
Senior PKI Engineer
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in United States.
• Implement and maintain machine certificate-based authentication for Windows endpoints.
• Integrate an established enterprise PKI environment with Palo Alto GlobalProtect Pre-Logon.
• Facilitate secure device authentication prior to Windows user login.
• Configure and troubleshoot certificate enrollment, renewal, expiration, and revocation.
• Collaborate with Microsoft Intune, Active Directory, and Windows endpoint management.
• Ensure the secure storage and protection of certificates and private keys, including scenarios involving TPM-backed keys when applicable.
• Support the processes for CRL and OCSP validation and certificate revocation.
• Configure and troubleshoot GlobalProtect certificate authentication and pre-logon connectivity.
• Assist in the transition from machine/device identity to authenticated user identity.
• Collaborate with network and security teams on Prisma Access, firewall policies, and secure endpoint connectivity.
• Troubleshoot certificate, authentication, and connectivity issues across endpoints.
• Support resilience and failover scenarios for GlobalProtect / Prisma Access gateways.
• Document technical configurations, operational processes, and troubleshooting procedures.
• Work in collaboration with endpoint, networking, identity, and security teams.
• Extensive hands-on experience with Public Key Infrastructure (PKI) in enterprise settings.
• Strong understanding of Microsoft AD CS / Certificate Services or similar enterprise PKI solutions.
• Experience in managing machine/device certificates.
• Familiarity with certificate enrollment and auto-enrollment procedures.
• Knowledge of certificate lifecycle management.
• Proficiency in certificate renewal and revocation processes.
• Experience with CRL / OCSP processes.
• Proficient in handling X.509 certificates.
• Skilled in managing private keys effectively.
• Strong background in Windows enterprise environments.
• Experience with Active Directory.
• Familiarity with Microsoft Intune or other enterprise endpoint management platforms.
• Strong troubleshooting skills related to certificates, authentication, endpoint configuration, and network connectivity.
• Experience working in security-focused enterprise environments.
• U.S. citizenship is mandatory.
• Must reside in the United States.
• Capability to work on an Individual Contractor or B2B contract basis.
• Preferred experience with Palo Alto GlobalProtect, Prisma Access, and GlobalProtect Pre-Logon.
• Experience with certificate-based VPN authentication is a plus.
• Understanding of Always-On VPN / Always-On GlobalProtect architectures is preferred.
• Experience with TPM-backed certificates and hardware-protected private keys is a plus.
• Familiarity with Microsoft Entra ID is preferred.
• Experience with CrowdStrike, Microsoft Defender, Tanium, or Qualys is advantageous.
• PowerShell scripting experience is preferred.
• Experience in regulated or high-security environments is preferred.
• Paid Time Off (PTO) included as part of the engagement.
• Remote work arrangement available.
• Full-time commitment aligned with the client's business hours and project requirements.
Muon Space
Anduril Industries
Siemens Healthineers
Get handpicked remote jobs straight to your inbox weekly.