PKI Operations Engineer

AUGUST SCHELL ENTERPRISES, INC.

Fort Meade (MD)

On-site

USD 120,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

August Schell Enterprises, Inc. seeks a PKI Operations Engineer to sustain and operate a DoD PKI environment in support of a DISA customer at Fort Meade. The role focuses on RHCS, CA availability, certificate lifecycle, and CVE remediation, with automation to reduce toil.

You will work hybrid and on-site as requested, collaborating with government and contractor teams, and supporting PQC migration and operational modernization efforts.

Qualifications

  • Active Secret clearance minimum (Top Secret preferred).
  • Local to the DMV area with ability to work on site at Fort Meade.
  • Five+ years of relevant systems/operations engineering experience.
  • Strong Linux (RHEL) systems administration and patching.
  • Experience with PKI, x.509, cryptography and security technologies.

Responsibilities

  • Operate and sustain the production PKI environment on RHCS.
  • Manage RA/CRL/OCSP operations and certificate lifecycle at scale.
  • onboard new customers, enclaves, and use cases onto the PKI.
  • Own CVE remediation and patch management for PKI and hosts.
  • Monitor system health; build alerting, logging, dashboards; incident response.
  • Operate and troubleshoot HSM integrations supporting CA operations.

Skills

PKI operations
RHEL Linux
Python/Bash scripting
ACME/CA automation
HSM operations
RHCS/Dogtag

Tools

RHCS (Red Hat Certificate System)
Podman/Docker
KVM virtualization
LDAP/Directory Services

Job description

PKI Operations Engineer
Ft. Meade, MD — Full Time (Hybrid)

August Schell is looking for a PKI Operations Engineer to sustain andoperateDoD enterprise Public Key Infrastructure in support of our DISA customer. This is a Red Hat Certificate System (RHCS) solution. Where our PKI Software Engineer builds the next-generation certificate-systems code, this role keeps the infrastructure running: operating and hardening the live RHCS environment, standing up new customers and enclaves, driving CVE remediation and patch cycles, monitoring system health, and automating the operational toil that keeps a high-volume CA reliable. The engineer workshand-in-handwith commercial product engineering, government operations teams, and other program contractors — including through the environment's post-quantum cryptography (PQC) migration.

Individuals in this role must be able to work hybrid and go on site at Fort Meade as requested.

Responsibilities Include
  • Operate and sustain the production PKI environment on Red Hat Certificate System (RHCS) — CA availability, certificate lifecycle operations, and the day-to-day health of the issuance pipeline

  • Run RA/CRL/OCSP operations and certificate lifecycle management, including the transition to shorter-lived certificates at higher issuance volume (ACME automation)

  • Onboard new customers, enclaves, and use cases onto the PKI — configuration, integration, and secure hardening of new environments to program standards

  • Own CVE remediation and patch management for the PKI stack and its underlying RHEL hosts — track, test, schedule, and apply security patches with minimal disruption to CA operations

  • Monitor system health and performance; build andmaintainalerting, logging, and dashboards; respond to and resolve operational incidents, and lead root-cause analysis

  • Operate and troubleshoot HSM integrations (EntrustnShield/ Thales Luna) supporting CA operations and key escrow

  • Automate operational tasks — health checks, backups, certificate/CRL monitoring,deploymentand configuration — using scripting and CI/CD tooling to reduce toil and manual error

  • Support the program's PQC migration from an operations standpoint (algorithm rollout, version transition, validation in the live environment)

  • Provide development support in an operational capacity asadditionalvalue — small fixes, config-as-code, tooling, and reproduction of issues for the product engineering team — without owning the core feature-development backlog

  • Communicate clearly across government operations stakeholders, commercial vendor engineering, and program contractors; document runbooks and elevate risks and blockers before theyimpactoperations

Requirements
  • Active Secret clearance minimum (Top Secret preferred and may berequired)

  • Local to the DMV area with the ability to work on site at Fort Meade as requested

  • Five (5)+years of relevant systems/operations engineering experience (flexible for candidates with exceptional PKI depth)

  • Strong Linux (RHEL) systems administration and operations background, including patch management and system hardening

  • Knowledge or experience with Linux containers and container orchestration (Podman/ Docker) and VMs (KVM)

  • Hands-on experience operating PKI, x.509, cryptography, and system/software security technologies

  • Direct experienceoperatingRed Hat Certificate System (RHCS) — this is a Red Hat solution.DogtagPKI experience (RHCS's upstream open-source project) is an accepted alternative skillset, as is comparable enterprise CA platform operations (EJBCA, Microsoft AD CS, Entrust Authority, ISCCertAgent, or similar)

  • Scripting/automationproficiency(Python, Bash, or similar) for operational tooling

  • DoD 8570/8140 IAT Level II certification (Security+ or equivalent)

  • Strong written and verbal communication skills, with a habit of documenting runbooks and operational procedures

Stand Out With
  • Prior DISA or DoD PKI program operations experience (Purebred, derived credentials, RA/CRL/OCSP operations at scale)

  • HSM operations experience (EntrustnShield, Thales Luna) — the customer runs Entrust HSMs

  • ACME protocol and certificate automation at scale

  • Post-quantum cryptography familiarity (ML-DSA/Dilithium, Kyber, CNSA 2.0 timelines) from a migration/operations lens

  • Configuration management and infrastructure-as-code (Ansible, or similar)

  • Directory Server / LDAP operations experience

  • Monitoring/observability tooling (Prometheus/Grafana, ELK, or similar) and incident response

  • Agile / ITSM operating rhythms (Scrum, JIRA, change management)

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

PKI Operations Engineer
PKI Operations Engineer

August Schell • Fort Meade (MD)

Hybrid
USD 120,000 - 170,000
PKI Software Engineer
PKI Software Engineer

August Schell • Fort Meade (MD)

Hybrid
USD 140,000 - 170,000
PKI Software Engineer
PKI Software Engineer

AUGUST SCHELL ENTERPRISES, INC. • Fort Meade (MD)

Hybrid
USD 140,000 - 170,000
PKI Operations Engineer – Hybrid (Fort Meade)
PKI Operations Engineer – Hybrid (Fort Meade)

AUGUST SCHELL ENTERPRISES, INC. • Fort Meade (MD)

Hybrid
USD 120,000 - 160,000
Hybrid PKI Operations Engineer - DoD Enterprise CA
Hybrid PKI Operations Engineer - DoD Enterprise CA

August Schell • Fort Meade (MD)

Hybrid
USD 120,000 - 170,000
PKI Engineer
PKI Engineer

ACL Digital • Atlanta (GA)

On-site
USD 110,000 - 170,000
Cyber PKI Administrator
Cyber PKI Administrator

SHR CONSULTING GROUP, LLC • Arlington (VA)

On-site
USD 110,000 - 150,000
Medical, dental, vision
401(k) with company contribution
Paid time off
+2
Public Key Infrastructure (PKI) Engineer #2840
Public Key Infrastructure (PKI) Engineer #2840

Genius Road, LLC • Dallas (TX)

On-site
USD 120,000 - 150,000
Cyber PKI Administrator
Cyber PKI Administrator

SHR Consulting Group • Arlington (VA)

On-site
USD 120,000 - 180,000
Medical, dental, vision
401(k) with company contribution
PTO + federal holidays
+1
Public Key Infrastructure (PKI) Engineer
Public Key Infrastructure (PKI) Engineer

The Amatriot Group • Dallas (TX)

Hybrid
USD 85,000 - 145,000