×
Register Here to Apply for Jobs or Post Jobs. X

Senior PKI Engineer

Job in Falls Church, Fairfax County, Virginia, 22042, USA
Listing for: General Dynamics Information Technology
Full Time position
Listed on 2026-03-12
Job specializations:
  • IT/Tech
    Cybersecurity, Systems Engineer
  • Engineering
    Cybersecurity, Systems Engineer
Salary/Wage Range or Industry Benchmark: 100000 - 125000 USD Yearly USD 100000.00 125000.00 YEAR
Job Description & How to Apply Below

Position Summary

The Senior PKI Engineer is responsible for designing, implementing, securing, and maintaining enterprise Public Key Infrastructure (PKI) services that support mission-critical authentication, encryption, digital signature, and certificate lifecycle operations. This role requires a general understanding of PIV implementation in the government space.

Key Responsibilities
  • Administer enterprise PKI systems, including Certificate Authorities (CAs), Online Certificate Status Protocol (OCSP) responders, Hardware Security Modules (HSMs), and certificate lifecycle service products.
  • Deep understanding and application of PKCS standards.
  • Implement PKI in hybrid or cloud-based environments such as Azure, AWS, and Google Cloud Platform (GCP).
  • Manage and configure Microsoft Active Directory Certificate Services (ADCS).
Automation & Integration
  • Support the automation of certificate issuance, renewal, monitoring, and compliance reporting processes.
Operations & Troubleshooting
  • Provide Tier III support for PKI, certificate-based authentication, TLS/SSL, smart cards, and identity management systems.
  • Troubleshoot issues such as certificate chain validation, revocation, OCSP/CRL failures, and integration challenges.
  • Ensure high availability, redundancy, and disaster recovery readiness for PKI services.
Modernization & Emerging Technologies
  • Support for post-quantum cryptography (PQC) transitions and compliance with emerging NIST standards.
  • Integrate cost-efficient open-source cryptographic libraries and JRE/JDK solutions.
  • Support zero-trust architecture strategies and cloud migration efforts.
  • Explore and evaluate new technologies to enhance scalability, automation, and security.
Required Qualifications
  • Education: Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or equivalent experience.
  • Experience:
    • 7+ years of hands‑on experience in PKI engineering, certificate services, and cryptographic system management.
    • Deep expertise with:
      • Microsoft Active Directory Certificate Services (ADCS)
      • Various HSMs (Thales, Safe Net, AWS Cloud

        HSM, etc.)
      • OCSP/CRL infrastructure
      • TLS/SSL, S/MIME, and device certificates
      • Smart card and PIV/CAC authentication systems
    • Strong understanding of:
      • NIST standards (e.g., SP 800-57, 800-131A, 800-63)
      • FIPS 140-2/3 compliance
      • Cryptography and key algorithms (X.509, ASN.
        1, RSA/ECC/PQC)
    • Proficiency in scripting/automation via Power Shell, Python, or Bash.
    • Background in solving vulnerability management challenges and addressing POA&M items.
    • Expertise in leading key ceremonies and managing cryptographic material securely.
  • Technical

    Skills:

    • Proficiency in networking, firewall rule implementations, and TLS/SSL troubleshooting.
    • In-depth knowledge of Windows environments, including certificate installation for CAPI and diverse applications/appliances.
    • Experience in SNMP monitoring, SIEM/syslog tools, and Docker troubleshooting.
    • Familiarity with VPN solutions (e.g., Cisco Secure Client) and NAC protocols like 802.1X.
Preferred Qualifications
  • Knowledge and experience with PQC migration and NIST PQC algorithm adoption.
  • Familiarity with identity and access management (IAM/IAG) platforms, IDMS, and federation systems.
  • Hands‑on experience with cloud‑native PKI solutions (e.g., Azure Key Vault, AWS ACM Private CA).
  • Relevant certifications, such as:
    • CISSP
    • CCSP
    • Security+
    • Microsoft security certifications
  • Experience in high‑assurance or federal agency‑regulated environments.
#J-18808-Ljbffr
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary