Senior PKI Engineer
HCC Consulting LLC · Remote, US
Apply directly on HCC Consulting LLC’s careers site — no account needed.
About the role
Position Summary
HCC Consulting is seeking a Senior PKI Engineer to support the modernization, administration, and optimization of enterprise Public Key Infrastructure (PKI) services for a federal customer. The successful candidate will be responsible for maintaining secure certificate services, improving PKI resiliency, implementing modern cryptographic solutions, and supporting enterprise identity and authentication services.
Responsibilities
- Design, implement, and administer enterprise PKI environments.
- Manage Root and Issuing Certificate Authorities (CAs), Online Certificate Status Protocol (OCSP) Responders, Certificate Revocation Lists (CRLs), and Registration Authorities.
- Administer certificate lifecycle management, including certificate issuance, renewal, revocation, recovery, and expiration monitoring.
- Configure and maintain Hardware Security Modules (HSMs) and cryptographic key management solutions.
- Support TLS/SSL certificates, code-signing certificates, S/MIME, client authentication, server authentication, and digital signature services.
- Integrate PKI services with Active Directory, Microsoft Entra ID, cloud platforms, enterprise applications, and identity management solutions.
- Monitor PKI health, troubleshoot certificate trust issues, and resolve authentication and encryption problems.
- Implement certificate lifecycle automation using PowerShell, Python, or other scripting tools.
- Support disaster recovery, backup, restoration, and high-availability configurations for PKI infrastructure.
- Develop and maintain PKI architecture documentation, standard operating procedures, and technical implementation guides.
- Ensure compliance with applicable federal cybersecurity standards, including NIST and FIPS requirements.
- Collaborate with cybersecurity, infrastructure, network, and application teams to support secure enterprise operations.
Required Qualifications
- Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, Engineering, or equivalent experience.
- Minimum of 8 years of IT infrastructure or cybersecurity experience.
- Minimum of 5 years of enterprise PKI engineering experience.
- Experience administering Microsoft Active Directory Certificate Services (AD CS) or comparable enterprise PKI platforms.
- Strong understanding of X.509 certificates, Certificate Authorities, OCSP, CRLs, TLS/SSL, digital certificates, and cryptographic key management.
- Experience with Hardware Security Modules (HSMs).
- Experience with Windows Server, Active Directory, DNS, LDAP, and enterprise authentication.
- Experience developing PowerShell or Python automation scripts.
- Strong troubleshooting and analytical skills.
- Excellent written and verbal communication skills.
- U.S. Citizenship.
Preferred Qualifications
- Experience supporting federal civilian or DoD agencies.
- Experience with Federal PKI (FPKI), PIV/CAC authentication, and enterprise identity management.
- Experience with AWS Certificate Manager, AWS Private CA, Azure Key Vault, AWS CloudHSM, or similar technologies.
- Familiarity with Zero Trust Architecture and Identity, Credential, and Access Management (ICAM).
- Relevant certifications such as CISSP, Security+, CCSP, Microsoft, AWS, or PKI-related certifications.
Pay: $70.00 - $85.00 per hour
Work Location: Remote
Description sourced from the public Indeed listing — this role isn't indexed from the company's career page yet.
Skills
- Python
Never be applicant #200 again
Every job here is indexed straight from company career pages — often hours after it opens, before it reaches the big boards. Create a free account and get your best matches in a twice-daily digest.
- Your best matches, twice a day
- No duplicates, no ghost jobs, no recruiter spam
- Every job free to browse — pay only when you apply
Free account — no card required
93 160 live jobs · 17 643 companies tracked · 6 168 added today