> Markdown version of [/jobs/ext/3332163-senior-software-engineer-pki-cryptographic-systems](https://www.wearedevelopers.com/jobs/ext/3332163-senior-software-engineer-pki-cryptographic-systems). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Software Engineer, PKI & Cryptographic Systems - **Company:** CloudFlare - **Location:** London, UK - **Experience:** Expert - **Salary:** £66,000.0 - £83,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, C++ (Programming Language), Data Centers, Distributed Systems, Federal Information Processing Standards (FIPS), Fuzz Testing, Hardware Security Module, Network Security, PostgreSQL, OpenSSL, Public Key Infrastructure, X.509, System Programming, Data Logging, Build Management, Kubernetes, Hashicorp, Cloudflare, Formal Methods - **Published:** September 29, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=ea21c2a6e42600e6 ## About the Role * 5+ years of production systems software experience, with a strong operational track record - you have carried a pager for something people depend on. * Deep working knowledge of applied cryptography and PKI. X.509, ASN.1/DER, RFC 5280, CRL distribution, Certificate Transparency, ACME, and the CA/Browser Forum Baseline Requirements. You do not need to be a cryptographer, but you need to reason precisely about certificate profiles, key parameters, and issuance policy. * Familiarity with HSMs. PKCS#11 integration, key ceremonies, key-attestation flows, and understanding of what FIPS 140-2/3 validation actually means in production. * Strong systems programming background in at least one of Go, Rust, or C/C++. * Distributed systems fluency - you have built or operated globally replicated, availability-critical services with strict correctness guarantees. * Experience designing and operating database schemas for high-integrity systems (Postgres or equivalent). * Security-hardened system design instincts - threat modelling, defence in depth, least privilege, and secure key handling. * Comfort with high-consequence work. A mis-issued or mis-revoked certificate is a public, industry-visible event. You need the temperament to move quickly and the discipline to be careful., * Direct experience working on or with a publicly-trusted or private CA, or a large-scale internal PKI (Let's Encrypt / Boulder, Google Trust Services, DigiCert, Sectigo, ISRG, Entrust, Microsoft PKI, HashiCorp Vault PKI, step-ca, CFSSL, or an internal CA at scale). * Experience with crypto/x509, BoringSSL, OpenSSL/AWS-LC, CFSSL, or an equivalent PKI codebase. * Experience with WebTrust for CAs / WebTrust BR / WebTrust Network Security audit engagements. * Familiarity with post-quantum cryptography - ML-DSA, ML-KEM, hybrid signature schemes, and the current state of PQ signature standardisation. * Familiarity with emerging browser trust-establishment proposals (e.g. Merkle Tree Certificates). * Prior participation in the CA/Browser Forum, IETF LAMPS / TLS / PLANTS / PQUIP working groups, the transparency.dev community, or a browser root program review. * Experience running or automating offline key ceremonies. * Experience operating Certificate Transparency log infrastructure or CT monitoring at scale. * Familiarity with formal methods, differential fuzzing, or property-based testing for cryptographic protocol code. * Kubernetes experience. ## Description At Cloudflare, we're not looking for people who wait for a polished roadmap; we're looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with. We value candidates who have the instinct to spot a "normalized" problem and the AI-native curiosity to create a solution using the latest tools. Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up. If you're the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you'll fit right in., We are investing in the next generation of Cloudflare's PKI and cryptographic infrastructure to keep up with, and stay ahead of, that shift. As a Senior Software Engineer on this team, you will design and build the systems that manage certificate lifecycles, protect and use private keys at scale, integrate with hardware security modules, automate issuance and renewal, and take Cloudflare's cryptographic stack into the post-quantum era. You will work at the intersection of applied cryptography, distributed systems, and security engineering - on infrastructure that a large fraction of the Internet quietly depends on., * Design and build core PKI systems - certificate lifecycle management, X.509 issuance and validation logic, key parameter enforcement, and policy engines aligned with industry standards including CA/Browser Forum guidance and browser root program policies. * Own the cryptographic core. Integrate with FIPS 140-2 Level 3 (and, where required, Level 4) HSMs via PKCS#11 and vendor-native SDKs; build key ceremony and key-lifecycle tooling; enforce strict key-usage boundaries in code. * Automate at scale. Build and evolve ACME-based issuance and renewal pipelines, short-lived certificate rotation, and revocation mechanisms that serve at Cloudflare's global scale. * Instrument transparency and audit trails. Integrate with Certificate Transparency, build append-only tamper-evident logging, and design evidence pipelines that hold up to rigorous third-party audit. * Maintain accreditation and respond to a changing compliance landscape. PKI operations must maintain compliance under CA/B Forum, WebTrust, and root store program frameworks. You will be aware of, and adapt to, changes in relevant policies, participate in public incident disclosure and discourse, and participate in regular third-party audits. * Represent Cloudflare in the WebPKI community. Write public CA incident reports and serve as a primary contact with the WebPKI community; clear technical writing is core to this role. * Ship the post-quantum future. Contribute to Cloudflare's ongoing post-quantum migration - including work on post-quantum encryption and authentication - so that Cloudflare's cryptographic infrastructure stays ahead of the transition. * Own code end-to-end from design through production incident response. Cryptographic infrastructure cannot silently fail; you will build the observability, runbooks, and on-call posture that keep the service inside SLO. * Partner across the org - with the SSL/TLS product teams, the HSM and data-centre infrastructure teams, the Cloudflare Research applied cryptography group, and adjacent product teams that consume PKI as a platform. * Raise the bar. Mentor other engineers joining an early-stage team, run design reviews, and establish the engineering standards, threat models, and secure-development practices this team will operate under for years.