Senior Public Key Infrastructure (PKI) Engineer

ZTI Solutions LLC

Merrifield (VA)

Hybrid

USD 150,000 - 210,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

4 weeks PTO
100% company-paid medical, dental, and
vision for employees and families
4% matching 401(k)
Certification reimbursement
Flexible hybrid work environment

Job summary

ZTI Solutions LLC is seeking a Senior Public Key Infrastructure (PKI) Engineer to architect, automate, and modernize enterprise PKI supporting DoD and Federal customers. This role focuses on enterprise server PKI, certificate lifecycle automation, and trust services to modernize CA infrastructure and support post-quantum planning.

You will collaborate with security teams, integrate PKI with AD, Azure, AWS, and DevSecOps pipelines, and help advance Zero Trust initiatives in mission-critical

Qualifications

  • Excellent analytical, problem-solving, and communication skills.
  • Experience administering enterprise PKI environments (AD CS or equivalent).
  • Experience automating certificate lifecycle management at scale.
  • Strong understanding of X.509, CRL/OCSP, and key management.

Responsibilities

  • Architect, deploy, administer, and maintain enterprise PKI environments and CA infrastructure (AD CS).
  • Design and manage enterprise server certificate strategies across Windows, Linux, virtualization, cloud, web services, APIs, and load balancers.
  • Automate certificate lifecycle management (issuance, renewal, revocation, monitoring) using automation tools.
  • Deploy, manage, and troubleshoot TLS/SSL certificates and trust chains across the enterprise.
  • Integrate PKI services with Active Directory, Azure, AWS, virtualization platforms, and DevSecOps pipelines.
  • Support Zero Trust initiatives through machine identity and certificate-based trust.
  • Support post-quantum cryptography planning and CNSA 2.0 migration.
  • Ensure PKI environments comply with NIST, FIPS, DISA STIGs, and RMF requirements.
  • Participate in incident response for certificate compromise or trust-related events.
  • Maintain technical documentation and architecture diagrams.
  • Provide technical leadership and mentorship to junior engineers.

Skills

Analytical
Problem-solving
Communication

Tools

AD CS
Windows Server
Linux
Azure
AWS
Terraform
Ansible
PowerShell
Python
Bash

Job description

Summary

ZTI Solutions is seeking a Senior Public Key Infrastructure (PKI) Engineer to architect, automate, and modernize enterprise PKI supporting Department of Defense and Federal customers.

This position focuses on enterprise server PKI, certificate lifecycle automation, and infrastructure trust services, not end-user certificate administration. You will modernize CA infrastructure, automate certificate management at scale, support post-quantum cryptography transition planning, and help shape Zero Trust initiatives in mission-critical DoD environments.

ZTI will sponsor Top Secret clearance processing. Benefits include 100% company-paid medical, dental, and vision for you and your family, 4 weeks PTO, and certification reimbursement.

