Public Key Infrastructure (PKI) Architect

Capital Technology Group

United States

Hybrid

USD 120,000 - 160,000

Full time

9 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Remote Work
Medical Coverage
401(k)

Job summary

Capital Technology Group seeks a PKI Architect to design and modernize enterprise PKI and identity trust services for federal systems. This senior role requires deep cryptographic expertise, IAM, and scalable infrastructure across highly secure environments.

You will lead cloud-native deployments on AWS/Azure, automate infrastructure with Ansible and CI/CD, and collaborate with security and engineering teams to implement DevSecOps while aligning with NIST, FIPS, and Zero Trust principles.

Qualifications

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, Engineering, Mathematics, or a related technical field (or equivalent experience)
  • 4+ years of professional experience in PKI architecting, cybersecurity engineering, IAM, infrastructure/security architecture, or enterprise platform engineering
  • Experience designing and supporting PKI solutions in FICAM and Federal PKI (FPKI) environments
  • Experience with X.509 certificate lifecycle management, automation, and policy development
  • Knowledge of X.509 certificate policies and CA/Browser Forum standards
  • Experience implementing certificate automation using ACME
  • Experience with Hardware Security Modules (HSMs) and cryptographic key management
  • Familiarity with Post-Quantum Cryptography (PQC) concepts and migration strategies
  • Experience with PKI platforms including DigiCert, Entrust, Microsoft AD CS, and Let’s Encrypt
  • Experience supporting CAC/PIV smart cards, server, code-signing, and S/MIME certificates, including trust chains
  • Experience with AWS and/or Azure cloud platforms
  • Familiarity with DevSecOps, CI/CD pipelines, and GitHub Enterprise
  • Understanding of NIST, FISMA, FIPS, and Zero Trust principles

Responsibilities

  • Design, implement, and evolve PKI architectures that enable secure authentication and Zero Trust initiatives
  • Build and support cloud-native solutions across AWS and Azure environments
  • Automate infrastructure, deployments, and operational processes using Ansible and CI/CD pipelines
  • Partner with security and engineering teams to implement DevSecOps practices and secure software delivery
  • Support compliance initiatives aligned with NIST, FISMA, FIPS, and Zero Trust Architecture principles
  • Monitor, troubleshoot, and optimize application and platform performance using security and observability tools

Job description

Capital Technology Group provides expert consulting services software development, digital transformation, human-centered design, data analytics and visualization, and cybersecurity.

Our multidisciplinary teams use agile methodologies to rapidly and incrementally deliver value in close collaboration with our clients. For over a decade, we have been trusted by both federal and commercial clients to solve complex, mission-critical business challenges. The quality of our work has been recognized by our partners and peers through our inclusion in the Digital Services Coalition, a group of forward- thinking firms recognized for excellence in delivering IT services.

Client Requirements: applicants MUST BE US Citizens and be able to obtain Public Trust clearance

The CTG Experience

At Capital Technology Group (CTG), our teams are passionate about modernizing how the federal government delivers software. We partner with federal agencies to build secure, scalable, and mission-driven solutions that make a meaningful impact on millions of people. Recognized by The Washington Post as a Top Workplace in 2025 and 2026. CTG fosters a culture rooted in our core values. Our values guide how we work together and support one another, creating an environment where employees feel trusted, empowered, and encouraged to grow both personally and professionally.

About the Role

CTG is seeking a PKI Architect to design, implement, and modernize enterprise Public Key Infrastructure (PKI) and identity trust services supporting mission-critical federal systems. This role is ideal for a senior technical architect with deep expertise in cryptographic systems, identity security, and scalable infrastructure design across complex, highly secure environments.

