PKI Operations Engineer

Posted Yesterday
Be an Early Applicant
Fort Meade, MD, USA
In-Office
Senior level
Big Data • Security • Software
The Role
Operate and sustain a DoD enterprise PKI (RHCS): manage CA availability, certificate lifecycle (RA/CRL/OCSP), HSM integrations, CVE remediation, monitoring, automation, customer onboarding, and support PQC migration while coordinating across vendors and government stakeholders.
Summary Generated by Built In

PKI Operations Engineer 

Ft. Meade, MD — Full Time (Hybrid) 

August Schell is looking for a PKI Operations Engineer to sustain and operate DoD enterprise Public Key Infrastructure in support of our DISA customer. This is a Red Hat Certificate System (RHCS) solution. Where our PKI Software Engineer builds the next-generation certificate-systems code, this role keeps the infrastructure running: operating and hardening the live RHCS environment, standing up new customers and enclaves, driving CVE remediation and patch cycles, monitoring system health, and automating the operational toil that keeps a high-volume CA reliable. The engineer works hand-in-hand with commercial product engineering, government operations teams, and other program contractors — including through the environment's post-quantum cryptography (PQC) migration. 

Individuals in this role must be able to work hybrid and go on site at Fort Meade as requested. 

Responsibilities Include 

  • Operate and sustain the production PKI environment on Red Hat Certificate System (RHCS) — CA availability, certificate lifecycle operations, and the day-to-day health of the issuance pipeline 

  • Run RA/CRL/OCSP operations and certificate lifecycle management, including the transition to shorter-lived certificates at higher issuance volume (ACME automation) 

  • Onboard new customers, enclaves, and use cases onto the PKI — configuration, integration, and secure hardening of new environments to program standards 

  • Own CVE remediation and patch management for the PKI stack and its underlying RHEL hosts — track, test, schedule, and apply security patches with minimal disruption to CA operations 

  • Monitor system health and performance; build and maintain alerting, logging, and dashboards; respond to and resolve operational incidents, and lead root-cause analysis 

  • Operate and troubleshoot HSM integrations (Entrust nShield / Thales Luna) supporting CA operations and key escrow 

  • Automate operational tasks — health checks, backups, certificate/CRL monitoring, deployment and configuration — using scripting and CI/CD tooling to reduce toil and manual error 

  • Support the program's PQC migration from an operations standpoint (algorithm rollout, version transition, validation in the live environment) 

  • Provide development support in an operational capacity as additional value — small fixes, config-as-code, tooling, and reproduction of issues for the product engineering team — without owning the core feature-development backlog 

  • Communicate clearly across government operations stakeholders, commercial vendor engineering, and program contractors; document runbooks and escalate risks and blockers before they impact operations 

Requirements 

  • Active Secret clearance minimum (Top Secret preferred and may be required) 

  • Local to the DMV area with the ability to work on site at Fort Meade as requested 

  • Five (5)+ years of relevant systems/operations engineering experience (flexible for candidates with exceptional PKI depth) 

  • Strong Linux (RHEL) systems administration and operations background, including patch management and system hardening 

  • Knowledge or experience with Linux containers and container orchestration (Podman / Docker) and VMs (KVM) 

  • Hands-on experience operating PKI, x.509, cryptography, and system/software security technologies 

  • Direct experience operating Red Hat Certificate System (RHCS) — this is a Red Hat solution. Dogtag PKI experience (RHCS's upstream open-source project) is an accepted alternative skillset, as is comparable enterprise CA platform operations (EJBCA, Microsoft AD CS, Entrust Authority, ISC CertAgent, or similar) 

  • Scripting/automation proficiency (Python, Bash, or similar) for operational tooling 

  • DoD 8570/8140 IAT Level II certification (Security+ or equivalent) 

  • Strong written and verbal communication skills, with a habit of documenting runbooks and operational procedures 

Stand Out With 

  • Prior DISA or DoD PKI program operations experience (Purebred, derived credentials, RA/CRL/OCSP operations at scale) 

  • HSM operations experience (Entrust nShield, Thales Luna) — the customer runs Entrust HSMs 

