Senior PKI Architect / Public Key Infrastructure (PKI) Engineer

  • -
  • Full-Time
  • On-Site

Job Description:

About the Role

We are seeking an experienced PKI Architect to lead the design, implementation, and governance of our enterprise Public Key Infrastructure (PKI). This role is responsible for ensuring the security, integrity, and availability of the organisation's cryptographic services, enabling secure digital identities, certificate lifecycle management, and trusted communications across enterprise platforms.

Working closely with security, infrastructure, cloud, and application teams, you will define PKI standards, implement best practices, and ensure compliance with industry security frameworks.

Key Responsibilities

Enterprise PKI Architecture

  • Design, implement and maintain enterprise PKI architecture, including Certificate Authority (CA) hierarchy, trust models, certificate policies and security controls.
  • Develop scalable, resilient and highly available PKI solutions aligned with business and security requirements.

Certificate Authority Management

  • Manage Certificate Authority (CA) and Registration Authority (RA) environments.
  • Oversee certificate issuance, renewal, revocation and lifecycle management.
  • Ensure secure and efficient certificate management processes.

Cryptographic Governance

  • Define and maintain enterprise cryptographic standards and policies.
  • Manage key lifecycle processes, encryption standards and Hardware Security Modules (HSMs).
  • Ensure adoption of approved cryptographic algorithms and best practices.

Infrastructure & Platform Security

  • Secure the deployment and operation of PKI services including:
    • Online Certificate Status Protocol (OCSP)
    • Certificate Revocation Lists (CRLs)
    • Offline Root Certificate Authorities
    • High Availability and Disaster Recovery configurations

Enterprise Integration

  • Integrate PKI services with enterprise technologies including:
    • Identity & Access Management (IAM)
    • TLS/SSL Certificates
    • Mobile Device Management (MDM)
    • Cloud platforms
    • IoT environments
    • Internal applications and enterprise services

Risk, Compliance & Governance

  • Conduct PKI security risk assessments.
  • Support internal and external security audits.
  • Ensure compliance with industry standards including NIST and ISO 27001.
  • Develop and maintain governance frameworks and security policies.

Documentation & Operational Excellence

  • Develop and maintain:
    • Certificate Policy (CP) and Certification Practice Statement (CPS)
    • Architecture documentation
    • Operational procedures
    • Technical standards
    • Governance documentation

Incident Response

  • Provide technical leadership during cryptographic incidents, certificate failures and trust-related security events.
  • Support root cause analysis and continuous improvement initiatives.

Skills & Experience

To be successful in this role, you will have:

  • Strong experience designing and managing enterprise Public Key Infrastructure (PKI) environments.
  • Deep knowledge of cryptographic technologies including:
    • X.509 certificates
    • PKCS standards
    • OCSP
    • CRLs
    • Public/private key management
    • Secure key lifecycle management
  • Hands-on experience administering:
    • Enterprise Certificate Authorities
    • Registration Authorities
    • Hardware Security Modules (HSMs)
    • Certificate Lifecycle Management (CLM) platforms
  • Solid understanding of security frameworks including:
    • NIST 800-53
    • ISO 27001 / ISO 27002
    • Cryptographic governance and compliance requirements
  • Experience automating PKI processes using PowerShell, Python or Shell scripting.
  • Excellent analytical, troubleshooting and stakeholder engagement skills.

Qualifications

  • Bachelor's or Master's degree in Computer Science, Information Security, Cyber Security or a related discipline.
  • Relevant industry certifications (such as CISSP, CCSP, Security+, or PKI-related certifications) will be highly regarded.

Why Join Us?

  • Work on enterprise-scale cyber security initiatives.
  • Lead the evolution of critical PKI and cryptographic services.
  • Collaborate with experienced security and infrastructure professionals.
  • Opportunity to influence enterprise security strategy and architecture.
  • Flexible and supportive working environment with ongoing professional development.