PKI Engineer

Spring, TX, US • Posted 14 hours ago • Updated 14 hours ago
Contract W2
Travel Required
On-site
$50 - $55/hr
Fitment

Dice Job Match Score™

📋 Comparing job requirements...

Job Details

Skills

  • PKI

Summary

Top 3 Skills
1. Enterprise PKI & HSM Operations
Root/Issuing CA administration, HSM key management, and secure certificate lifecycle control.
Deep expertise in ADCS, domain controller certificates, chain of trust, CRLs/OCSP, and privileged access isolation.
3. Automation & Observability
PowerShelldriven certificate automation, Terraform-based infrastructure, and Datadog monitoring for PKI health.

Summary
Seeking a Senior PKI / Certificate Services Engineer to operate and secure its enterprise Public Key Infrastructure and certificate services at the Tier 0 global administrator level.
This role includes working with HSMs, root and issuing CAs, certificate lifecycle automation, and infrastructure supporting domain controllers and privileged AD operations.
This work is highly sensitive and requires deep experience supporting PKI in large, securityfocused enterprises.

Key Responsibilities
Operate and maintain enterprise PKI including Root CAs, Issuing CAs, HSMs, CRLs, and OCSP.
Manage certificate templates, issuance, and lifecycle for domain controllers, servers, applications, and Tier 0 systems.
Perform secure key ceremonies, certificate rotations, audits, and recovery processes.
Ensure only authorized domain controllers can join forests/domains through certificate validation and security enforcement.
Script and automate certificate operations using PowerShell; build repeatable infrastructure with Terraform.
Utilize Datadog for monitoring PKI infrastructure and certificaterelated dependencies.
Work closely with AD engineers, Cloud Authentication teams, and Cybersecurity on identity trust boundaries.
Maintain strong control of privileged access, leastprivilege, and Tier 0 isolation practices.

Qualifications MustHave Experience
7+ years operating enterprise PKI/ADCS with root/issuing CA administration.
Experience configuring and managing Hardware Security Modules (HSMs).
Deep understanding of certificate trust, chainoftrust, CRLs/OCSP, and crypto hygiene.
Handson PowerShell automation experience.
Experience with Terraform for repeatable infrastructure patterns.
Experience using Datadog for proactive observability.
Preferred
Strong understanding of privileged identity boundaries (Tier 0).
Experience supporting domain controller certificates in complex AD architectures.
Exposure to Tanium or other enterprise governance/config tools

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91172358
  • Position Id: 8902829
  • Posted 14 hours ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Spring, Texas

Today

Easy Apply

Contract

Depends on Experience

Plano, Texas

Today

Full-time

USD 128,250.00 - 175,000.00 per year

Hybrid in Coppell, Texas

25d ago

Easy Apply

Full-time

Depends on Experience

Spring, Texas

Yesterday

Easy Apply

Contract

$40 - $50

Search all similar jobs