PKI / Certificate Management Engineer (R-00198)

5 hours, 17 minutes ago
Full-time
Senior
DevOps and Infrastructure
True Zero Technologies

True Zero Technologies

True Zero Technologies specializes in cybersecurity programs and software solutions, focusing on proactive defense and IT engineering services.

Internet Software & Services
11-50
Founded 2016

Description

  • Design, implement, and maintain enterprise Public Key Infrastructure supporting internal and external certificate requirements.
  • Manage the full certificate lifecycle, including request, issuance, validation, distribution, renewal, revocation, expiration, and retirement.
  • Implement ACME-based certificate automation and other automated enrollment and renewal workflows.
  • Manage certificates across Windows, Linux, cloud platforms, containers, applications, load balancers, network devices, and other enterprise systems.
  • Design and operate integrations with AWS Private CA, AWS Certificate Manager, and related AWS services.
  • Implement and administer Hardware Security Module capabilities, including AWS CloudHSM, for secure key protection and cryptographic operations.
  • Support Federal PKI and DoD PKI trust relationships, certificate chains, and interoperability requirements.
  • Integrate CAC/PIV authentication with enterprise applications, identity platforms, operating systems, and secure access workflows.
  • Implement and maintain mutual TLS for workload identity, service-to-service authentication, and Zero Trust communications.
  • Establish certificate discovery, inventory, monitoring, and alerting capabilities to prevent unmanaged certificates and expiration-related outages.
  • Develop governance standards for certificate ownership, issuance, naming, key length, cryptographic algorithms, renewal periods, revocation, and retention.
  • Troubleshoot certificate-chain, trust-store, TLS, cryptographic, enrollment, renewal, and authentication issues.
  • Partner with cybersecurity, identity, cloud, platform, network, and application teams to integrate PKI services into enterprise architectures and deployment workflows.
  • Maintain PKI architecture documentation, operational procedures, runbooks, governance standards, and audit evidence.

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related technical discipline.
  • Demonstrated experience designing, implementing, or administering enterprise Public Key Infrastructure (PKI).
  • Strong knowledge of X.509 certificates, certificate authorities, trust chains, cryptographic algorithms, key management, revocation, and certificate lifecycle management.
  • Experience implementing automated certificate issuance and renewal using ACME or comparable certificate automation technologies.
  • Experience managing certificates across Windows, Linux, cloud, containerized, network, and application environments.
  • Hands-on experience with AWS Private CA, AWS Certificate Manager, AWS CloudHSM, or comparable cloud PKI and HSM technologies.
  • Strong understanding of cryptography, encryption, digital signatures, hashing, key exchange, and secure communications.
  • Experience integrating PKI with IAM, directory services, applications, network infrastructure, and cloud services.
  • Familiarity with Federal PKI, DoD PKI, CAC/PIV authentication, and government certificate trust models.
  • Experience implementing mTLS and certificate-based workload identity in Zero Trust architectures.
  • Familiarity with FIPS-validated cryptography and cryptographic requirements for government or regulated environments.
  • Experience with certificate discovery, inventory management, expiration monitoring, and proactive renewal processes.
  • Strong understanding of TLS configuration, secure networking, trust stores, certificate validation, and PKI troubleshooting.
  • Experience supporting AWS GovCloud, government, defense, or other regulated environments is preferred.
  • Strong governance, risk management, documentation, troubleshooting, and cross-functional collaboration skills.
  • AWS Certified Security – Specialty is preferred.
  • Microsoft Certified: Cybersecurity Architect Expert (SC-100) is preferred.
  • Red Hat Certified Engineer (RHCE) is preferred.
  • Microsoft Certified: Windows Server Hybrid Administrator Associate is preferred.
  • Entrust or DigiCert PKI certifications, where applicable, are preferred.

Benefits

  • Competitive salary paid twice per month.
  • Best-in-class medical coverage.
  • 100% of medical premiums covered by True Zero.
  • Company-wide new business incentive programs.
  • Contribution incentives for white papers, blog posts, and internal webinars.
  • 3 weeks of PTO starting plus 11 paid holidays annually.
  • 401(k) program with 100% company match on the first 4%.
  • Monthly reimbursement of cell phone and home internet costs.
  • Paternity/maternity leave.
  • Investment in training and certifications.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Lead Traveling Security Technician

Unlimited Technology 51-250 Professional Services

Unlimited Technology is hiring a Traveling Security Technician for UT Government to install, service, test, and inspect access control and IP camera systems for customers across the U.S.

5 hours, 17 minutes ago

Staff Vulnerability Management Engineer

Chainguard 51-250 Internet Software & Services

Chainguard is hiring a Staff Vulnerability Management Engineer to lead its AI-driven open source vulnerability disclosure and coordination efforts across internal teams, maintainers, and industry stakeholders.

Go Java JavaScript Penetration Testing Python
5 hours, 17 minutes ago

Manager, Design - Systems & Infrastructure

Figma 1K-5K Internet Software & Services

Figma is hiring a Design Manager to lead its internal Design Systems and Design Infrastructure work as the company evolves its product suite and design operations.

Design Systems Figma
5 hours, 17 minutes ago

Staff Vulnerability Management Engineer

Chainguard 51-250 Internet Software & Services

Chainguard is hiring a Staff Vulnerability Management Engineer to lead its AI-era open source vulnerability disclosure and coordination efforts across internal teams, customers, maintainers, and industry bodies.

Go Java JavaScript Penetration Testing Python
5 hours, 17 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers