Join a leading cybersecurity team as a Senior PKI Engineer, responsible for designing, deploying, and managing PKI infrastructures and certificate lifecycles. Ensure security compliance, automate processes, and support trust services across On-Premise and cloud environments. This role requires strong cryptography expertise, PKI experience, and proficiency in ADCS or other PKI solutions.
We are looking for a Senior PKI Engineer to join a leading cybersecurity team. In this role, you will design, deploy, and maintain PKI infrastructures, including Root and Sub Certificate Authorities (CAs), HSMs, OCSP, and CRL services. You will manage the full lifecycle of certificates, from generation and storage to rotation, revocation, and auditing, ensuring robust security practices.
Key responsibilities include defining and maintaining certificate policies (CP/CPS), securing certification chains, automating processes through scripting (PowerShell, Python), and implementing CI/CD pipelines to optimize operations. You will ensure compliance with eIDAS, ETSI standards, and X.509, and support trust services across both On-Premise and cloud environments.
The ideal candidate has 5-7 years of experience in PKI or Trust Services, strong knowledge of cryptographic algorithms (RSA, ECC, SHA, KDF), and hands-on experience with PKI protocols such as OCSP, SCEP, CMP, and TLS. Experience with ADCS or open-source/commercial PKI solutions is essential. Candidates should have strong problem-solving skills, the ability to work in complex infrastructures, and the capacity to define policies, ensure compliance, and contribute to security architecture.
This role offers the opportunity to work on critical security projects, influence cybersecurity strategy, and participate in the evolution of trust and identity management within a high-profile organization.
* 5-7 years of experience in PKI or Trust Services environments
* Strong knowledge of certificate lifecycle management and cryptography (RSA, ECC, SHA)
* Expertise with PKI protocols: OCSP, SCEP, CMP, TLS
* Experience with ADCS and/or commercial/open-source PKI solutions
* Familiarity with HSM, Root/Sub CA, OCSP, CRL
* Skilled in automation and scripting (PowerShell, Python) and CI/CD pipelines
* Understanding of standards and compliance: eIDAS, ETSI, X.509, CP/CPS
* Ability to define policies, ensure security compliance, and work in complex infrastructures
* Strong problem-solving, communication, teamwork, and analytical skills
