PKI / Certificate Management Engineer (R-00198)

Posted One Month Ago
Be an Early Applicant
Hiring Remotely in USA
Remote
Senior level
Professional Services
The Role
Design, deploy, and maintain enterprise PKI and certificate lifecycle automation across Windows, Linux, cloud, containers, applications, and network devices. Implement ACME automation, integrate AWS Private CA/ACM and HSMs, support FPKI/DoD PKI and CAC/PIV, enable mTLS and Zero Trust, establish governance, monitoring, inventory, and troubleshooting processes, and collaborate with security, cloud, identity, and application teams.
Summary Generated by Built In
True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes. True Zero recognizes that those outcomes begin and end with our people, and that is what we have built a community of like-minded, driven, and passionate individuals and innovators who are aligned in a common goal of delivering top-tier services to our customers. Our culture and commitment have been recognized through numerous accolades, including being named one of the Best Places to Work in 2023 in two categories (“Prosperous and Thriving” ($5MM–$50MM in gross revenue) and “Mid-Atlantic Region” (DC, DE, MD, NC, VA, WV)), and again in 2025 as a Best Places to Work honoree. In addition, True Zero earned coveted spots on the Inc. 5000 list of fastest-growing companies in America in 2022, 2023, and 2025, a testament to our sustained growth driven by our people-first approach and unwavering dedication to excellence.
 

The PKI / Certificate Management Engineer designs, deploys, and maintains a secure, scalable Public Key Infrastructure supporting enterprise, cloud, government, and hybrid environments. The role is responsible for automating certificate issuance and renewal, managing certificate lifecycles across Windows, Linux, cloud platforms, containers, applications, and network devices, and establishing governance and monitoring processes that reduce the risk of certificate-related outages.

This position supports the Zero Trust architecture through certificate-based authentication, encryption, workload identity, and secure communications. The engineer will also support Federal PKI and DoD PKI integrations, CAC/PIV authentication, mutual TLS, FIPS-validated cryptography, hardware security modules, and cloud-native certificate services in AWS GovCloud.

Job Responsibilities

  • Design, implement, and maintain enterprise Public Key Infrastructure (PKI) supporting internal and external certificate requirements.
  • Manage the full certificate lifecycle, including request, issuance, validation, distribution, renewal, revocation, expiration, and retirement.
  • Implement and maintain ACME-based certificate automation and other automated enrollment and renewal workflows.
  • Manage certificates across Windows, Linux, cloud platforms, containers, applications, load balancers, network devices, and other enterprise systems.
  • Design and operate integrations with AWS Private Certificate Authority (AWS Private CA), AWS Certificate Manager (ACM), and related AWS services.
  • Implement and administer Hardware Security Module (HSM) capabilities, including AWS CloudHSM, for secure protection of private keys and cryptographic operations.
  • Support Federal PKI (FPKI) and DoD PKI trust relationships, certificate chains, and interoperability requirements.
  • Integrate CAC/PIV authentication with enterprise applications, identity platforms, operating systems, and secure access workflows.
  • Implement and maintain mutual TLS (mTLS) for workload identity, service-to-service authentication, and Zero Trust communications.
  • Ensure cryptographic implementations use FIPS-validated cryptographic modules and approved algorithms where required.
  • Establish certificate discovery, inventory, monitoring, and alerting capabilities to identify unmanaged certificates and prevent expiration-related outages.
  • Develop governance standards for certificate ownership, issuance, naming, key length, cryptographic algorithms, renewal periods, revocation, and retention.
  • Integrate certificate management with Identity and Access Management (IAM) platforms and authentication workflows.
  • Support secure networking and communications through TLS, mTLS, certificate-based authentication, and encryption standards.
  • Monitor PKI platform health, certificate status, revocation services, HSM operations, and certificate expiration events.
  • Troubleshoot complex certificate-chain, trust-store, TLS, cryptographic, enrollment, renewal, and authentication issues.
  • Partner with cybersecurity, identity, cloud, platform, network, and application teams to integrate PKI services into enterprise architectures and deployment workflows.
  • Maintain PKI architecture documentation, certificate policies, operational procedures, runbooks, governance standards, and audit evidence.

Job Qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related technical discipline.
  • Demonstrated experience designing, implementing, or administering enterprise Public Key Infrastructure (PKI).
  • Strong knowledge of X.509 certificates, certificate authorities, trust chains, cryptographic algorithms, key management, revocation, and certificate lifecycle management.
  • Experience implementing automated certificate issuance and renewal using ACME or comparable certificate automation technologies.
  • Experience managing certificates across Windows, Linux, cloud, containerized, network, and application environments.
  • Hands-on experience with AWS Private CA, AWS Certificate Manager, AWS CloudHSM, or comparable cloud PKI and HSM technologies.
  • Strong understanding of cryptography, encryption, digital signatures, hashing, key exchange, and secure communications.
  • Experience integrating PKI with IAM, directory services, applications, network infrastructure, and cloud services.
  • Familiarity with Federal PKI, DoD PKI, CAC/PIV authentication, and government certificate trust models.
  • Experience implementing mTLS and certificate-based workload identity in Zero Trust architectures.
  • Familiarity with FIPS-validated cryptography and cryptographic requirements for government or regulated environments.
  • Experience with certificate discovery, inventory management, expiration monitoring, and proactive renewal processes.
  • Strong understanding of TLS configuration, secure networking, trust stores, certificate validation, and PKI troubleshooting.
  • Experience supporting AWS GovCloud, government, defense, or other regulated environments is preferred.
  • Strong governance, risk management, documentation, troubleshooting, and cross-functional collaboration skills.
  • Preferred Certifications:
    • AWS Certified Security – Specialty
    • Microsoft Certified: Cybersecurity Architect Expert (SC-100)
    • Red Hat Certified Engineer (RHCE)
    • Microsoft Certified: Windows Server Hybrid Administrator Associate
    • Entrust or DigiCert PKI certifications, where applicable

