PKI Engineer

  • Charlotte, NC
  • Posted 4 hours ago | Updated 4 hours ago

Overview

On Site
Depends on Experience
Accepts corp to corp applications
Contract - Independent
Contract - W2
Contract - 12 Month(s)

Skills

Active Directory
Algorithms
Apache Tomcat
Auditing
BMC Remedy
Change Management
Collaboration
Computer Hardware
Contract Lifecycle Management
Disaster Recovery
Documentation
Educate
Encryption
F5
Hierarchical Storage Management
High Availability
IEEE 802.1X
IT Service Management
Java
KPI
Kubernetes
Lifecycle Management
Linux
Management
Microsoft
Microsoft Azure
Microsoft Certified Professional
Microsoft Windows
Migration
OpenSSL
Operational Excellence
PKI
Python
RFC
Regulatory Affairs
Regulatory Compliance
Reporting
SAS Cloud Analytic Services
SSL
Scripting
ServiceNow
Smart Card
TLS
Technical Writing
Test-driven Development
Training
Unix
Use Cases
Web Browsers
Windows PowerShell
X.509

Job Details

PKI Engineer

Charlotte, NC

Contract

 

What are the top 3 skills required for this role?

1.Ideal candidate should be well experienced in PKI, certificate lifecycle management (CLCM), infrastructure automation and credential management (CMS) systems. Should have experience with ACME protocols, scripting (e.g., PowerShell, Python), and enterprise CLM tools

2. Windows, Linux/Unix, Apache, Tomcat, Java Keystore, F5, Azure Key Vault.

3. This is a hard core development / engineering role

 

Job Description/ Responsibilities

Key Responsibilities

  • Lead the infrastructure protection strategy to create, evolve, and secure internal PKI and credential management security strategy.
  • Design, implement, and operate enterprise-grade PKI solutions, including internal and external Certificate Authorities (CAs), Hardware Security Modules (HSMs), and certificate lifecycle management platforms.
  • Create design components, develop code, and test changes using test-driven development methodologies.
  • Provide subject matter expertise in resolving complex problems related to PKI environment.
  • Manage, secure, engineer and provide governance for key and certificate management services, including robust, enterprise-grade PKI, certificate lifecycle management (CLCM), infrastructure automation and credential management (CMS) systems.
  • Implement and maintain automated certificate renewal programs; capture use-cases for certificate revocation, enrollment & renewal processes.
  • Monitor creation of encryption keys to ensure protection against modification and unauthorized disclosure.
  • Define Trust Strategies and understand security and governance requirements for Certification Authorities.
  • Architect and manage internal PKI infrastructure including CA, RA, CRL, OCSP, and HSM integrations.
  • Design and implement certificate lifecycle automation using ACME protocols, scripting (e.g., PowerShell, Python), and enterprise CLM tools.
  • Install and manage certificates across platforms: Windows, Linux/Unix, Apache, Tomcat, Java Keystore, F5, Azure Key Vault.
  • Implement digital certificate policies aligned with X.509 standards and CA/Browser Forum baseline requirements.
  • Develop and maintain Certificate Policy and Certificate Practice Statements (CP/CPS).
  • Provide PKI support for application integrations, including TLS/SSL, S/MIME, 802.1x, Smartcards, and Code Signing.
  • Collaborate with IAM, Infrastructure, Security, and Application teams to integrate PKI into broader identity solutions.
  • Contribute to change management and documentation using ITSM tools (ServiceNow, Remedy).
  • Maintain high availability and disaster recovery readiness for PKI infrastructure.
  • Track and report on PKI service metrics, SLAs, KPIs, and KRIs to ensure operational excellence.
  • Develop and maintain SOPs, technical documentation, and training materials.

Preferred Skills

  • Strong technical knowledge of enterprise PKI operations, cryptographic algorithms (symmetric/asymmetric), digital signatures, with strong understanding of compliance, auditing, and key management.
  • Microsoft certifications (e.g., Azure Security Engineer, MCSA).
  • Knowledge of CA/B Forum, RFC 5280, RFC 6960 (OCSP).
  • Familiarity with containerized environments and Kubernetes certificate management.
  • Experience with Active Directory Certificate Services, GlobalSign, Sectigo, DigiCert, Keyfactor, OpenSSL, or other certificate management platforms. Understanding of OCSP, CA, RA, CRL, and BYOK configurations.
  • Comprehensive understanding of the PKI/HSM ecosystem, including technology, standards, implementations, and migration strategies.
  • Experience with developing scripts for administrative and automation tasks.
  • Collaborate with other IT and Operational teams to integrate PKI solutions with existing systems/applications.
  • Monitor and troubleshoot PKI related issues.
  • Assist and educate users/administrators with certificate enabled applications, such as SSL/TLS, S/MIME, Code Signing, Smartcard, 802.1x, EAP-TLS, etc.
  • Drive technical discussions to understand digital certificate services requirements.
  • Maintain and enhance global solutions for the digital certificate area ensuring high availability and disaster recovery.
  • Knowledge of PKI Standards including X.509, CP/CPS, CA/Browser Forum Baseline Requirements.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.

About Digitive LLC