FREE ACCESS
5,000–10,000 jobs/day
See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

PKI, Certificate Management Engineer
True Zero Technologies, LLCPKI engineer managing enterprise certificates, HSMs, and Zero Trust authentication. Supporting True Zero Technologies’ regulated government and defense security environments.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in designing, implementing, and managing enterprise Public Key Infrastructure (PKI) with a strong focus on certificate lifecycle management, cryptographic operations, and integration with cloud services. Proficient in ensuring compliance with Federal and DoD PKI standards while maintaining secure communications and governance practices.
Highest-signal resume keywords
Public Key Infrastructure (PKI) ManagementCertificate Lifecycle ManagementAWS Certificate ManagerAutomated Certificate Issuance (ACME)Cryptography and Encryption
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
X.509 CertificatesCertificate AuthoritiesTrust ChainsKey ManagementRevocation ManagementMTLS ImplementationTLS ConfigurationCertificate DiscoveryCryptographic AlgorithmsSecure Communications
Soft Skills
GovernanceRisk ManagementDocumentationTroubleshootingCross-Functional Collaboration
Tools & Technologies
AWS Private Certificate AuthorityAWS CloudHSMIAM PlatformsDirectory ServicesNetwork Infrastructure
Certifications & Qualifications
AWS Certified Security – SpecialtyMicrosoft Certified: Cybersecurity Architect Expert (SC-100)Red Hat Certified Engineer (RHCE)Microsoft Certified: Windows Server Hybrid Administrator AssociateEntrust or DigiCert PKI Certifications
Industry Keywords
Federal PKIDoD PKICAC/PIV AuthenticationZero Trust ArchitecturesFIPS-Validated Cryptography
Tech Stack
Tools & technologiesAWSCloudCyber SecurityLinux
About the role
Key responsibilities & impact- Design, implement, and maintain enterprise Public Key Infrastructure (PKI) supporting internal and external certificate requirements
- Manage the full certificate lifecycle, including request, issuance, validation, distribution, renewal, revocation, expiration, and retirement
- Implement and maintain ACME-based certificate automation and automated enrollment and renewal workflows
- Manage certificates across Windows, Linux, cloud platforms, containers, applications, load balancers, network devices, and other enterprise systems
- Design and operate integrations with AWS Private Certificate Authority, AWS Certificate Manager, and related AWS services
- Implement and administer HSM capabilities, including AWS CloudHSM, for private-key protection and cryptographic operations
- Support Federal PKI and DoD PKI trust relationships, certificate chains, and interoperability requirements
- Integrate CAC/PIV authentication with enterprise applications, identity platforms, operating systems, and secure access workflows
- Implement and maintain mutual TLS (mTLS) for workload identity, service-to-service authentication, and Zero Trust communications
- Ensure cryptographic implementations use FIPS-validated modules and approved algorithms where required
- Establish certificate discovery, inventory, monitoring, and alerting to identify unmanaged certificates and prevent expiration-related outages
- Develop governance standards for certificate ownership, issuance, naming, key length, algorithms, renewal periods, revocation, and retention
- Integrate certificate management with IAM platforms and authentication workflows
- Support secure networking and communications through TLS, mTLS, certificate-based authentication, and encryption standards
- Monitor PKI platform health, certificate status, revocation services, HSM operations, and certificate expiration events
- Troubleshoot certificate-chain, trust-store, TLS, cryptographic, enrollment, renewal, and authentication issues
- Partner with cybersecurity, identity, cloud, platform, network, and application teams to integrate PKI services into enterprise architectures and deployment workflows
- Maintain PKI architecture documentation, certificate policies, operational procedures, runbooks, governance standards, and audit evidence
Requirements
What you’ll need- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related technical discipline
- Demonstrated experience designing, implementing, or administering enterprise Public Key Infrastructure (PKI)
- Strong knowledge of X.509 certificates, certificate authorities, trust chains, cryptographic algorithms, key management, revocation, and certificate lifecycle management
- Experience implementing automated certificate issuance and renewal using ACME or comparable technologies
- Experience managing certificates across Windows, Linux, cloud, containerized, network, and application environments
- Hands-on experience with AWS Private CA, AWS Certificate Manager, AWS CloudHSM, or comparable cloud PKI and HSM technologies
- Strong understanding of cryptography, encryption, digital signatures, hashing, key exchange, and secure communications
- Experience integrating PKI with IAM, directory services, applications, network infrastructure, and cloud services
- Familiarity with Federal PKI, DoD PKI, CAC/PIV authentication, and government certificate trust models
- Experience implementing mTLS and certificate-based workload identity in Zero Trust architectures
- Familiarity with FIPS-validated cryptography and cryptographic requirements for government or regulated environments
- Experience with certificate discovery, inventory management, expiration monitoring, and proactive renewal processes
- Strong understanding of TLS configuration, secure networking, trust stores, certificate validation, and PKI troubleshooting
- Experience supporting AWS GovCloud, government, defense, or other regulated environments is preferred
- Strong governance, risk management, documentation, troubleshooting, and cross-functional collaboration skills
- Preferred certifications: AWS Certified Security – Specialty; Microsoft Certified: Cybersecurity Architect Expert (SC-100); Red Hat Certified Engineer (RHCE); Microsoft Certified: Windows Server Hybrid Administrator Associate; Entrust or DigiCert PKI certifications, where applicable
Benefits
Comp & perks- Competitive salary, paid twice per month
- Best in class medical coverage
- 100% of medical premiums covered by True Zero
- Company wide new business incentive programs
- Contribution Incentives (i.e. white papers, blog posts, internal webinars, etc.)
- 3 weeks of PTO starting + 11 Paid Holidays Annually
- 401k Program with 100% company match on the first 4%
- Monthly reimbursement of Cell Phone and Home Internet costs
- Paternity/Maternity Leave
- Investment in training and certifications to broaden and deepen your technical skills