Turn this role into an interview — a resume and cover letter built around what this employer wants.
Private Advertiser is seeking a PKI Engineer to implement and operate our Public Key Infrastructure, including CA/RA, HSM operations, OCSP, CRL, and timestamping. You’ll manage the certificate lifecycle and ensure secure key management across business systems.
You will collaborate with cybersecurity, infrastructure, and applications teams to maintain high availability and compliance, while improving security hardening and incident response capabilities.
Implement, operate, monitor, and support Public Key Infrastructure (PKI) services, including Certificate Authority (CA), Registration Authority (RA), Hardware Security Module (HSM), Online Certificate Status Protocol (OCSP), Certificate Revocation List (CRL), timestamping, and related trust services.
Manage certificate lifecycle activities, including certificate issuance, renewal, revocation, validation, and secure key management.
Support integration between PKI services and business applications, systems, or customer-facing platforms.
Perform troubleshooting, system monitoring, incident support, vulnerability remediation, system hardening, and change implementation.
Maintain technical documentation, operational procedures, audit evidence, and compliance records in line with internal policies and regulatory requirements.
Work closely with cybersecurity, infrastructure, application, and operations teams to ensure PKI services remain secure, reliable, scalable, and highly available.
The PKI Engineer is responsible for managing and supporting the organisation’s Public Key Infrastructure and digital trust services. The role covers CA and RA systems, HSM operations, certificate issuance and revocation, OCSP and CRL services, timestamping, and integration with business applications. The candidate will ensure that PKI platforms are secure, highly available, properly documented, and aligned with compliance, audit, and operational requirements. This position also supports monitoring, troubleshooting, system hardening, incident response, change implementation, and continuous improvement activities to strengthen the organisation’s trust infrastructure. The candidate should have strong technical knowledge in cryptography, security infrastructure, operating systems, networking, and secure system administration, with the ability to work collaboratively across technical and business teams.
QUALIFICATIONS
Bachelor’s Degree in Computer Science, Information Technology, Cybersecurity, Engineering, or equivalent experience.
Minimum 2–5 years of experience in PKI, cybersecurity, systems administration, infrastructure operations, or related technical roles.
Knowledge of X.509 certificates, certificate lifecycle management, CA/RA operations, HSM, OCSP, CRL, TLS/SSL, encryption, key management, and authentication technologies.
Experience with Windows Server, Linux, networking, scripting, monitoring tools, incident handling, change management, documentation, and security hardening.
Relevant certifications such as Security+, CISSP, CEH, Microsoft, Linux, cloud, or PKI-related certification will be an added advantage.