About this role
About the Role Senior Public Key Infrastructure (PKI) Engineer to architect, automate, and modernize enterprise PKI supporting DoD/Federal compliance. You will design scalable PKI services, automate certificate lifecycles, and partner with security teams to harden cryptographic systems. What You'll Do
- Architect PKI infrastructure and automated certificate issuance, renewal, revocation, and policy enforcement.
- Maintain compliance with DoD/Federal regulations and ensure auditability.
- Implement certificate lifecycle automation using scripting and automation tools (PowerShell, Python, Bash; Ansible, Terraform).
- Collaborate with security, IT ops, and cloud teams; evaluate PKI technologies (AD CS, HSMs, and third-party CAs).
- Support modernization efforts (cloud, containers, APIs) and integrate PKI with rest of enterprise security tooling. What We're Looking For
- U.S. citizen with active Secret clearance.
- 8+ years of systems/security experience, 4+ focused on PKI.
- AD CS experience; certificate lifecycle automation; scripting/automation proficiency.
- Knowledge of X.509, cryptography, and DoD/Federal compliance. Nice to Have
- Experience with AD CS ecosystem tools: ACME, SCEP/EST; REST APIs; PowerShell, Python, Bash; Ansible, Terraform.
- Cloud/platform experience: Azure, AWS; Kubernetes; HSMs; familiarity with Entrust, DigiCert, EJBCA, Keyfactor, Venafi. Compensation & Benefits
- Salary: $150,000 - $190,000 per year.
- Hybrid work arrangement in Fairfax, VA; U.S. citizen with active clearance; comprehensive benefits may apply.