×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

PKI ​/ Certificate Management Engineer (R-00198

Job in San Diego, San Diego County, California, 92189, USA
Listing for: Socket.dev
Full Time position
Listed on 2026-08-18
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 140000 - 190000 USD Yearly USD 140000.00 190000.00 YEAR
Job Description & How to Apply Below
Position: PKI / Certificate Management Engineer (R-00198)

True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes. True Zero recognizes that those outcomes begin and end with our people, and that is what we have built a community of like-minded, driven, and passionate individuals and innovators who are aligned in a common goal of delivering top-tier services to our customers.

Our culture and commitment have been recognized through numerous accolades, including being named one of the Best Places to Work in 2023 in two categories (“Prosperous and Thriving” ($5MM–$50MM in gross revenue) and “Mid-Atlantic Region” (DC, DE, MD, NC, VA, WV)), and again in 2025 as a Best Places to Work honoree. In addition, True Zero earned coveted spots on the Inc.

5000
list of fastest-growing companies in America in 2022, 2023, and 2025
, a testament to our sustained growth driven by our people-first approach and unwavering dedication to excellence.

The PKI / Certificate Management Engineer designs, deploys, and maintains a secure, scalable Public Key Infrastructure supporting enterprise, cloud, government, and hybrid environments. The role is responsible for automating certificate issuance and renewal, managing certificate life cycles across Windows, Linux, cloud platforms, containers, applications, and network devices, and establishing governance and monitoring processes that reduce the risk of certificate-related outages.

This position supports the Zero Trust architecture through certificate-based authentication, encryption, workload identity, and secure communications. The engineer will also support Federal PKI and DoD PKI integrations, CAC/PIV authentication, mutual TLS, FIPS-validated cryptography, hardware security modules, and cloud-native certificate services in AWS Gov Cloud.

Job Responsibilities
  • Design, implement, and maintain enterprise

    Public Key Infrastructure (PKIs) supporting internal and external certificate requirements.
  • Manage the full certificate lifecycle, including request, issuance, validation, distribution, renewal, revocation, expiration, and retirement.
  • Implement and maintain ACME-based certificate automation and other automated enrollment and renewal workflows.
  • Manage certificates across Windows, Linux, cloud platforms, containers, applications, load balancers, network devices, and other enterprise systems.
  • Design and operate integrations with AWS Private Certificate Authority (AWS Private CA), AWS Certificate Manager (ACM), and related AWS services.
  • Implement and administer Hardware Security Module (HSM) capabilities, including AWS CloudHSM, for secure protection of private keys and cryptographic operations.
  • Support Federal PKI (FPKI) and DoD PKI trust relationships, certificate chains, and interoperability requirements.
  • Integrate CAC/PIV authentication with enterprise applications, identity platforms, operating systems, and secure access workflows.
  • Implement and maintain mutual TLS (mTLS) for workload identity, service-to-service authentication, and Zero Trust communications.
  • Ensure cryptographic implementations use FIPS-validated cryptographic modules and approved algorithms where required.
  • Establish certificate discovery, inventory, monitoring, and alerting capabilities to identify unmanaged certificates and prevent expiration-related outages.
  • Develop governance standards for certificate ownership, issuance, naming, key length, cryptographic algorithms, renewal periods, revocation, and retention.
  • Integrate certificate management with Identity and Access Management (IAM) platforms and authentication workflows.
  • Support secure networking and communications through TLS, mTLS, certificate-based authentication, and encryption standards.
  • Monitor PKI platform health, certificate status, revocation services, HSM operations, and certificate expiration events.
  • Troubleshoot complex certificate-chain, trust-store, TLS, cryptographic, enrollment, renewal, and authentication issues.
  • Partner with cybersecurity, identity, cloud, platform, network, and application teams to integrate PKI services into enterprise architectures and…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary