Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cyber PKI Administrator

Shrgroup.net

SHR - Software Hardware Re-engineered

About SHR Consulting Group


SHR is a premier technology integrator solving our nation's most complex modernization and readiness challenges across the defense, federal civilian, and intelligence markets. Our robust portfolio of offerings includes high-end solutions in systems engineering and integration; enterprise IT, including cloud services; cyber; software; advanced analytics and AI. With an intimate understanding of our customers' challenges and deep expertise in existing and emerging technologies, we integrate the best components from our own portfolio and our partner ecosystem to deliver innovative, effective, and efficient solutions.

We are a rapidly growing organization seeking a Cyber PKI Administrator to provide specialized IT expertise for supporting a DISA environment. This position is responsible for the installation, configuration, operation, and maintenance of Public Key Infrastructure (PKI) services and Hardware Security Module (HSM) appliances that protect DoD identity, authentication, and encryption capabilities. The Cyber PKI Administrator ensures that HSM devices, Certificate Authorities, and supporting services are properly configured, maintained, and updated, and that the cryptographic environment adheres to DoD security standards, organizational values, and contractual performance requirements.

This role supports Government customers across one or more classification domains and may require work across standard business hours or on a shift/rotational schedule, depending on task order requirements. Because HSMs are designated mission-critical assets, the role demands strict adherence to two-person integrity, separation of duties, and disciplined audit and access controls. The Cyber PKI Administrator serves as the primary administrator of the cryptographic environment and works alongside designated backup administrators in the broader operations team who hold equivalent privileged credentials and emergency access.


Duties will vary based on position and area of focus:

HSM Operations and Administration

  • Install, configure, and maintain enterprise-class Hardware Security Module (HSM) appliances in accordance with vendor best practices, DoD security configuration baselines, and approved standard operating procedures (SOPs).
  • Monitor HSM health, performance, and availability; identify, troubleshoot, and resolve hardware, firmware, and client-side issues in a timely manner.
  • Perform HSM firmware updates, software patches, and supporting client software upgrades in compliance with DoD Information Assurance Vulnerability Management (IAVM) requirements and Government-directed maintenance windows.
  • Maintain HSM configuration documentation, baseline records, and change logs in accordance with configuration management processes.
  • Partition and Role Management : Create and manage HSM partitions, assign cryptographic officer and user roles, and enforce quorum (M of N) authentication controls so that no single individual can perform sensitive operations.
  • Key Lifecycle Management : Oversee the full lifecycle of cryptographic key material - generation, distribution, rotation, backup, escrow, restoration, and destruction - and maintain chain-of-custody documentation for all key operations.
  • Key Ceremony Execution : Plan and execute formal key ceremonies for Root and Issuing Certificate Authority events; develop and maintain ceremony scripts and witness logs.
  • Tamper Integrity : Maintain tamper-evident packaging, seal logs, and physical inspection records consistent with FIPS 140-2/140-3 operational guidance.
Public Key Infrastructure (PKI) and Certificate Management
  • Operate and maintain enterprise Certificate Authorities, Online Certificate Status Protocol (OCSP) responders, and Certificate Revocation List (CRL) distribution services across multiple classification domains.
  • Issue, renew, revoke, and replace DoD and National Security System (NSS) PKI certificates for web servers, domain controllers, Domain Name System (DNS) servers, and other infrastructure components.
  • Expiration Tracking : Build and maintain a comprehensive certificate expiration tracker; coordinate proactive renewal with affected system owners to prevent service disruption and report status to Government leadership on a recurring cadence.
  • Root and Policy CA Operations : Support Root and Policy Certificate Authority lifecycle events, including offline operations, approved key ceremonies, and Government-directed updates.
  • Smart Card and CAC Integration : Manage Common Access Card (CAC) and PKI integration for Government and contractor personnel, including user authentication, certificate mapping, and smart-card-based access controls.
  • PKI Consumer Coordination : Partner with Domain Services, application, database, and platform teams to ensure dependent systems consume PKI services correctly and remain compliant with cryptographic standards.
Physical and Logical Access Control
  • Enforce physical and logical access controls to HSM appliances; maintain access rosters and coordinate facility access with Government POCs.
  • Execute two-person rule procedures for sensitive cryptographic operations in partnership with designated backup administrators.
  • Train and qualify designated backup administrators from the broader operations team to maintain emergency access to the cryptographic environment, ensuring continuity of operations without compromising separation of duties.
  • Audit privileged access to the cryptographic environment on a recurring basis and report findings to Government leadership.
Cybersecurity and Compliance
  • Ensure all PKI and HSM systems maintain compliance with DoD Security Technical Implementation Guides (STIGs), Information Assurance Vulnerability Alerts (IAVAs), and applicable Command Cyber Tasking Orders (CCTOs).
  • Conduct and analyze vulnerability scans (e.g., ACAS/Nessus) of HSM management interfaces and PKI infrastructure; apply remediations including security patches, configuration changes, and STIG settings within Government-required timelines.
  • Support Risk Management Framework (RMF) activities including the development and maintenance of system security documentation, Plan of Action and Milestones (POA&Ms), and Assessment and Authorization (A&A) artifacts for the cryptographic environment.
  • Log Auditing : Review HSM and Certificate Authority audit logs on a recurring schedule, investigate anomalies, and coordinate with the defensive cyber operations team on any indicators of compromise.
  • Adhere to DoD 8570.01-M / DoD 8140 Information Assurance workforce requirements applicable to the assigned role.
Documentation and Communication
  • Develop, update, and maintain SOPs, Work Instructions (WIs), key ceremony scripts, and technical documentation for all supported cryptographic services.
  • Provide status updates, incident reports, and After Action Reports (AARs) as required by Government leadership.
  • Participate in configuration change control board (CCB) processes; coordinate all PKI and HSM changes through approved change management procedures.
  • Collaborate with network, cybersecurity, server operations, and application teams to resolve cross-functional issues.
  • Provide technical support and training to end users and junior staff as needed.
Security Clearance Requirement

