Top Requirements:
5+ years in security engineering with demonstrated independent project ownership (not queue-based SOC analyst experience), including hands-on PKI engineering work).
1. PKI engineering (not just certificate consumption) — demonstrable understanding of PKI solution design and operations: enrollment protocols (SCEP, EST), Certificate Policy / Certification Practice Statement (CP/CPS), trusted roles, Levels of Assurance, NIST SP 800-63, and real use cases such as certificate-based authentication and software signing/validation.
2. Remediation lifecycle engineering — owning remediation-plan review and vulnerability/finding tracking from finding to validated closure.
Nice to have:
• Microsoft Sentinel, KQL/query and rule authoring, dashboards, and end-to-end security event investigation, driven independently with strong written documentation
• Hands-on AI/agentic security tooling (e.g., Claude / LLM-assisted code & configuration analysis, prompt engineering for security use cases) per CISO AI direction;
• Absolute endpoint platform engineering (SSO, policy groups, API); scripting/automation (Python/PowerShell); aviation / OT / cyber-physical or embedded-systems exposure;
• HSM / key-management and code-signing infrastructure
• Writes, tests, and documents technical work products (e.g., code, scripts, processes) according to organizational standards and practices
· Solves technical problems and builds components/libraries with far-ranging impact
· Delivers high quality work and coaches more junior engineers on technical craftsmanship
· Conducts root cause analysis to identify systemic problems and defines and leads execution of action items to address
· Designs thoughtfully integrated systems that model organizational best practices, allowing disparate teams across product domains to deliver value with speed, scale, and reliability
· Oversees the management of technical debt in existing systems and drives opportunities to eliminate within ongoing implementations