PKI / Certificate Management Engineer (R-00198)

1 month ago
Full-time
Senior
DevOps and Infrastructure
True Zero Technologies

True Zero Technologies

True Zero Technologies specializes in cybersecurity programs and software solutions, focusing on proactive defense and IT engineering services.

Internet Software & Services
11-50
Founded 2016

Description

  • Design, implement, and maintain enterprise Public Key Infrastructure supporting internal and external certificate requirements.
  • Manage the full certificate lifecycle, including request, issuance, validation, distribution, renewal, revocation, expiration, and retirement.
  • Implement ACME-based certificate automation and other automated enrollment and renewal workflows.
  • Manage certificates across Windows, Linux, cloud platforms, containers, applications, load balancers, network devices, and other enterprise systems.
  • Design and operate integrations with AWS Private CA, AWS Certificate Manager, and related AWS services.
  • Implement and administer Hardware Security Module capabilities, including AWS CloudHSM, for secure key protection and cryptographic operations.
  • Support Federal PKI and DoD PKI trust relationships, certificate chains, and interoperability requirements.
  • Integrate CAC/PIV authentication with enterprise applications, identity platforms, operating systems, and secure access workflows.
  • Implement and maintain mutual TLS for workload identity, service-to-service authentication, and Zero Trust communications.
  • Establish certificate discovery, inventory, monitoring, and alerting capabilities to prevent unmanaged certificates and expiration-related outages.
  • Develop governance standards for certificate ownership, issuance, naming, key length, cryptographic algorithms, renewal periods, revocation, and retention.
  • Troubleshoot certificate-chain, trust-store, TLS, cryptographic, enrollment, renewal, and authentication issues.
  • Partner with cybersecurity, identity, cloud, platform, network, and application teams to integrate PKI services into enterprise architectures and deployment workflows.
  • Maintain PKI architecture documentation, operational procedures, runbooks, governance standards, and audit evidence.

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related technical discipline.
  • Demonstrated experience designing, implementing, or administering enterprise Public Key Infrastructure (PKI).
  • Strong knowledge of X.509 certificates, certificate authorities, trust chains, cryptographic algorithms, key management, revocation, and certificate lifecycle management.
  • Experience implementing automated certificate issuance and renewal using ACME or comparable certificate automation technologies.
  • Experience managing certificates across Windows, Linux, cloud, containerized, network, and application environments.
  • Hands-on experience with AWS Private CA, AWS Certificate Manager, AWS CloudHSM, or comparable cloud PKI and HSM technologies.
  • Strong understanding of cryptography, encryption, digital signatures, hashing, key exchange, and secure communications.
  • Experience integrating PKI with IAM, directory services, applications, network infrastructure, and cloud services.
  • Familiarity with Federal PKI, DoD PKI, CAC/PIV authentication, and government certificate trust models.
  • Experience implementing mTLS and certificate-based workload identity in Zero Trust architectures.
  • Familiarity with FIPS-validated cryptography and cryptographic requirements for government or regulated environments.
  • Experience with certificate discovery, inventory management, expiration monitoring, and proactive renewal processes.
  • Strong understanding of TLS configuration, secure networking, trust stores, certificate validation, and PKI troubleshooting.
  • Experience supporting AWS GovCloud, government, defense, or other regulated environments is preferred.
  • Strong governance, risk management, documentation, troubleshooting, and cross-functional collaboration skills.
  • AWS Certified Security – Specialty is preferred.
  • Microsoft Certified: Cybersecurity Architect Expert (SC-100) is preferred.
  • Red Hat Certified Engineer (RHCE) is preferred.
  • Microsoft Certified: Windows Server Hybrid Administrator Associate is preferred.
  • Entrust or DigiCert PKI certifications, where applicable, are preferred.

Benefits

  • Competitive salary paid twice per month.
  • Best-in-class medical coverage.
  • 100% of medical premiums covered by True Zero.
  • Company-wide new business incentive programs.
  • Contribution incentives for white papers, blog posts, and internal webinars.
  • 3 weeks of PTO starting plus 11 paid holidays annually.
  • 401(k) program with 100% company match on the first 4%.
  • Monthly reimbursement of cell phone and home internet costs.
  • Paternity/maternity leave.
  • Investment in training and certifications.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Insider Risk Security Engineer

Zscaler 1K-5K Internet Software & Services

Zscaler is hiring a remote U.S. Insider Risk Security Engineer to strengthen its Enterprise Security insider-risk program through investigations, detection engineering, playbook development, and stakeholder engagement.

JavaScript Python SIEM
8 hours, 17 minutes ago

Senior Director, Security Engineering

Iterable 251-1K Media

Iterable is hiring a Senior Director, Security Engineering to lead its global security organization and technical security portfolio, strengthening product, platform, application, detection, and response capabilities while advancing an AI-forward security strategy.

8 hours, 32 minutes ago

Staff Cloud Architect L4

Robots & Pencils 51-250 IT Services

Robots & Pencils is seeking a Staff Cloud Architect for a six-month contract to lead end-to-end architecture and delivery of complex cloud, data, and AI/ML systems for enterprise client engagements.

Apache Airflow Apache Spark AWS Azure CI/CD dbt Docker GitHub Actions HIPAA Hugging Face Kafka Kubernetes Machine Learning Microservices MLflow MLOps MongoDB PostgreSQL Prefect Pulumi Python PyTorch Serverless Snowflake TensorFlow Terraform Vertex AI
8 hours, 47 minutes ago

Senior Security Engineer

Garner Health Specialized Consumer Services

Garner Health is hiring a Senior Security Engineer to protect patient data by securing cloud infrastructure, applications, systems, and databases while helping embed security across its healthcare platform.

AWS CrowdStrike Kubernetes Network Security Python REST API Terraform
8 hours, 47 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers