Remote job
Network Security Engineer - PKI
Job details
About this role
Role overview The Network Security Engineer will support certificate lifecycle operations across a federal customer's application portfolio, guiding stakeholders on Public Key Infrastructure practices while delivering responsive service. This is a hands-on technical lead role that combines troubleshooting, automation development, and team supervision in a security-focused federal environment.
Responsibilities - Lead and supervise the PKI team, providing technical direction, project requirements, and strategic guidance for complex and critical applications. - Investigate complex certificate and PKI issues, recommend improvements, and implement solutions that ensure sustainable operations. - Drive certificate automation initiatives using Venafi or CyberArk TPP, identifying opportunities to introduce AI into recurring workflows. - Produce reports, documentation, and runbooks leveraging AI and other automation tooling. - Communicate effectively with IT customers, developers, and system administrators across multiple stakeholder groups.
Requirements - Strong understanding of Public Key Infrastructure, including Certificate Authority administration, Certificate Enrollment Web Service and Policy Web Service, and Active Directory Certificate Services monitoring. - Proficiency in PowerShell scripting and familiarity with REST API integration, SCEP, and Microsoft AD auto-enrollment. - Hands-on experience with certificate management platforms such as Venafi or CyberArk TPP, Microsoft Certificate Authority, and Hardware Security Modules. - Infrastructure background in one or more areas: IT or server administration, networking, Active Directory or LDAP, Unix or Linux, virtualization, or access control. - Demonstrated ability to troubleshoot digital certificate issues and an interest in advancing automation and AI-driven approaches. - Awareness of post-quantum cryptography concepts and strong written and verbal communication skills.
Nice to have - Familiarity with VCERT, Portable Git, Ansible, and Visual Studio Code. - Experience with ServiceNow or comparable change, incident, and problem management tooling. - Background in TLS/SSL-dependent platforms such as F5, NetScaler, IIS, Apache, WebLogic, or WebSphere. - Server virtualization experience with VMware or Hyper-V, plus database administration on MSSQL. - Relevant certifications such as A+, Network+, Security+, Venafi or CyberArk administration, CCENT, or CCNA.
Benefits and work setup - Remote position with candidates located in specific metro areas; occasional on-site work may be required given the federal context. - Eligibility for security clearance and a background investigation is required for the role. - Medical plan options including a zero-deductible PPO and a high-deductible plan with health savings account contributions, plus dental coverage. - Twelve corporate holidays, a flexible time off program, mobile phone and home internet allowance, and access to a retirement plan after an initial waiting period. - Business casual dress expectations and sedentary work with extended computer use.