PKI Engineer, Mid

ASM Research, An Accenture Federal Services Company

Little Rock (AR)

On-site

USD 125,000 - 137,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

ASM Research, An Accenture Federal Services Company, is seeking a Mid PKI Engineer to design, implement, and maintain enterprise PKI services that enable secure authentication, encryption, and digital signatures for mission-critical systems.

The role leads certificate lifecycle management across user, device, application, and service identities, integrating PKI with identity platforms, cloud services, and security controls in a federal IT environment. A SECRET clearance is required.

Qualifications

  • Bachelor’s degree in IT, Computer Science, Cybersecurity, or related field, or equivalent relevant experience.
  • 4–7 years of experience in security engineering or infrastructure roles with primary responsibility for architecting and operating PKI and certificate management solutions.
  • Deep understanding of PKI architectures, including CA hierarchies, trust models, OCSP/CRL mechanisms, and certificate lifecycle controls.
  • Strong familiarity with cryptographic standards and protocols such as TLS, S/MIME, and code signing, and their secure configuration in enterprise environments.
  • Hands‑on experience with enterprise PKI platforms and associated tooling, including integration with identity and network security services.
  • Strong analytical, problem‑solving, and communication skills, with the ability to document designs, policies, and operational procedures clearly.
  • Ability to obtain and maintain a SECRET security clearance, with U.S. citizenship required.

Responsibilities

  • Architect, deploy, and operate PKI infrastructures, including certificate authorities, registration authorities, and OCSP/CRL services across on‑premises and cloud environments.
  • Design and manage scalable certificate lifecycle processes (enrollment, distribution, renewal, revocation, and automation) for large fleets of endpoints, applications, and services.
  • Integrate PKI with enterprise systems such as identity platforms, VPN and Wi‑Fi authentication, TLS termination, secure email, and code signing, resolving complex interoperability and trust issues.
  • Implement and administer PKI platforms and tooling (for example, AD CS, commercial or cloud PKI, HSM‑backed key stores, or machine identity management solutions) with appropriate backup, monitoring, and high availability.
  • Define and maintain certificate policies, certification practice statements, and PKI runbooks that align with organizational and regulatory security requirements.
  • Lead troubleshooting of PKI and certificate‑related incidents, including chain and trust failures, protocol misconfigurations, and key management issues, and drive durable remediation.
  • Provide expert guidance to security, infrastructure, and application teams on cryptographic standards, key management, and secure PKI usage patterns.

Skills

PKI architectures
Certificate lifecycle management
Security engineering
Cryptography standards
Communication skills

Education

Bachelor’s degree in IT, Computer Science, Cybersecurity, or related field

Tools

AD CS
HSM-backed key stores

Job description

The PKI Engineer, Mid designs, implements, and maintains enterprise public key infrastructure services that underpin secure authentication, encryption, and digital signatures for mission‑critical systems. The role owns certificate lifecycle management processes, ensuring robust issuance, renewal, revocation, and automation patterns for user, device, application, and service identities.

Working in a federal IT environment, this position integrates PKI capabilities with identity platforms, network security controls, applications, and cloud services, resolving complex certificate and trust issues across heterogeneous environments. The engineer develops and enforces PKI policies, technical standards, and operational procedures, collaborating with security stakeholders to ensure resilience, compliance, and audit‑ready operation of the PKI.

Key Responsibilities
  • Architect, deploy, and operate PKI infrastructures, including certificate authorities, registration authorities, and OCSP/CRL services across on‑premises and cloud environments.

  • Design and manage scalable certificate lifecycle processes (enrollment, distribution, renewal, revocation, and automation) for large fleets of endpoints, applications, and services.

  • Integrate PKI with enterprise systems such as identity platforms, VPN and Wi‑Fi authentication, TLS termination, secure email, and code signing, resolving complex interoperability and trust issues.

  • Implement and administer PKI platforms and tooling (for example, AD CS, commercial or cloud PKI, HSM‑backed key stores, or machine identity management solutions) with appropriate backup, monitoring, and high availability.

  • Define and maintain certificate policies, certification practice statements, and PKI runbooks that align with organizational and regulatory security requirements.