You Will Get To
  • Design, implement, and evolve PKI architectures that enable secure authentication and Zero Trust initiatives
  • Build and support cloud-native solutions across AWS and Azure environments.
  • Automate infrastructure, deployments, and operational processes using Ansible and CI/CD pipelines.
  • Partner with security and engineering teams to implement DevSecOps practices and secure software delivery.
  • Support compliance initiatives aligned with FIPS, NIST 800-53, FISMA, and Zero Trust Architecture principles.
  • Monitor, troubleshoot, and optimize application and platform performance using security and observability tools.
Who You Are
  • A collaborative engineer who enjoys solving complex technical and security challenges.
  • Passionate about building scalable, secure, and reliable cloud-based solutions.
  • Comfortable working across application development, cloud infrastructure, identity, and security domains.
  • Skilled at balancing technical innovation with operational excellence and compliance requirements.
  • An effective communicator who can work with cross-functional teams and stakeholders.
Qualifications
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, Engineering, Mathematics, or a related technical field (or equivalent experience)
  • 4+ years of professional experience in PKI architecting, cybersecurity engineering, identity and access management (IAM), infrastructure/security architecture, or enterprise platform engineering (not limited to application development)
  • Experience designing and supporting PKI solutions in FICAM and Federal PKI (FPKI) environments.
  • Experience with X.509 certificate lifecycle management , automation, and policy development.
  • Knowledge of X.509 certificate policies and CA/Browser Forum standards.
  • Experience implementing certificate automation using ACME.
  • Experience with Hardware Security Modules (HSMs) and cryptographic key management.
  • Familiarity with Post-Quantum Cryptography (PQC) concepts and migration strategies.
  • Experience with PKI platforms including DigiCert , Entrust , Microsoft AD CS , and Let’s Encrypt.
  • Experience supporting CAC/PIV smart cards , server, code-signing, and S/MIME certificates, including certificate trust chains and validation.
  • Experience with cloud platforms such as AWS and/or Azure.
  • Familiarity with DevSecOps practices, CI/CD pipelines, and source control platforms such as GitHub Enterprise.
  • Understanding of security frameworks and standards including NIST, FISMA, FIPS, and Zero Trust principles.
Nice to Have
  • Experience using Docker and Kubernetes.
  • Experience with Shibboleth, CyberArk, or HashiCorp Vault.
  • Experience with Splunk, Tenable, Checkmarx, SonarQube, or related security tooling.
  • Experience with STIG hardening, vulnerability management, or compliance programs.
  • Familiarity with PIV authentication and identity governance solutions.
  • Experience supporting highly regulated environments, including federal or public sector organizations.
  • Relevant cloud, security, or architecture certifications.
Client Requirements
  • Applicants must be U.S. Citizens
  • Ability to obtain a Public Trust clearance
Salary

We are committed to offering a competitive salary for this position, with an estimated range of $120,000 to $160,000 annually. Please note that this range is intended to provide a general idea of what to expect. The final offer may vary based on experience, skills, and other factors.

Full Time Employee Benefits
  • Remote Work (Hybrid roles will be specified in the job post)
  • Competitive Compensation Package
  • Medical, Dental, and Vision
  • Life Insurance, Short/Long Term Disability
  • Employee Assistance Program
  • 401(k) with 4% matching
  • Liberal PTO vacation policy
  • Generous Annual Continuing Education
  • Annual Wellness BudgetBonus Incentive Programs (Employee referrals and performance-based rewards)

Thanks for your interest in Capital Technology Group!

Capital Technology Group is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

PKI Engineer
PKI Engineer

Capital Technology Group • United States

Hybrid
USD 100,000 - 130,000
Remote Work
Medical Insurance
Dental Insurance
+8
PKI Engineer
PKI Engineer

Capital Technology Group • Washington

Hybrid
USD 100,000 - 130,000
Remote Work
Medical, Dental, Vision
401(k) with 4% matching
+7
Senior Public Key Infrastructure (PKI) Engineer
Senior Public Key Infrastructure (PKI) Engineer

ZTI Solutions LLC • Merrifield (VA)

Hybrid
USD 150,000 - 210,000
4 weeks PTO
100% company-paid medical, dental, and
vision for employees and families
+3
Full Stack Engineer
Full Stack Engineer

Capital Technology Group • Silver Spring (MD)

Hybrid
USD 75,000 - 110,000
Remote Work
Competitive Compensation Package
Medical, Dental, and Vision
+4
PKI Engineer - Active TS/SCI With CI Poly
PKI Engineer - Active TS/SCI With CI Poly

ENS Solutions, LLC • Riverdale Park (MD)

On-site
USD 120,000 - 150,000
Medical/Dental/Vision coverages
401k from day 1
PTO + 11 holidays
+5
Public Key Infrastructure (PKI) Engineer #2840
Public Key Infrastructure (PKI) Engineer #2840

Genius Road, LLC • Dallas (TX)

On-site
USD 120,000 - 150,000
PKI Security Admin
PKI Security Admin

General Dynamics Corporation • Falls Church (VA), Northern (KY)

Hybrid
USD 97,000 - 131,000
401K with company match
Comprehensive health packages
Paid vacation and holidays
+1
PKI, Cryptography and Zero Trust Architect
PKI, Cryptography and Zero Trust Architect

Ironbow • Northern (KY)

Hybrid
USD 140,000 - 190,000
PKI, Cryptography and Zero Trust Architect
PKI, Cryptography and Zero Trust Architect

Iron Bow Technologies • Washington

On-site
USD 150,000 - 190,000
Software Developer
Software Developer

Capital-Technology-Group • Washington

Hybrid
USD 75,000 - 110,000
Remote Work
Medical Insurance
Dental Insurance
+7