delivering security architecture and PKI programmes within complex enterprise and government/defence environments. Core Expertise Public Key Infrastructure Enterprise PKI architecture and design Centralised PKI architecture Root Certificate Authority architecture Offline Root CA Intermediate/Issuing Certificate Authorities Subordinate CA design Certificate Policy (CP) Certification Practice Statement (CPS) Certificate life cycle management Certificate issuance, renewal and revocation CRL and OCSP architecture Trust hierarchy and trust-store management Certificate discovery and inventory PKI migration and consolidation Legacy PKI rationalisation PKI resilience and disaster recovery Key management and cryptographic controls Keyfactor Keyfactor Certificate Lifecycle Management Keyfactor Command Certificate discovery and inventory Certificate issuance and renewal Automated certificate life cycle management Certificate policy and governance Keyfactor integrations Enterprise application onboarding Certificate automation PKI workflow design Keyfactor API integration Certificate monitoring and alerting Keyfactor platform architecture Migration to centralised CLM Cryptography & Security X.509 certificates RSA/ECC TLS/SSL Digital signatures Encryption and key management HSM technologies Cryptographic key life cycle management Certificate-based authentication mTLS Smart cards/PIV/CAC technologies Cryptographic policy Certificate trust models Crypto-agility Post-Quantum Cryptography considerations Architecture Security Architecture Enterprise Architecture High-Level Design Low-Level Design Technical Architecture Security Architecture Principles Architecture governance Threat modelling Security risk assessment Technology standards Integration architecture Cloud and hybrid architecture Identity and access management, Extensive experience supporting Keyfactor CLM implementations, including: Keyfactor platform architecture Enterprise certificate discovery Certificate inventory and classification Certificate ownership models Certificate life cycle workflows Automated certificate issuance Automated renewal Certificate revocation CA integration Application onboarding Certificate policy enforcement API integration Monitoring and alerting Certificate expiry management PKI governance Legacy PKI migration Operational handover Particular focus on establishing a single, centrally governed certificate life cycle capability across a complex enterprise environment. PKI Architecture Experience Central PKI Designed centralised PKI services incorporating: Offline Root CA ? Intermediate CA ? Issuing CA ? Keyfactor CLM ? Enterprise Applications/Infrastructure Including appropriate segregation, security controls, trust relationships and operational processes. Certificate Lifecycle Experienced across the complete certificate life cycle: Discovery ? Registration ? Approval ? Issuance ? Deployment ? Monitoring ? Renewal ? Revocation ? Retirement High Availability & Resilience Experience designing resilient PKI environments, including: CA redundancy HSM resilience Key backup and recovery Disaster recovery Certificate database resilience CRL availability OCSP availability Geographic resilience Recovery procedures Business continuity considerations Architecture & Documentation Strong experience producing: High-Level Designs Low-Level Designs Solution Architecture Documents Security Architecture Documents Architecture Decision Records PKI Architecture Diagrams Certificate Policy Certification Practice Statements Technical Specifications Integration Designs Migration Strategies Test Strategies Operational Runbooks Support Models Technical Risk Assessments Security & Compliance Experienced working within highly regulated and security-sensitive environments, with strong understanding of: ISO 27001 NIST Cybersecurity Framework CIS Controls Security architecture principles Zero Trust principles Cryptographic standards Certificate security Key management Secure system design Risk management Security governance Data protection Operational resilience Technical Environment PKI/CLM Keyfactor Microsoft AD CS Enterprise PKI X.509 Certificate Authorities, mTLS Digital certificates HSM Key management Digital signatures Infrastructure Microsoft Windows Server Active Directory Linux VMware Network infrastructure Load balancers Web infrastructure Enterprise applications Cloud Microsoft Azure AWS Cloud PKI Cloud certificate management Hybrid PKI architectures Integration REST APIs Automation PowerShell Certificate automation Enterprise application integration, Relevant degree or equivalent professional experience in Cyber Security, Computer Science, Engineering or related discipline. Security Architecture qualifications desirable. PKI/Cryptography certifications desirable. Keyfactor