
PKI Engineer, Certificate Management & HSM
Overview
You will own PKI infrastructure for a Dallas-based enterprise, delivering certificate lifecycle management and HSM integration at scale. You will join a security engineering team of 8, reporting to the CISO, and collaborate with network, application, and compliance teams. This contract role stands out because you will drive the migration to AWS Certificate Manager and Azure Key Vault, modernizing legacy systems in the first 90 days.
What You'll Do7
- 1Design and deploy PKI hierarchies with Microsoft CA and Thales HSM in the first month, ensuring high availability.
- 2Build automated certificate enrollment and renewal pipelines using Venafi and Ansible, cutting manual effort by 50%.
- 3Lead the integration of AWS Certificate Manager with CloudHSM, streamlining issuance for cloud workloads.
- 4Debug and resolve certificate validation failures across TLS, IPsec, and S/MIME, minimizing downtime.
- 5Drive the migration from OpenSSL custom scripts to EJBCA for certificate authority management.
- 6Ship a security compliance dashboard tracking certificate expiry, using Elasticsearch and Kibana.
- 7Scale the certificate issuance process to support 20,000+ devices and services without disruption.
Requirements7
- 15+ years engineering enterprise PKI solutions, including HSM deployment and key ceremonies.
- 23+ years scripting with Python or PowerShell to automate certificate operations.
- 3Hands-on experience with Microsoft CA and Venafi or EJBCA.
- 4Proficiency in TLS, SSL, and X.509 certificate standards.
- 5Familiarity with AWS Certificate Manager, Azure Key Vault, and CloudHSM.
- 6Experience creating and enforcing CA governance policies and audit trails.
- 7Bachelor's degree in Computer Science, Information Security, or equivalent work experience.
Salary Insight
$43 - $45k per year
Similar open positions
Explore active roles that match your skills and interests.

Digitive LLC
VerifiedPKI Cyber Security Engineer, AWS & DevOps
You will own PKI design, implementation, and administration across a cloud-first enterprise environment. Your work directly enables secure certificate lifecycle management for mission-critical systems. You will collaborate with DevOps and security teams to integrate PKI with AWS IAM, Kubernetes, and CI/CD pipelines. This role stands out for its hybrid work model and impact on large-scale infrastructure. You bring 8-10+ years of experience to a 6-month engagement with potential to extend.

Winsnow, Inc
VerifiedPKI Engineer, Certificate Authority & Active Directory
You own the Certificate Authority (CA) Management core, Active Directory, and platform authentication across Windows and Unix environments for Winsnow, Inc. This onsite contract role in Dallas, TX drives the processes and controls around CA operations, integrating automation tools to harden the PKI infrastructure. You'll partner with security and infrastructure teams, ensuring certificate lifecycle management scales securely. This role stands out for its hands-on focus on CA and AD integration with Windows and Unix systems.

InfiCare
VerifiedPKI Architect InfiCare San Jose CA Hybrid
Design and architect scalable PKI solutions to support enterprise security requirements. This role drives secure digital identity infrastructure across hybrid environments. Own the end-to-end implementation of robust certificate frameworks. Differentiate by shaping zero-trust security architectures.
631 Booz Allen Hamilton_United States
VerifiedSenior PKI Engineer at Booz Allen Hamilton
Lead ownership of large scale PKI projects for government clients. Analyze identity lifecycle and define enterprise identity records. Design deploy support systems that verify user privileges and manage credentials for critical assets. Implement enterprise class solutions to stop adversaries. Support national security missions.

Visionaire Partners
VerifiedSenior Cybersecurity Engineer, Cloud Security
You will spearhead defensive operations, threat detection, and risk mitigation across complex enterprise networks, AWS and Azure, and endpoint environments. You will design security tool architecture to harden system baselines and drive security posture across cloud and containerized infrastructure. Your stack includes SIEM, EDR, CSPM, and IaC tools. You will partner with DevOps and network teams to embed security into the build pipeline. This role puts you at the center of security strategy for a critical infrastructure provider.

ApTask
VerifiedHSM Crypto Custody Engineer ApTask
Design and maintain secure HSM-backed signing infrastructure for self-custody platforms. Lead development of cryptographic services for financial institutions. This role differs by focusing on enterprise-grade HSM integration and compliance-driven workflows.