  • ACME protocol and certificate automation at scale 

  • Post-quantum cryptography familiarity (ML-DSA/Dilithium, Kyber, CNSA 2.0 timelines) from a migration/operations lens 

  • Configuration management and infrastructure-as-code (Ansible, or similar) 

  • Directory Server / LDAP operations experience 

  • Monitoring/observability tooling (Prometheus/Grafana, ELK, or similar) and incident response 

  • Agile / ITSM operating rhythms (Scrum, JIRA, change management) 

Skills Required

  • Active Secret clearance minimum (Top Secret preferred and may be required)
  • Local to the DMV area with ability to work on site at Fort Meade as requested
  • Five (5)+ years relevant systems/operations engineering experience (flexible for exceptional PKI depth)
  • Strong Linux (RHEL) systems administration and operations background, including patch management and hardening
  • Knowledge or experience with Linux containers and container orchestration (Podman / Docker) and VMs (KVM)
  • Hands-on experience operating PKI, x.509, cryptography, and system/software security technologies
  • Direct experience operating Red Hat Certificate System (RHCS) or equivalent enterprise CA platform (Dogtag, EJBCA, AD CS, Entrust, ISC CertAgent)
  • Scripting/automation proficiency (Python, Bash, or similar) for operational tooling
  • DoD 8570/8140 IAT Level II certification (Security+ or equivalent)
  • Strong written and verbal communication skills, documenting runbooks and operational procedures
  • Prior DISA or DoD PKI program operations experience (Purebred, derived credentials, RA/CRL/OCSP at scale)
  • HSM operations experience (Entrust nShield, Thales Luna)
  • ACME protocol and certificate automation at scale
  • Post-quantum cryptography familiarity (Dilithium, Kyber, CNSA 2.0) from an operations perspective
  • Configuration management / infrastructure-as-code (Ansible or similar)
  • Directory Server / LDAP operations experience
  • Monitoring/observability tooling and incident response (Prometheus/Grafana, ELK, or similar)
  • Familiarity with Agile / ITSM operating rhythms (Scrum, JIRA, change management)
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Rockville, MD
84 Employees
Year Founded: 1991

What We Do

August Schell is dedicated to delivering agile and innovative cybersecurity solutions to proactively defend and protect organization’s data against cyber attacks. Through our proven expertise with cybersecurity services and solutions, we are masters at designing, deploying and implementing highly secure solutions for on-premise and cloud based computing environments. We offer a wide range of next-generation products and services for: - Enterprise-Scale Identity Management, including Derived Credentials for Mobility - Big Data, including Security and Visualization related to Big Data Network Security and Visibility - Operational Intelligence - Data Center Security, including Firewalls, Endpoint Awareness/Management, and Virtualization - Cloud Security and Visibility - Application and Data Security - Software-Defined Data Center (SDDC), including Compute, Storage, Network & Backup We understand how critically important it is to defend critical digital assets and sensitive data from the constant threat of cyber attacks. We do not take this responsibility lightly and it’s with integrity that August Schell has defined our approach to our customers, without boundaries.

Similar Jobs

Pluralsight Logo Pluralsight

Marketing Manager

Edtech • Information Technology • Software
Remote or Hybrid
USA
1000 Employees
84K-110K Annually

SoFi Logo SoFi

Director, Strategic Finance - SoFi Checking & Savings and Credit Card

Fintech • Mobile • Software • Financial Services
Easy Apply
Remote or Hybrid
United States
4500 Employees
157K-270K Annually

GoodRx Logo GoodRx

Fp&a Manager

Consumer Web • Coupons • Healthtech • Social Impact • Pharmaceutical
Remote or Hybrid
USA
800 Employees
102K-216K Annually

Byrd's House Detective DBA BHD Home and Mold Inspections Logo Byrd's House Detective DBA BHD Home and Mold Inspections

Help Desk Specialist

Agency • Logistics • Real Estate • Virtual Reality • Consulting • Hospitality • Data Privacy
Remote or Hybrid
United States
100 Employees
35-45 Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account