Senior PKI Engineer

Southlake, TX, US • Posted 3 days ago • Updated 3 hours ago
Full Time
On-site
USD $135,000.00 - 150,000.00 per year
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Collaboration
  • Creative Problem Solving
  • Finance
  • SaaS
  • IaaS
  • Cloud Computing
  • X.509
  • SAS Cloud Analytic Services
  • Servers
  • Build Automation
  • Auditing
  • Agile
  • Stakeholder Engagement
  • Network Security
  • Active Directory
  • Scripting
  • Windows PowerShell
  • Python
  • GitHub
  • .NET
  • Management
  • Computer Hardware
  • Software Engineering
  • Access Control
  • Research
  • Testing
  • Communication
  • Computer Science
  • Cyber Security
  • Data Security
  • CISSP
  • CISM
  • Cisco Certifications
  • CISA
  • Security+
  • Software Development Methodology
  • Threat Modeling
  • Workflow
  • Software Security
  • Authentication
  • Identity Management
  • Security Engineering
  • Artificial Intelligence
  • Security Controls
  • FOCUS
  • PKI
  • Lifecycle Management

Summary

Your Opportunity

At Schwab, you're empowered to make an impact on your career. Here, innovative thought meets creative problem solving, helping us "challenge the status quo" and transform the finance industry together.

We believe in the importance of in-office collaboration and fully intend for the selected candidate for this role to work on site in the specified location(s).

At Schwab, you're empowered to make an impact on your career. Here, innovative thought meets creative problem solving, helping us challenge the status quo and transform the finance industry together. Schwab's Cybersecurity organization is the first line of defense for the Firm, and the Senior Security Engineer on the Public Key Infrastructure PKI team will play a key role in designing, implementing, and maintaining enterprise PKI controls that reduce risk and support Schwab's security policies and standards.

We are looking for a senior, hands-on security engineer with strong experience in Public Key Infrastructure, certificate lifecycle management, trust models, automation, and enterprise security engineering. This role will support PKI capabilities across on-prem, SaaS, and IaaS cloud-based environments, with responsibility for managing and improving Certificate Authorities CAs, Registration Authorities RAs, Hardware Security Modules HSMs, and X.509 certificate lifecycle processes across a large enterprise environment.

This is a senior engineering role focused on building reliable, scalable, and automated PKI services that other teams depend on. The right candidate will bring strong technical judgment around certificate lifecycle risks, trust chains, validation, renewal failure modes, and system integrations, while also being able to partner across cybersecurity, infrastructure, application, and engineering teams to deliver secure and reliable PKI solutions.

What You'll Do

  • Architect, deploy, maintain, and enhance enterprise PKI infrastructure, including Certificate Authorities CAs, Registration Authorities RAs, Hardware Security Modules HSMs, and related certificate services.
  • Implement and maintain issuance, renewal, revocation, and lifecycle management processes for digital certificates used by users, servers, applications, services, and devices across the organization.
  • Design and build automation that improves PKI reliability, reduces manual effort, and scales certificate lifecycle management across enterprise environments.
  • Apply PKI, certificate, and trust concepts when designing or reviewing system architectures, platform integrations, authentication flows, access control mechanisms, and security automation.
  • Integrate PKI solutions with security systems, applications, infrastructure platforms, developer workflows, and enterprise technology services.
  • Identify and address trust failures, certificate lifecycle risks, validation gaps, automation issues, and potential sources of outages or security exposure.
  • Conduct security assessments and audits of PKI systems to identify vulnerabilities, operational risks, and opportunities for improvement.
  • Drive complex technical initiatives from design through delivery using cybersecurity practices, software engineering principles, agile delivery methods, and strong stakeholder engagement.
  • Partner closely with Data Protection, Cybersecurity, infrastructure, application, developer, and engineering teams to ensure PKI services meet business, security, and operational needs.
  • Translate technical PKI and trust requirements into practical, repeatable engineering patterns that can be adopted across teams.

What you have

Required Qualifications

  • 5+ years of hands-on experience in network security, data security, PKI, certificate management, or other cybersecurity-related controls and technologies.
  • Strong understanding of Public Key Infrastructure PKI principles, including certificate lifecycle management, trust chains, validation, renewal, revocation, and common failure modes.
  • Experience managing or supporting enterprise PKI technologies such as Microsoft Active Directory Certificate Services AD CS, Entrust, Venafi, or other commercial PKI solutions.
  • Experience with Certificate Lifecycle Management automation using tools and scripting/coding such as Venafi, PowerShell, and Python; GitHub and .NET experience are highly desired.
  • Experience managing or working with Hardware Security Modules HSMs.
  • Strong software engineering or automation background with the ability to design, build, and maintain services or automation that operate reliably at scale.
  • Experience integrating PKI with authentication, access control, applications, infrastructure platforms, or enterprise security systems.
  • Ability to assess system designs and identify trust, identity, certificate, or cryptographic risks without requiring deep cryptographic research or protocol design specialization.
  • Proven ability to deliver high-visibility, high-impact cybersecurity projects with cross-functional teams while maintaining strong results across planning, requirements, design, testing, and deployment.
  • Strong communication skills with the ability to translate technical information for different audiences and influence stakeholders across multiple levels of the organization.
  • Bachelor's degree in computer science or a related field highly preferred.

Preferred Qualifications

  • Cybersecurity or data protection certifications such as CISSP, GIAC, CISM, CCSP, CISA, Security+, or related certifications.
  • Experience with secure SDLC, threat modeling, vulnerability remediation workflows, application security, or platform security engineering.
  • Exposure to identity, authentication, access management, or broader trust and platform security engineering concepts.
  • Familiarity with AI-assisted development or AI security controls is a plus, but the primary focus of this role remains PKI, certificate lifecycle management, and trust engineering.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 90989465
  • Position Id: 209cca46bb284f7c3b0c2bcf0dd75e05
  • Posted 3 days ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Irving, Texas

Today

Easy Apply

Full-time

$50 - $70 per hour

Westlake, Texas

Today

Easy Apply

Full-time

$1 - $3 per hour

Fort Worth, Texas

15d ago

Easy Apply

Contract, Third Party

Depends on Experience

Hybrid in Dallas, Texas

Today

Easy Apply

Contract

Depends on Experience

Search all similar jobs