PKI Systems Engineer
Listed on 2026-08-18
-
IT/Tech
Cybersecurity, Systems Engineer
Support and sustain enterprise Public Key Infrastructure (PKI) operations for the National Airspace System (NAS), administering the full certificate lifecycle and ensuring secure, standards-compliant certificate issuance and validation across a diverse operational environment.
You will configure, harden, and administer PKI management tools and platforms, troubleshoot certificate chain and trust store issues, and integrate digital certificates into servers, applications, network devices, and cloud services to enable secure TLS/SSL communications — automating issuance, renewal, and deployment at scale.
Concepts Beyond provides Software Engineering, Systems Engineering, and Aviation expertise to develop advanced Air Traffic Management concepts; develops cybersecurity solutions in PKI, post-quantum computing, zero trust & confidential computing;
Develops AI/ML and cloud computing tools for Aviation Safety & Data Analytics.
- PKI Environment Design & Certificate Lifecycle Management: Design, deploy, administer, and maintain PKI environments, encompassing the full certificate lifecycle from issuance and renewal through revocation (CRL/OCSP), rekeying, and archival, ensuring configurations align with security policy, operational risk tolerance, and long-term sustainment goals.
- PKI Platform Configuration & Hardening: Configure, harden, and administer PKI management tools and platforms across diverse system environments to support secure certificate issuance and validation workflows, troubleshoot certificate chain and trust store errors, and maintain consistent, standards-based configurations across heterogeneous operational environments.
- Certificate Integration & Automation: Integrate digital public certificates into servers, applications, network devices, and cloud-based services to enable secure TLS/SSL communications, including automating certificate issuance, renewal, and deployment processes to reduce manual effort, minimize error rates, and support faster, more reliable certificate provisioning at scale.
- Program Support & Operations: Review FAA program and project documentation to identify PKI, digital certificate, and dependencies and risks, coordinating with program offices and technical stakeholders to align certificate management practices and automation initiatives with FAA program schedules and requirements. Support day-to-day operations including ticketing systems, documentation, NIST-aligned security policy compliance, and backup coverage to ensure operational redundancy and continuity.
- Industry Engagement & Outreach: Contribute to working groups and standards bodies, and represent the organization externally through publications, conference presentations, and panel participation.
- Strategic Insight & Opportunity Identification: Stay current on government and industry activities to identify emerging trends, gaps, and innovation opportunities. Contribute ideas that support growth and new business opportunities.
- Bachelor’s degree in Engineering, Computer Science, or a related field, plus 15+ years of relevant experience.
- Experience designing, deploying, administering, and maintaining PKI environments across the full certificate lifecycle (issuance, renewal, revocation via CRL/OCSP, rekeying, archival).
- Experience configuring, hardening, and administering PKI management tools and platforms across diverse system environments.
- Experience troubleshooting certificate chain and trust store errors and maintaining standards-based configurations across heterogeneous environments.
- Experience integrating digital public certificates into servers, applications, network devices, and cloud-based services for secure TLS/SSL communications.
- Experience automating certificate issuance, renewal, and deployment processes.
- Experience reviewing program and project documentation to identify PKI and identity management dependencies and risks, and coordinating with program offices and technical stakeholders.
- Familiarity with NIST-aligned security policy compliance and day-to-day operational support (ticketing systems, documentation, backup coverage).
- Experience working with FAA or other government programs.
- Familiarity with Non-Personnel Entity (NPE) Identity Management Systems.
- Certifications such as CISSP, Security+, or equivalent.
- Experience with PKI/CA platforms (e.g., EJBCA, Venafi, Microsoft ADCS).
- Scripting or automation experience (e.g., Python, Power Shell, Ansible) for certificate lifecycle automation.
- Awareness of or experience with post-quantum cryptography (PQC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).