PKI & Encryption Engineer
Indexed description
We are seeking a PKI & Encryption Engineer to design, implement, automate, and manage enterprise PKI and certificate lifecycle solutions. This role requires deep expertise in X.509 certificates, TLS/SSL, certificate authorities, issuance, renewal, and revocation. The ideal candidate will solve complex technical problems, build reusable components, coach junior engineers, and partner with security teams to build secure, scalable systems.
Key Responsibilities
- Write, test, and document technical work products such as code, scripts, and processes according to organizational standards.
- Solve technical problems and build components/libraries with far-ranging impact.
- Deliver high-quality work and coach more junior engineers on technical craftsmanship.
- Conduct root cause analysis to identify systemic problems and define/lead execution of action items.
- Design thoughtfully integrated systems that model organizational best practices and enable disparate teams to deliver value with speed, scale, and reliability.
- Oversee the management of technical debt in existing systems and drive opportunities to eliminate it within ongoing implementations.
- Anticipate scaling, latency, and durability challenges and guide teams in implementing mitigating strategies.
- Partner with the security organization to incorporate security-conscious practices early in the lifecycle of new systems.
- Evaluate technical risks and guide toward practical prevention strategies.
- Reflect on squad delivery practices, recommend improvements to leadership, and drive implementation.
- Maintain focus on removing duplication of effort across teams and proactively identify reuse opportunities.
- Measure and assess team performance and identify areas of development for individuals.
- Explore emerging technologies, lead development of prototypes with little or no guidance, and incorporate them into architectural solutions where appropriate.
Top Requirements
- PKI and X.509 certificate expertise: TLS/SSL, CA, issuance, renewal, revocation.
- Enterprise certificate lifecycle management experience: Keyfactor, Venafi, DigiCert, Sectigo, ADCS, etc.
- Automation and scripting experience: PowerShell, Python, APIs.
- 3–5 years of related experience.
Nice to Have
- Keyfactor Command
- EJBCA
- Azure Key Vault
- HashiCorp Vault
- ACME
- Azure / AWS
- F5
- NGINX
- IIS
- DevOps / IaC experience
Skills
PKI, X.509, TLS/SSL, SSL Certificate Management, Certificate Authority, CA, Certificate Issuance, Certificate Renewal, Certificate Revocation, Keyfactor, Venafi, DigiCert, Sectigo, ADCS, PowerShell, Python, API Integration, Automation, Azure Key Vault, HashiCorp Vault, ACME, Azure, AWS, F5, NGINX, IIS, DevOps, Infrastructure as Code.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search