- Company Name
- SoTalent
- Job Title
- Security Engineer
- Job Description
-
Job Title: PKI Security Engineer
Role Summary
Design, deploy, and maintain enterprise Public Key Infrastructure (PKI) solutions to safeguard digital identities and protect data across the organization. Combines deep technical knowledge of PKI principles with hands‑on engineering and automation skills to enable secure certificate lifecycle management and integration with authentication and identity systems.
Expectations
* Architect and operate end‑to‑end PKI components including Certificate Authorities (CAs), Registration Authorities (RAs), and Hardware Security Modules (HSMs).
* Own certificate issuance, renewal, revocation, and policy enforcement to support secure authentication and encryption.
* Automate PKI processes through scripting and development tools, ensuring repeatable, auditable workflows.
* Integrate PKI with identity & access management, directory services, and application platforms.
* Lead audits, risk assessments, and continuous improvement initiatives for PKI security posture.
* Collaborate across security, networking, and application teams to design scalable, highly available PKI architectures.
* Deliver guidance on best practices, standards, and compliance requirements for PKI deployments.
Key Responsibilities
* Deploy, configure, and manage PKI infrastructure (CAs, RAs, HSMs) on Windows and Linux platforms.
* Implement automated certificate lifecycle pipelines in PowerShell, Python, or .NET.
* Integrate PKI with Microsoft ADCS, Venafi, Entrust, and other industry tools.
* Perform certificate issuance, renewal, revocation, and re‑issuance operations for internal and external services.
* Conduct regular audits, penetration tests, and vulnerability assessments on PKI components.
* Produce documentation, SOPs, and security controls for PKI processes.
* Mentor and train team members on PKI concepts and automation techniques.
* Stay current with cryptographic standards, attack vectors, and regulatory requirements related to digital certificates.
Required Skills
* 5+ years in cybersecurity, network, or data engineering with a focus on PKI.
* Extensive knowledge of PKI architecture, certificate lifecycle, and security frameworks.
* Proficiency with Microsoft ADCS, Entrust, Venafi, and HSM technologies.
* Strong scripting and programming skills in PowerShell, Python; experience with .NET is a plus.
* Familiarity with source control (Git, GitHub) and CI/CD pipelines for automation.
* Ability to translate complex technical concepts to non‑technical stakeholders.
* Excellent problem‑solving, analytical, and communication skills.
Required Education & Certifications
* Bachelor’s degree in Computer Science, Information Security, or a related field.
* Industry certifications preferred: CISSP, CISM, CCSP, GIAC, Security+.
* Demonstrated experience designing and deploying large‑scale, highly available PKI systems.