  • Lead troubleshooting of PKI and certificate‑related incidents, including chain and trust failures, protocol misconfigurations, and key management issues, and drive durable remediation.

  • Provide expert guidance to security, infrastructure, and application teams on cryptographic standards, key management, and secure PKI usage patterns.

Required Qualifications
  • Bachelor’s degree in IT, Computer Science, Cybersecurity, or a related field, or equivalent relevant experience.

  • 4–7 years of experience in security engineering or infrastructure roles with primary responsibility for architecting and operating PKI and certificate management solutions.

  • Deep understanding of PKI architectures, including CA hierarchies, trust models, OCSP/CRL mechanisms, and certificate lifecycle controls.

  • Strong familiarity with cryptographic standards and protocols such as TLS, S/MIME, and code signing, and their secure configuration in enterprise environments.

  • Hands‑on experience with enterprise PKI platforms and associated tooling, including integration with identity and network security services.

  • Strong analytical, problem‑solving, and communication skills, with the ability to document designs, policies, and operational procedures clearly.

  • Ability to obtain and maintain a SECRET security clearance, with U.S. citizenship required.

Preferred Qualifications
  • Experience designing and operating enterprise‑grade PKI in regulated or government environments, including integration with hardware security modules and security monitoring tools.

  • Advanced security or PKI‑focused certifications (for example, CISSP or PKI‑specific credentials) that validate expertise in cryptography and certificate management.

  • Experience contributing to broader security architectures, policies, and best practices that rely on PKI.

Compensation Ranges

Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract‑specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.

EEO Requirements

It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.

All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment.

Physical Requirements

The physical requirements described in "Knowledge, Skills and Abilities" above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, "light office duties' or "lifting up to 50 pounds" or "some travel" required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions.

Disclaimer

The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.

$125k - $136,701

EEO Requirements

It is the policy of ASM that an individual's race, color, religion, sex, disability, age, gender identity, veteran status, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.

All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, veteran status, disability, gender identity, or age. All decisions on employment are made to abide by the principle of equal employment.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Identity Security - PKI Engineer
Identity Security - PKI Engineer

Intel • Phoenix (AZ)

On-site
USD 105,000 - 149,000
Stock bonuses
Health benefits
Retirement plan
Operations Security Advisor/Cybersecurity Incident Response Engineer, Sr
Operations Security Advisor/Cybersecurity Incident Response Engineer, Sr

ASM Research, An Accenture Federal Services Company • Little Rock (AR)

On-site
USD 80,000 - 111,000
Senior PKI Engineer
Senior PKI Engineer

State Street • Clifton (NJ)

On-site
USD 120,000 - 203,000
401K with company match
Insurance coverage including basiclife
Medical, dental, vision, long-term dis
+3
Senior PKI Engineer
Senior PKI Engineer

State Street • Devon (PA)

On-site
USD 120,000 - 203,000
401K with company match
Comprehensive insurance coverage
Paid time off including vacation and/​
Senior PKI Engineer
Senior PKI Engineer

State Street • Quincy (MA)

On-site
USD 120,000 - 203,000
401K with company match
Medical, dental, vision
Paid time off
+2
Identity Security - PKI Engineer
Identity Security - PKI Engineer

Worky • Chandler (AZ)

On-site
USD 105,000 - 149,000
Senior PKI Engineer
Senior PKI Engineer

State Street • Austin (TX)

On-site
USD 120,000 - 203,000
401K match
Medical Insurance (basic)
Paid time off
+3
Cryptography Engineer, Vice President
Cryptography Engineer, Vice President

State Street • Boston (MA)

On-site
USD 120,000 - 203,000
401K with company match
Comprehensive insurance coverage
Paid time off for various needs
+2
Cryptography Engineer, Vice President
Cryptography Engineer, Vice President

State Street • Quincy (MA)

On-site
USD 120,000 - 203,000
401K retirement savings plan with company match
Comprehensive health coverage
Paid time off including vacation and sick leave
PKI (Public Key Infrastructure) Specialist
PKI (Public Key Infrastructure) Specialist

Cymertek Corporation • Maryland

On-site
USD 120,000 - 180,000
Excellent Salaries
Flexible Work Schedule
401k with matching