We’re actively searching for talented security and technology practitioners who are ready to experience the True Zero difference. As a True Zero team member, you'll enjoy:
 
- Competitive salary, paid twice per month
- Best in class medical coverage
- 100% of medical premiums covered by True Zero
- Company wide new business incentive programs
- Contribution Incentives (i.e. white papers, blog posts, internal webinars, etc.)
- 3 weeks of PTO starting + 11 Paid Holidays Annually
- 401k Program with 100% company match on the first 4%
- Monthly reimbursement of Cell Phone and Home Internet costs
- Paternity/Maternity Leave
- Investment in training and certifications to broaden and deepen your technical skills

Skills Required

  • Bachelor's degree in Cybersecurity, Computer Science, IT, Information Systems, or related field
  • Experience designing, implementing, or administering enterprise Public Key Infrastructure (PKI)
  • Strong knowledge of X.509 certificates, certificate authorities, trust chains, cryptographic algorithms, key management, revocation, and certificate lifecycle management
  • Experience implementing automated certificate issuance and renewal using ACME or comparable automation
  • Experience managing certificates across Windows, Linux, cloud, containerized, network, and application environments
  • Hands-on experience with AWS Private CA, AWS Certificate Manager (ACM), AWS CloudHSM, or comparable cloud PKI and HSM technologies
  • Strong understanding of cryptography, encryption, digital signatures, hashing, key exchange, and secure communications
  • Experience integrating PKI with IAM, directory services, applications, network infrastructure, and cloud services
  • Familiarity with Federal PKI, DoD PKI, CAC/PIV authentication, and government certificate trust models
  • Experience implementing mTLS and certificate-based workload identity in Zero Trust architectures
  • Familiarity with FIPS-validated cryptography and cryptographic requirements for government or regulated environments
  • Experience with certificate discovery, inventory management, expiration monitoring, and proactive renewal processes
  • Strong understanding of TLS configuration, trust stores, certificate validation, and PKI troubleshooting
  • Strong governance, risk management, documentation, troubleshooting, and cross-functional collaboration skills
  • Experience supporting AWS GovCloud, government, defense, or other regulated environments
  • AWS Certified Security - Specialty
  • Microsoft Certified: Cybersecurity Architect Expert (SC-100)
  • Red Hat Certified Engineer (RHCE)
  • Microsoft Certified: Windows Server Hybrid Administrator Associate
  • Entrust or DigiCert PKI certifications
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Washington, DC
31 Employees
Year Founded: 2016

What We Do

True Zero Technologies is a Professional Services firm and authorized product reseller. Made up of passionate technologists, TZT delivers services for both the public and private sector, creating unique and scalable solutions based on business context driven requirements. TZT is rapidly expanding it's team to meet demand, we have many opportunities including long-term, multi-year contracts supporting Splunk instances large and small with ample opportunity to help shape large operational and security programs. Apply today! https://truezerotech.applicantpro.com/jobs/

Similar Jobs

NBCUniversal Logo NBCUniversal

Devops Engineer

AdTech • Cloud • Digital Media • Information Technology • News + Entertainment • App development
Remote or Hybrid
New York, NY, USA
180K-230K Annually

NBCUniversal Logo NBCUniversal

Senior Software Engineer

AdTech • Cloud • Digital Media • Information Technology • News + Entertainment • App development
Remote or Hybrid
New York, NY, USA
120K-170K Annually

Applied Systems Logo Applied Systems

Staff Software Engineer

Artificial Intelligence • Cloud • Payments • Software • Business Intelligence • Generative AI • Automation
Remote or Hybrid
2 Locations
3116 Employees
175K-175K Annually

General Motors Logo General Motors

Software Engineer

Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Remote or Hybrid
2 Locations
165000 Employees
128K-189K Annually

Similar Companies Hiring

ABN AMRO Clearing USA LLC Thumbnail
Information Technology • Professional Services • Financial Services
Chicago, IL
215 Employees
Fora Thumbnail
Agency • On-Demand • Professional Services • Sales • Software • Travel • Hospitality
New York, NY
250 Employees
Energy CX Thumbnail
Greentech • Professional Services • Business Intelligence • Consulting • Energy • Financial Services • Utilities
Chicago, IL
108 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account