PKI and Certificate Cybersecurity Engineer

Request Technology, LLC

Austin (TX)

On-site

USD 140,000 - 190,000

Full time

37 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Prestigious Global Firm is seeking a Senior PKI Cybersecurity Engineer to lead certificate lifecycle management and PKI operations across IT and business teams.

You will manage encryption keys, HSMs, and secure cryptographic controls while advancing endpoint, cloud, and identity security with automation and strong governance.

Qualifications

  • Bachelor’s degree or equivalent professional experience required; security certifications preferred.
  • 5–8+ years IT experience, including 3–5+ years in cybersecurity engineering or related security role.
  • Advanced PKI and cryptography expertise with PKI lifecycle management, AD CS, encryption key management, and HSMs.
  • Strong knowledge of EDR, SIEM, threat detection, hunting, and incident response processes.
  • Hands-on experience with listed security platforms (CrowdStrike, Microsoft Sentinel, Netskope, etc.).
  • Deep understanding of authentication, federation, conditional access, privileged access management, and modern identity platforms.
  • Cloud security experience in Microsoft Azure and Microsoft Entra; knowledge of Zero Trust and secure architectures.
  • Proficiency in PowerShell, Python, and KQL for security automation and telemetry.

Responsibilities

  • Manage full lifecycle of digital certificates and PKI environments (AD CS).
  • Administer encryption key management platforms and HSMs for secure crypto handling.
  • Design and implement security controls across network, endpoint, cloud, and identity domains.
  • Optimize EDR, SIEM, DLP, CASB and related platforms for improved detection and response.
  • Identify security gaps and lead remediation initiatives to strengthen security posture.
  • Provide technical leadership and collaborate with IT, architecture, product, and project teams.
  • Advance secure endpoint and identity practices with infrastructure and business teams.
  • Develop and maintain security standards, patterns, and baselines aligned with NIST/CIS.
  • Enhance security operations via scripting, automation, telemetry optimization.

Skills

Security engineering
Threat detection
Incident response
Automation
PKI & cryptography
Identity & access management
Cloud security
Azure security

Education

Bachelor's degree
Certifications: CISSP, OSCP, AZ-500

Tools

CrowdStrike
Microsoft Sentinel
Google SecOps
Netskope
Cisco Umbrella
BeyondTrust
Cribl
DigiCert
CyberArk Certificate Management (Venafi)
Microsoft Entra

Job description

***We are unable to sponsor for this permanent full-time role***

***Position is bonus eligible***

Prestigious Global Firm is currently seeking a Senior PKI Cybersecurity Engineer with strong Certificate Management experience. Candidate will work across a broad range of cybersecurity domains—including Public Key Infrastructure (PKI), certificate lifecycle management, endpoint security, cloud security, identity protection, and security operations—while partnering with teams across Information Technology (IT), architecture, and business functions to ensure secure and scalable technology solutions.

Responsibilities:

  • Certificate & PKI Management: Manage the full lifecycle of digital certificates, including discovery, issuance, renewal, monitoring, revocation, and automation, while administering Public Key Infrastructure (PKI) and Microsoft Active Directory Certificate Services (AD CS) environments.
  • Encryption & Key Security: Administer enterprise encryption key management platforms and Hardware Security Modules (HSMs), ensuring secure generation, storage, rotation, archival, and destruction of cryptographic keys.
  • Security Engineering: Design, implement, maintain, and continuously improve network, endpoint, cloud, and identity security controls through monitoring, tuning, and automation.
  • Threat Detection & Response: Optimize Endpoint Detection and Response (EDR), Security Information and Event Management (SIEM), Data Loss Prevention (DLP), Cloud Access Security Broker (CASB), and related security platforms to improve visibility, detection accuracy, and response effectiveness.
  • Risk Reduction: Identify security gaps, control weaknesses, and misconfigurations, then lead remediation initiatives and implement long-term solutions that strengthen the security posture.
  • Technical Leadership: Serve as a lead contributor on security initiatives, partnering with Information Technology (IT), architecture, product, and project teams to support secure onboarding and integration of applications and platforms.
  • Identity & Access Security: Advance secure endpoint and identity practices by collaborating with infrastructure and business teams to improve protection of critical systems and data.
  • Standards & Governance: Develop and maintain security standards, engineering patterns, and baselines aligned with industry frameworks such as the National Institute of Standards and Technology (NIST) and Center for Internet Security (CIS).
  • Automation & Operational Excellence: Enhance security operations through scripting, workflow automation, telemetry optimization, and continuous process improvement.
  • Mentorship & Knowledge Sharing: Support team growth through mentoring, documentation, reusable solutions, and technical guidance for less experienced engineers.
  • Incident & Escalation Support: Act as an escalation point for complex security issues, contributing to incident response readiness, runbooks, and on-call support processes.
  • Innovation & Technology Evaluation: Research emerging security technologies and recommend solutions that improve operational efficiency and reduce organizational risk.

