
PKI, Certificate Management Engineer
Posted Aug 14

Posted Aug 14
This is a fully remote position, open to applicants in United States.
β’ Design, implement, and maintain an enterprise Public Key Infrastructure (PKI) to support both internal and external certificate needs.
β’ Oversee the complete certificate lifecycle, which includes request, issuance, validation, distribution, renewal, revocation, expiration, and retirement.
β’ Implement and sustain ACME-based certificate automation along with automated enrollment and renewal workflows.
β’ Manage certificates across various platforms including Windows, Linux, cloud environments, containers, applications, load balancers, network devices, and other enterprise systems.
β’ Design and operate integrations with AWS Private Certificate Authority, AWS Certificate Manager, and other related AWS services.
β’ Implement and manage HSM capabilities, such as AWS CloudHSM, for the protection of private keys and cryptographic operations.
β’ Support Federal PKI and DoD PKI trust relationships, certificate chains, and interoperability requirements.
β’ Integrate CAC/PIV authentication with enterprise applications, identity platforms, operating systems, and secure access workflows.
β’ Implement and maintain mutual TLS (mTLS) for workload identity, service-to-service authentication, and Zero Trust communications.
β’ Ensure that cryptographic implementations utilize FIPS-validated modules and approved algorithms as necessary.
β’ Establish certificate discovery, inventory, monitoring, and alerting to identify unmanaged certificates and prevent outages due to expiration.
β’ Develop governance standards regarding certificate ownership, issuance, naming conventions, key lengths, algorithms, renewal periods, revocation, and retention policies.
β’ Integrate certificate management with IAM platforms and authentication workflows.
β’ Support secure networking and communications through TLS, mTLS, certificate-based authentication, and encryption standards.
β’ Monitor the health of the PKI platform, certificate status, revocation services, HSM operations, and certificate expiration events.
β’ Troubleshoot issues related to certificate chains, trust stores, TLS, cryptography, enrollment, renewal, and authentication.
β’ Collaborate with cybersecurity, identity, cloud, platform, network, and application teams to incorporate PKI services into enterprise architectures and deployment workflows.
β’ Maintain documentation for PKI architecture, certificate policies, operational procedures, runbooks, governance standards, and audit evidence.
β’ Bachelorβs degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related technical field.
β’ Proven experience in designing, implementing, or managing enterprise Public Key Infrastructure (PKI).
β’ In-depth knowledge of X.509 certificates, certificate authorities, trust chains, cryptographic algorithms, key management, revocation, and certificate lifecycle management.
β’ Experience in implementing automated certificate issuance and renewal using ACME or similar technologies.
β’ Skilled in managing certificates across Windows, Linux, cloud, containerized, network, and application environments.
β’ Practical experience with AWS Private CA, AWS Certificate Manager, AWS CloudHSM, or similar cloud PKI and HSM technologies.
β’ Strong understanding of cryptography, encryption, digital signatures, hashing, key exchange, and secure communications.
β’ Experience in integrating PKI with IAM, directory services, applications, network infrastructure, and cloud services.
β’ Familiarity with Federal PKI, DoD PKI, CAC/PIV authentication, and government certificate trust models.
β’ Experience in implementing mTLS and certificate-based workload identity within Zero Trust architectures.
β’ Knowledge of FIPS-validated cryptography and cryptographic requirements applicable to government or regulated environments.
β’ Experience with certificate discovery, inventory management, expiration monitoring, and proactive renewal strategies.
β’ Strong understanding of TLS configuration, secure networking, trust stores, certificate validation, and PKI troubleshooting.
β’ Experience supporting AWS GovCloud, government, defense, or other regulated environments is preferred.
β’ Excellent governance, risk management, documentation, troubleshooting, and cross-functional collaboration abilities.
β’ Preferred certifications: AWS Certified Security β Specialty; Microsoft Certified: Cybersecurity Architect Expert (SC-100); Red Hat Certified Engineer (RHCE); Microsoft Certified: Windows Server Hybrid Administrator Associate; Entrust or DigiCert PKI certifications, where applicable.
β’ Competitive salary, paid bi-monthly.
β’ Top-tier medical coverage.
β’ 100% of medical premiums covered by True Zero.
β’ Company-wide new business incentive programs.
β’ Contribution incentives (such as white papers, blog posts, internal webinars, etc.).
β’ 3 weeks of PTO at the start + 11 Paid Holidays annually.
β’ 401k Program with 100% company match on the first 4%.
β’ Monthly reimbursement for Cell Phone and Home Internet expenses.
β’ Paternity and Maternity Leave.
β’ Investment in training and certifications to enhance and expand your technical expertise.
Mercor
RTX
Expel
Qualus
Get handpicked remote jobs straight to your inbox weekly.