Public Key Infrastructure Architect - DigiCert; PKI Architect
Listed on 2026-06-06
-
IT/Tech
Cybersecurity, Systems Engineer
Public Key Infrastructure Architect - Digi Cert (PKI Architect)
Join to apply for the Public Key Infrastructure Architect - Digi Cert (PKI Architect) role at Infinite Ranges
Public Key Infrastructure Architect - Digi Cert (PKI Architect)4 days ago Be among the first 25 applicants
Join to apply for the Public Key Infrastructure Architect - Digi Cert (PKI Architect) role at Infinite Ranges
Get AI-powered advice on this job and more exclusive features.
Please Note:
These are 100% REMOTE, project-based Consulting opportunities that range from 5-15 hours a week per project, depending on the need.
Infinite Ranges stands on the cutting edge of deploying, implementing, and custom consulting for tailored application modernization and Dev Sec Ops solutions. While we build Dev Sec Ops , Platform Engineering, and App Modernization solutions, we also offer highly skilled Surge resourcing services for professional service firms, ISVs, resellers, and industry-leading OEMs such as VMWare and AWS, ensuring excellence and expert guidance at every step
In under 48 months, we’ve grown to 60+ OEM partners, a staff of over 50, and hundreds of engagements, delivering both people and professional services at-scale
About
The Role
Are you passionate about cryptography and digital security with Digi Cert expertise? We are seeking PKI (Public Key Infrastructure) Architects & Engineers proficient in strategy, design, and implementation to steer our organization towards unparalleled security. Join us to redefine excellence in secure communications.
What You Will Be Doing 2. PKI Implementation: 3. Certificate Management: 4. Security and Risk Management: 5. Collaboration and Documentation: What We Want To See:
- PKI Strategy and Design:
- Develop a holistic PKI strategy aligned with organizational security objectives.
- Design end-to-end PKI architecture encompassing root and intermediate certificate authorities, end-entity lifecycle management, and policy frameworks.
- Take the lead in deploying PKI infrastructure that’s both scalable and seamlessly integrated with existing systems.
- Configure and manage certificate authorities to establish trust within and outside the organization.
- Formulate and implement procedures for certificate issuance, renewal, and revocation.
- Use automation tools for certificate lifecycle management and to ensure compliance with best practices.
- Regularly conduct security assessments of the PKI setup and contribute to incident response plans.
- Stay abreast of industry trends, threats, and best practices in PKI and cryptography.
- Collaborate with network, security, and Dev Ops teams for a seamless and secure integration of PKI elements.
- Maintain comprehensive and up-to-date technical documentation for PKI configurations, procedures, and policies.
- Digi Cert Digital Trust Associate certification (or willingness to obtain).
- Digi Cert Digital Trust Solutions Engineer certification strongly preferred.
- Experience with Digi Cert Technical Professional tracks such as:
- Managing Digi Cert Cert Central TLS Manager
- Administering Digi Cert Trust Lifecycle Manager
- Administering Digi Cert IoT Trust Manager
- Administering Digi Cert Software Trust Manager
- Administering Digi Cert Document Trust Manager (bonus)
- Administering Digi Cert Embedded Trust Manager (bonus)
- Administering Digi Cert DNS Trust Manager (bonus)
- Strong knowledge of PKI, SSL/TLS, certificate lifecycle management, and CA hierarchy.
- Familiarity with automation tools and scripting for certificate deployment (e.g., Power Shell, Python, or Ansible).
- Experience with cloud platforms (AWS, Azure, GCP) and integrating PKI with cloud-native services.
- Understanding of cryptographic standards (X.509, RSA/ECC, OCSP, CRL, etc.).
- Knowledge of IT and Cybersecurity frameworks, such as NIST, FIPS, CSF, CIS, ISO 27001/2.
- Working knowledge of Cloud provider security architecture design patterns, and key control methods - Bring your own key, Hold your own key, partitioned HSMs.
- Experience with OWASP Web/API vulnerabilities and compensating controls (CSRF, XSS, SQLI, etc.)
- Digi Cert
- Sectigo
- Keyfactor
- AppviewX
- Microsoft PKI infrastructure
- Thales HSMs (Luna, et al)
- OCSP
Certifications like Certified Information Systems Security Professional (CISSP)
Certified Information Security Manager (CISM)
Microsoft Certificate Authority
Certificate management platform experience
Hardware Security Module (HSM)
Seniority level
- Seniority level
Mid-Senior level
- Employment type
Contract
- Job function
Information Technology - Industries
IT Services and IT Consulting
Referrals increase your chances of interviewing at Infinite Ranges by 2x
Apply BELOW
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).