Sr. Security Engineer
Job Description
Senior-level security engineering role focused on enterprise certificate and cryptographic services, with an emphasis on PKI reliability, automation, and standards.
Responsibilities
- Support daily operations for PKI infrastructure, including availability, resiliency, and patching
- Own certificate lifecycle activities: issuance, renewal, and revocation processes
- Maintain and improve certificate inventories across applications and infrastructure to reduce expiration and trust-related risk
- Develop and enhance automation for certificate management using APIs, pipelines, scripting, and related tooling
- Integrate PKI capabilities with enterprise environments, including CI/CD workflows, cloud services, and application platforms
- Help define and enforce standards for certificate usage, cryptography, and associated security policies
- Collaborate cross-functionally to support PKI onboarding, tooling adoption, and clear ownership practices
- Assist with incident response and remediation involving certificates, encryption, and trust chain issues
- Contribute to reporting, visibility, and compliance efforts tied to certificate health and security controls
- Participate in modernization work, including evaluation of emerging cryptographic approaches and tools
Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, or related field (or equivalent experience)
- 3–7+ years experience in PKI, cybersecurity engineering, or infrastructure security
- Hands-on experience with certificate lifecycle management
- Working knowledge of PKI platforms and tools, including Venafi, DigiCert, Microsoft CA, or AWS ACM
- Strong understanding of TLS/SSL, cryptographic principles, and key management practices
- Ability to collaborate and communicate technical concepts clearly across teams
- High attention to detail with a focus on secure, reliable operations
Technologies
- Venafi, DigiCert, Microsoft CA, AWS ACM
- TLS/SSL
- CI/CD
- HSMs
- AWS, Azure
- NIST
- PCI-DSS
- CMMC
Preferred Skills
- Experience with HSMs and key custody operations
- Background in PKI automation using scripting, APIs, or pipeline-based workflows
- Experience supporting cloud certificate services (AWS or Azure)
- Knowledge of compliance frameworks such as NIST, PCI-DSS, or CMMC
- Experience supporting PKI at scale in large enterprise environments
- Familiarity with trust store management across distributed systems
Location: Atlanta, GA (onsite)