Senior Public Key Infrastructure - PKI Engineer

Vervic

  • Fairfax, Virginia
  • 13 days ago
    Want to know if you’re a fit?
    Upload your resume and let our AI show you.

    Skills

    • Amazon Web Services (AWS)unmatched
    • Ansibleunmatched
    • Application Programming Interface (API)unmatched
    • Atlassian JIRAunmatched
    • Authenticationunmatched
    • Automationunmatched
    • Bash Scriptingunmatched
    • Best Practicesunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Certificate Authoritiesunmatched
    • Certificate Issuanceunmatched
    • Cloud Computingunmatched
    • Communication Skillsunmatched
    • CompTIA Security+unmatched
    • Computer Scienceunmatched
    • Continuous Deployment/Deliveryunmatched
    • Continuous Integrationunmatched
    • Cryptographyunmatched
    • Cryptography Algorithmsunmatched
    • Defense Information Systems Agency (DISA)unmatched
    • Digital Certificatesunmatched
    • DoD Directive 8140unmatched
    • DoD Directive 8570unmatched
    • Enterprise Architectureunmatched
    • Enterprise Protectionunmatched
    • FISMA - Federal Information Security Management Actunmatched
    • Federal Information Processing Standards (FIPS)unmatched
    • GIAC - Global Information Assurance Certificationunmatched
    • Governmentunmatched
    • Human Capitalunmatched
    • Human Resourcesunmatched
    • IAT - Information Assurance Technicalunmatched
    • Identify Issuesunmatched
    • Identity Data Managementunmatched
    • Incident Responseunmatched
    • Information Technology & Information Systemsunmatched
    • Internet Securityunmatched
    • Interpersonal Skillsunmatched
    • Linux Administrationunmatched
    • Microsoft Access Databaseunmatched
    • Microsoft Active Directoryunmatched
    • Microsoft Certificationsunmatched
    • Microsoft Product Familyunmatched
    • Microsoft Windows Azureunmatched
    • Microsoft Windows Serverunmatched
    • Network Systemsunmatched
    • Operations Security (OPSEC)unmatched
    • Presentation/Verbal Skillsunmatched
    • Problem Solving Skillsunmatched
    • Public Key Infrastructure (PKI)unmatched
    • Publicationsunmatched
    • Python Programming/Scripting Languageunmatched
    • REST (Representational State Transfer)unmatched
    • Regulatory Complianceunmatched
    • SSL-TLS (Secure Socket Layer - Transport Layer Security)unmatched
    • Scripting (Scripting Languages)unmatched
    • Security Architectureunmatched
    • Security Complianceunmatched
    • Smartcardsunmatched
    • Standard Operating Procedures (SOP)unmatched
    • Systems Administration/Managementunmatched
    • Systems Engineeringunmatched
    • Talent Managementunmatched
    • Technical Writingunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • United States Citizenunmatched
    • United States Department of Defense (DoD)unmatched
    • Windows PowerShellunmatched
    • Writing Skillsunmatched

    Description

    Senior Public Key Infrastructure (PKI) Engineer
    Hybrid -Fairfax, VA (3 days onsite)
    Rate: $185,000

     
    Job Description:
    Seeking a Senior Public Key Infrastructure (PKI) Engineer to work in our Fairfax, VA office in a hybrid onsite/remote capacity.

    The Senior PKI Engineer will be responsible for the architecture, implementation, administration, automation, and maintenance of enterprise Public Key Infrastructure (PKI) systems and cryptographic services.
     
    This role supports secure authentication, encryption, digital signing, certificate lifecycle management, and enterprise trust services across complex environments.
     
    The engineer will lead efforts to modernize and automate certificate management processes, reduce manual administration, and improve the scalability and security of PKI operations.
     
    Responsibilities include managing certificate authorities (CAs), automating certificate issuance and renewal workflows, integrating PKI services with enterprise platforms, and supporting compliance with cybersecurity standards and operational requirements.
     
    Key Responsibilities:
    • Architect, deploy, configure, and maintain enterprise PKI environments and certificate authority infrastructure. 
    • Automate certificate lifecycle management processes including certificate issuance, renewal, revocation, rotation, and expiration monitoring. 
    • Develop and maintain automation scripts, APIs, and workflows for PKI and certificate management using tools such as PowerShell, Python, Ansible, Terraform, or similar technologies. 
    • Implement automated certificate enrollment and management solutions for servers, applications, network devices, containers, and cloud platforms. 
    • Administer internal and external certificate authorities (Microsoft CA, Entrust, DigiCert, EJBCA, or similar platforms). 
    • Implement and maintain TLS/SSL certificates across enterprise systems and environments. 
    • Troubleshoot PKI-related issues involving authentication, encryption, trust relationships, and certificate validation. 
    • Support identity and access management integrations using certificates, smart cards, and multifactor authentication technologies. 
    • Ensure PKI systems comply with organizational security policies and applicable standards such as NIST, FIPS, DISA STIGs, FedRAMP, or FISMA requirements. 
    • Collaborate with cybersecurity, DevSecOps, cloud, network, and systems engineering teams to integrate secure certificate management into enterprise platforms and CI/CD pipelines. 
    • Participate in incident response activities involving cryptographic systems, certificate compromise, or trust-related issues. 
    • Maintain technical documentation, architecture diagrams, standard operating procedures, and configuration baselines.
    • Other duties, as assigned. 
    Required Skills:
    • U.S. Citizen. No dual citizenship.
    • Candidate requires a Secret Clearance to Interview. Final clearance required is TS.
    • Minimum 12 years of experience with no degree. 
    • Active DoD 8140 IAT Level II Security+ (or higher) or ability to obtain within 90 days of hire.
    • Ability to work in a hybrid capacity, with up to 3 business days per week onsite in Fairfax, VA.  
    • Experience with:
      • Administering enterprise PKI and certificate management environments. 
      • Automating certificate management and infrastructure processes.
      • Microsoft Active Directory Certificate Services (AD CS) or comparable PKI platforms. 
      • Developing automation using PowerShell, Python, Bash, REST APIs, or infrastructure-as-code tools.
      • Windows Server and/or Linux administration. 
    • Strong knowledge of: 
    • TLS/SSL protocols.
    • Certificate authorities and registration authorities.
    • PKI architecture and trust models.
    • Cryptographic algorithms and key management.
    • Smart card and MFA technologies.
    • Understanding of enterprise security architecture and cybersecurity best practices. 
    • Ability to troubleshoot authentication and certificate-related issues across enterprise systems.
    • Strong problem-solving and decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate solution.
    • Highly developed interpersonal and oral/written communication skills, with the ability to effectively and professionally interact with a diverse set of stakeholders (from peers to end-users to executive management).
    Desired Skills:
    • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related field (or equivalent experience) with 8 years of experience.
    • Experience with:
    • Supporting cloud-native certificate services in AWS, Azure, or Google Cloud. 
    • Government, DoD, or regulated environments. 
    • Jira and Confluence.
    • Knowledge of Zero Trust architectures and identity-based security models. 
    • Familiarity with DISA STIGs, NIST 800-series publications, FedRAMP, or FISMA compliance requirements. 
    • Relevant certifications such as: 
    • CISSP 
    • Security+ 
    • Microsoft Certified: Identity and Access Administrator 
    • Certified Encryption Specialist (ECES) 
    • GIAC certifications 
    Clearance:
    • Top Secret required; we can submit Secret though.
     EOE
    Compensation: $185,000.00 per year

    We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law.





    Numbers & Facts

    LocationFairfax, Virginia
    Websitehttps://www.vervichr.com/

    Similar Jobs

    See more jobs