
PKI Cyber Security Engineer, AWS & DevOps
Overview
You will own PKI design, implementation, and administration across a cloud-first enterprise environment. Your work directly enables secure certificate lifecycle management for mission-critical systems. You will collaborate with DevOps and security teams to integrate PKI with AWS IAM, Kubernetes, and CI/CD pipelines. This role stands out for its hybrid work model and impact on large-scale infrastructure. You bring 8-10+ years of experience to a 6-month engagement with potential to extend.
What You'll Do9
- 1Design and deploy PKI hierarchies, including root and issuing CAs, using AWS Certificate Manager and Private CA.
- 2Automate certificate provisioning and renewal with PowerShell, Python, and YAML scripts.
- 3Integrate PKI with Kubernetes clusters for mTLS and service mesh security.
- 4Build and maintain DevOps pipelines for certificate lifecycle management using AWS CodePipeline and Jenkins.
- 5Troubleshoot and resolve PKI-related issues across AWS services, Active Directory, and third-party applications.
- 6Lead the migration of existing certificate services to AWS Private CA, ensuring zero downtime.
- 7Develop and enforce PKI policies, procedures, and audit controls for compliance.
- 8Collaborate with security teams to implement hardware security modules (HSMs) and key management best practices.
- 9Document PKI architecture, runbooks, and incident response procedures for operational handoff.
Requirements8
- 18-10+ years in cyber security with a focus on PKI design, implementation, and administration.
- 2Expert-level scripting with PowerShell, Batch, JSON, Python, and YAML.
- 3Hands-on experience with AWS services: Private CA, Certificate Manager, IAM, CloudHSM, and KMS.
- 4Strong knowledge of DevOps automation using Terraform, Ansible, or CloudFormation.
- 5Proven ability to integrate PKI with Kubernetes, Docker, and service mesh solutions.
- 6Familiarity with Active Directory Certificate Services and PKI best practices (e.g., NIST, CA/Browser Forum).
- 7Experience with X.509 certificates, algorithms, and cryptographic key management.
- 8Excellent problem-solving and communication skills for cross-team collaboration.
Salary Insight
Salary not disclosed in listing
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.

InfiCare
VerifiedPKI Architect InfiCare San Jose CA Hybrid
Design and architect scalable PKI solutions to support enterprise security requirements. This role drives secure digital identity infrastructure across hybrid environments. Own the end-to-end implementation of robust certificate frameworks. Differentiate by shaping zero-trust security architectures.

Visionaire Partners
VerifiedSenior Cybersecurity Engineer, Cloud Security
You will spearhead defensive operations, threat detection, and risk mitigation across complex enterprise networks, AWS and Azure, and endpoint environments. You will design security tool architecture to harden system baselines and drive security posture across cloud and containerized infrastructure. Your stack includes SIEM, EDR, CSPM, and IaC tools. You will partner with DevOps and network teams to embed security into the build pipeline. This role puts you at the center of security strategy for a critical infrastructure provider.

Virtusa Corporation
VerifiedLead Cyber Security Engineer IAM Cloud Architecture
Own and scale secure identity access management solutions across cloud platforms. Lead cross functional teams to design and implement robust security frameworks. Drive adoption of modern authentication protocols and zero trust architectures.
System One
VerifiedSenior Windows Server Cloud DevOps Engineer
Own Windows Server production operations and Kubernetes environment while maintaining availability. Lead incident response and design secure scalable cloud architectures. Develop and manage Infrastructure as Code using Terraform and Ansible. Create CI/CD pipelines and DevSecOps automation. Design monitoring logging and alerting solutions. Enforce security best practices and produce technical documentation. Mentor junior engineers and provide technical leadership in DevOps practices. This is a senior role where you will own systems and drive improvements. The position offers a unique blend of on-premises and cloud expertise.
631 Booz Allen Hamilton_United States
VerifiedSenior PKI Engineer at Booz Allen Hamilton
Lead ownership of large scale PKI projects for government clients. Analyze identity lifecycle and define enterprise identity records. Design deploy support systems that verify user privileges and manage credentials for critical assets. Implement enterprise class solutions to stop adversaries. Support national security missions.

QUANTUM TECHNOLOGIES LLC
VerifiedAWS Cloud Engineer, Application Security
You will own security for applications built and operated on AWS, embedding security across the entire SDLC from design to incident response. You will work with development teams to enforce secure coding and automate security checks in CI/CD pipelines. You will also manage runtime protection and respond to security incidents, collaborating with engineering and operations. This contract role in Dallas, TX offers 6+ months of work with potential extension, focusing on application security in a dynamic cloud environment.