Top 3 Skills
1. Enterprise PKI & HSM Operations
Root/Issuing CA administration, HSM key management, and secure certificate lifecycle control.
Deep expertise in ADCS, domain controller certificates, chain of trust, CRLs/OCSP, and privileged access isolation.
3. Automation & Observability
PowerShelldriven certificate automation, Terraform-based infrastructure, and Datadog monitoring for PKI health.
Summary
Seeking a Senior PKI / Certificate Services Engineer to operate and secure its enterprise Public Key Infrastructure and certificate services at the Tier 0 global administrator level.
This role includes working with HSMs, root and issuing CAs, certificate lifecycle automation, and infrastructure supporting domain controllers and privileged AD operations.
This work is highly sensitive and requires deep experience supporting PKI in large, securityfocused enterprises.
Key Responsibilities
Operate and maintain enterprise PKI including Root CAs, Issuing CAs, HSMs, CRLs, and OCSP.
Manage certificate templates, issuance, and lifecycle for domain controllers, servers, applications, and Tier 0 systems.
Perform secure key ceremonies, certificate rotations, audits, and recovery processes.
Ensure only authorized domain controllers can join forests/domains through certificate validation and security enforcement.
Script and automate certificate operations using PowerShell; build repeatable infrastructure with Terraform.
Utilize Datadog for monitoring PKI infrastructure and certificaterelated dependencies.
Work closely with AD engineers, Cloud Authentication teams, and Cybersecurity on identity trust boundaries.
Maintain strong control of privileged access, leastprivilege, and Tier 0 isolation practices.
Qualifications MustHave Experience
7+ years operating enterprise PKI/ADCS with root/issuing CA administration.
Experience configuring and managing Hardware Security Modules (HSMs).
Deep understanding of certificate trust, chainoftrust, CRLs/OCSP, and crypto hygiene.
Handson PowerShell automation experience.
Experience with Terraform for repeatable infrastructure patterns.
Experience using Datadog for proactive observability.
Preferred
Strong understanding of privileged identity boundaries (Tier 0).
Experience supporting domain controller certificates in complex AD architectures.
Exposure to Tanium or other enterprise governance/config tools