Qualifications:

  • Education & Certifications: Bachelor’s degree or equivalent professional experience required. Industry certifications such as CompTIA Security+, Certified Information Systems Security Professional (CISSP), Offensive Security Certified Professional (OSCP), SC-200, or AZ-500 are preferred.
  • Relevant Experience: 5-8+ years of Information Technology (IT) experience, including 3-5+ years in cybersecurity engineering or a closely related security-focused role.
  • PKI & Cryptography Expertise: Advanced experience with digital certificate lifecycle management, Public Key Infrastructure (PKI), Microsoft Active Directory Certificate Services (AD CS), encryption key management platforms, and Hardware Security Modules (HSMs).
  • Security Operations Expertise: Strong knowledge of Endpoint Detection and Response (EDR), Security Information and Event Management (SIEM), threat detection, threat hunting, and incident response processes.
  • Security Platform Experience: Hands‑on experience with technologies such as CrowdStrike, Microsoft Sentinel, Google SecOps, Netskope, Cisco Umbrella, BeyondTrust, Cribl, DigiCert, CyberArk Certificate Management (formerly Venafi), and Microsoft Entra.
  • Identity & Access Management: Deep understanding of authentication, federation, conditional access, privileged access management, and modern identity platforms.
  • Cloud & Enterprise Security: Experience implementing and supporting cloud security controls, particularly within Microsoft Azure and Microsoft Entra environments, with knowledge of Zero Trust principles and secure architecture practices.
  • Automation & Scripting: Ability to improve security operations through automation using tools and languages such as PowerShell, Python, and Kusto Query Language (KQL).
  • Problem Solving: Proven ability to troubleshoot and resolve complex technical and security issues across multiple systems, platforms, and teams.
  • Communication & Collaboration: Strong ability to translate technical concepts into actionable insights, influence stakeholders, and work effectively across technical and non-technical teams.
  • Business Mindset: Customer-focused approach with the ability to balance security, risk management, and business objectives while managing multiple priorities.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer
Senior Security Engineer

Request Technology, LLC • Chicago (IL)

On-site
USD 120,000 - 165,000
Senior Security Engineer
Senior Security Engineer

Request Technology, LLC • Austin (TX)

On-site
USD 125,000 - 170,000
PKI Engineer
PKI Engineer

ACL Digital • Atlanta (GA)

On-site
USD 110,000 - 170,000
Senior PKI Engineer
Senior PKI Engineer

Insight Global • Charlotte (NC)

On-site
USD 120,000 - 140,000
Public Key Infrastructure (PKI) Engineer #2840
Public Key Infrastructure (PKI) Engineer #2840

Genius Road, LLC • Dallas (TX)

On-site
USD 120,000 - 150,000
Public Key Infrastructure (PKI) Engineer
Public Key Infrastructure (PKI) Engineer

The Amatriot Group • Dallas (TX)

Hybrid
USD 85,000 - 145,000
Security (PKI) Engineer
Security (PKI) Engineer

KPG99 INC • Rosemont (IL)

On-site
USD 120,000 - 180,000
Senior PKI Engineer
Senior PKI Engineer

Charles Schwab • Phoenix (AZ)

On-site
USD 150,000 - 190,000
401(k) with company match
Sabbatical after 5 years
Parental leave and family benefits
+2
PKI Engineer - Active TS/SCI With CI Poly
PKI Engineer - Active TS/SCI With CI Poly

ENS Solutions, LLC • Riverdale Park (MD)

On-site
USD 120,000 - 150,000
Medical/Dental/Vision coverages
401k from day 1
PTO + 11 holidays
+5
PKI Security Engineer
PKI Security Engineer

Mindlance • Eagan (MN)

On-site
USD 100,000 - 130,000