Key Responsibilities
  • Architect, deploy, administer, and maintain enterprise PKI environments and Certificate Authority (CA) infrastructure, including Microsoft Active Directory Certificate Services (AD CS).
  • Design and manage enterprise server certificate strategies across Windows, Linux, virtualization, cloud, web services, APIs, and load balancers.
  • Automate certificate lifecycle management (issuance, renewal, revocation, expiration monitoring, key rotation, reporting) using ACME, SCEP/EST, REST APIs, PowerShell, Python, Bash, Ansible, or Terraform.
  • Deploy, manage, and troubleshoot TLS/SSL certificates, trust chains, and certificate validation across the enterprise.
  • Integrate PKI services with Active Directory, Azure, AWS, virtualization platforms, and DevSecOps pipelines.
  • Support Zero Trust initiatives through machine identity and certificate-based trust.
  • Support planning for post-quantum cryptography and CNSA 2.0 migration.
  • Ensure PKI environments comply with NIST, FIPS, DISA STIGs, and RMF requirements.
  • Participate in incident response for certificate compromise or trust-related events.
  • Maintain technical documentation, architecture diagrams, SOPs, and configuration baselines.
  • Provide technical leadership and mentorship to junior engineers.
Requirements
  • U.S. Citizen with an active Secret clearance; eligible for Top Secret (ZTI sponsors processing).
  • Hybrid: up to 3 days/week onsite in Fairfax, VA.
  • DoD 8140 IAT Level II certification (Security+ CE or higher), or ability to obtain within 90 days.
  • 8+ years of systems/security engineering experience with 4+ years focused on enterprise PKI (or 12 years total without a degree).
  • Experience administering AD CS or comparable enterprise PKI platforms.
  • Experience automating certificate lifecycle management at scale.
  • Experience administering Windows Server and/or Linux.
  • Strong understanding of X.509, CRL/OCSP, enterprise trust models, cryptographic algorithms, and key management.
  • Excellent analytical, problem-solving, and communication skills.
Preferred Qualifications
  • CISSP, Azure Security Engineer Associate, or AWS Certified Security - Specialty.
  • Experience with Entrust, DigiCert, EJBCA, Keyfactor, Venafi, or similar platforms.
  • Hardware Security Module (HSM) experience.
  • Azure Government, AWS GovCloud, or hybrid cloud environments.
  • PKI integration with Kubernetes, containers, or service mesh.
  • Experience supporting DoD RMF, FedRAMP, or CMMC compliance initiatives.
Benefits
  • 4 weeks PTO plus all federal holidays paid.
  • 100% company-paid medical, dental, and vision for employees and their families.
  • 4% matching 401(k).
  • Professional training and certification reimbursement.
  • Flexible hybrid work environment.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

PKI Engineer - Active TS/SCI With CI Poly
PKI Engineer - Active TS/SCI With CI Poly

ENS Solutions, LLC • Riverdale Park (MD)

On-site
USD 120,000 - 150,000
Medical/Dental/Vision coverages
401k from day 1
PTO + 11 holidays
+5
Senior PKI Engineer - Enterprise Certificate Automation
Senior PKI Engineer - Enterprise Certificate Automation

ZTI Solutions LLC • Merrifield (VA)

Hybrid
USD 150,000 - 210,000
4 weeks PTO
100% company-paid medical, dental, and
vision for employees and families
+3
PKI Engineer - Active TS/SCI With CI Poly
PKI Engineer - Active TS/SCI With CI Poly

ENS Solutions, LLC • McLean (VA)

On-site
USD 110,000 - 165,000
Free Platinum-Level Medical/Dental/VIP
401k Contribution from Day 1
PTO + 11 Paid Federal Holidays
+1
PKI Engineer - Active TS/SCI With CI Poly
PKI Engineer - Active TS/SCI With CI Poly

ENS Solutions, LLC • Reston (VA)

On-site
USD 90,000 - 130,000
401k Contribution from Day 1
PTO + 11 Paid Federal Holidays
Long & Short Term Disability Insurance
+3
PKI Systems Administrator
PKI Systems Administrator

A3T (Agil3 Technology Solutions) • Mechanicsburg

On-site
USD 90,000 - 130,000
PKI / Certificate Management Engineer (R-00198)
PKI / Certificate Management Engineer (R-00198)

Socket.dev • United States

Remote
USD 140,000 - 190,000
Competitive salary
Medical coverage
401k program
+1
PKI Systems Administrator (CAA)
PKI Systems Administrator (CAA)

A3T (Agil3 Technology Solutions) • Oklahoma

On-site
USD 70,000 - 90,000
Medical Insurance
Dental Insurance
Vision Insurance
+7
PKI Engineer - Active TS/SCI with CI Poly
PKI Engineer - Active TS/SCI with CI Poly

ENS Solutions, LLC • Washington

On-site
USD 90,000 - 120,000
Free Platinum-Level Medical/Dental/Vision coverage
401k Contribution from Day 1
PTO + 11 Paid Federal Holidays
+3
Public Key Infrastructure (PKI) Engineer
Public Key Infrastructure (PKI) Engineer

The Amatriot Group • Dallas (TX)

Hybrid
USD 85,000 - 145,000
PKI Software Engineer
PKI Software Engineer

August Schell • Fort Meade (MD)

Hybrid
USD 140,000 - 170,000