certification/accreditation desirable. CISSP/CISM/SABSA/TOGAF or equivalent desirable. Microsoft security/PKI certifications desirable., The successful candidate must hold UK Security Check (SC) clearance and be able to work on security-sensitive environments. ", "industry": "IT", "baseSalary": {"@type": "MonetaryAmount", "currency": "GBP", "value": {"@type": "QuantitativeValue", "value": "\u00a3550 - \u00a3600 OUTSIDE IR35"}}, "identifier": {"@type": "PropertyValue", "name": "[[BRANDNAME]]", "value": "[[IDENTIFIER]]"}, "datePosted": "2026-09-29T09:06+00:00", "validThrough": "2026-10-13T09:06+00:00", "hiringOrganization": {"@type": "Organization", "name": "Costello & Reyes Group Limited", "logo": "https://cjassets-fabkerfbaaayfhdm.z02.azurefd.net/images/jobbranding/ae601c3a131427bd/images/ae601c3a131427bd_detail.png"}, "jobLocation": {"@type": "Place", "address": {"@type": "PostalAddress", "addressRegion": "Derbyshire", "addressLocality": "Derby", "addressCountry": "United Kingdom"}, "geo": {"@type": "GeoCoordinates", "latitude": "52.915", "longitude": "-1.472"}}, "url" ## Description Provided technical leadership for the design and delivery of a centralised enterprise PKI capability., Acted as the primary Keyfactor technical SME throughout the delivery life cycle. Designed the Keyfactor architecture and integration model supporting enterprise-wide certificate life cycle management. Developed certificate onboarding and migration strategies for business applications, infrastructure and services. Established certificate ownership and life cycle responsibilities across application and infrastructure teams. Designed automated certificate issuance and renewal workflows. Integrated Keyfactor with enterprise technologies and certificate authorities. Conducted discovery of existing certificates and PKI services across a complex technology estate. Identified unmanaged, expired, duplicated and non-compliant certificates. Developed a structured approach to migrating Legacy certificates into the centralised PKI/CLM capability. Defined PKI security controls, operational processes and governance requirements. Worked with security teams to define appropriate certificate policies and standards. Provided technical input into PKI-related risk assessments and security architecture reviews. Produced HLDs, LLDs, architecture diagrams, technical specifications and implementation documentation. Supported technical workshops with infrastructure, application, security and architecture teams. Provided technical guidance to engineering teams during implementation. Supported testing, validation and operational acceptance. Developed technical documentation and knowledge-transfer materials for internal support teams., Designed and implemented enterprise PKI services supporting large-scale business and infrastructure environments. Developed centralised certificate management strategies to replace fragmented application-specific PKI arrangements. Performed detailed assessment of existing certificate authorities and trust relationships. Developed PKI rationalisation and consolidation roadmaps. Designed secure CA hierarchies and certificate trust models. Defined requirements for HSM-backed CA private keys. Developed certificate life cycle management processes covering issuance, renewal, revocation and retirement. Supported integration of PKI with: o Microsoft Active Directory o Active Directory Certificate Services o Windows infrastructure o Linux o Network infrastructure o Load balancers o Web Servers o Databases o Application platforms o Cloud services Developed certificate automation approaches to reduce manual certificate-management activities. Worked with application owners to identify certificate dependencies and renewal requirements. Supported migration from Legacy certificate-management approaches to centrally governed services. Developed operational procedures covering certificate incidents, compromised keys and certificate expiry., Designed and delivered a centralised enterprise PKI architecture across a complex technology estate. Led the technical architecture for Keyfactor Certificate Lifecycle Management implementation. Established enterprise-wide certificate discovery and inventory capability. Developed automated certificate issuance and renewal processes. Supported migration away from fragmented and Legacy certificate-management arrangements. Designed secure CA hierarchies incorporating offline Root CA and HSM-backed key protection. Reduced operational risk associated with unmanaged and expiring certificates through centralised monitoring and life cycle management. Established governance and ownership models for enterprise certificates. Provided technical leadership across security, infrastructure, application and architecture teams.