U.S. Citizenship and a minimum active Secret security clearance are required for this position. Certain task orders or work locations may require a Top Secret (TS) or TS/SCI clearance. All personnel must be able to obtain and maintain the required clearance level and must possess a valid DoD Common Access Card (CAC). Personnel may be required to access systems across multiple classification domains, including Unclassified (NIPR), Secret (SIPR), and Top Secret/Collateral networks.

Education Requirements

One of the following is required:
  • Bachelor's degree in Computer Science, Computer Engineering, Information Technology, Information Systems, Cybersecurity, or a closely related technical field; OR
  • Associate's degree in a related technical field plus additional qualifying experience; OR
  • Equivalent combination of education, training, and directly relevant DoD IT experience as defined by labor category level below.
    • Junior (0-2 years) - Works under supervision; executes defined tasks; learns SOPs and tools
    • Mid (3-5 years - Works independently on most tasks; supports complex troubleshooting; mentors juniors
    • Senior (6+ years) - SME-level expertise; leads technical efforts; guides architecture and compliance decisions
Minimum Qualifications
  • Hands-on experience administering enterprise PKI in a Windows Active Directory environment, including Certificate Authorities, OCSP, and CRL distribution.
  • Working knowledge of Hardware Security Modules (HSMs) and FIPS 140-2/140-3 operational requirements.
  • Experience with cryptographic key lifecycle management: generation, backup, cloning, restoration, escrow, and destruction.
  • Working knowledge of Windows Server operating systems (2016/2019/2022), Active Directory, Group Policy, and PowerShell scripting.
  • Understanding of cryptographic concepts: asymmetric and symmetric algorithms, hashing, digital signatures, X.509 certificate structure, and certificate chain validation.
  • Ability to apply DoD STIGs and IAVAs to maintain system compliance.
  • Ability to operate under strict two-person integrity, separation-of-duties, and audit controls.
  • Ability to create and maintain technical documentation, SOPs, and key ceremony scripts.
  • Ability to work shift hours, weekends, or on-call rotations as required by task order.
  • Strong oral and written communication skills; ability to brief technical topics to non-technical stakeholders.
Preferred Qualifications
  • Experience in a DoD, Intelligence Community, or Federal Government IT environment.
  • Direct hands-on experience with Thales Luna Network HSM or Luna PCIe HSM appliances and associated administrative tooling.
  • Experience operating Microsoft Active Directory Certificate Services (AD CS) at enterprise scale.
  • Experience with OCSP responders, CRL signing, and Certificate Transparency.
  • Experience supporting DoD PKI, NSS PKI, or External Certification Authority (ECA) programs.
  • Familiarity with HSM integration with VMware, Microsoft IIS, F5, and other PKI-consuming platforms.
  • Familiarity with DoD RMF processes, eMASS, and A&A documentation.
  • Knowledge of DoD Identity, Credential, and Access Management (ICAM) frameworks.
  • PowerShell, Python, or Bash scripting for PKI and HSM automation.
Required Certifications

DoD Directive 8570.01-M / DoD 8140 baseline certification requirements applicable to their assigned Cyber IT/Cybersecurity role. The following certifications satisfy the minimum IAT Level II requirement:
  • CompTIA Security+ CE
  • Cisco CCNA Security
  • CySA+ (CompTIA Cybersecurity Analyst)
  • GIAC Security Essentials (GSEC)
  • Systems Security Certified Practitioner (SSCP)
Additional computing environment (CE) certifications may be required depending on the specific technologies managed (e.g., Microsoft, VMware, Red Hat, Cisco). Certifications must be current and maintained throughout the period of performance.

Desired Vendor Certification

In addition to the IAT Level II baseline above, the Thales Luna HSM Professional Engineer certification is strongly desired for this position. As an alternative pathway, a candidate who possesses the credentials and demonstrated experience to be granted Domain Administrator privileges may be considered, provided the candidate commits to achieving the Thales Luna HSM Professional Engineer certification within six (6) months of hire. Failure to obtain the certification within the agreed window may result in reassignment from the primary cryptographic administrator role.

Work Environment and Physical Requirements
  • Work is performed in a Government facility or contractor site supporting classified and/or unclassified IT environments.
  • Personnel may be required to work in data centers or consolidated server rooms with associated environmental conditions (temperature, noise, and physical equipment).
  • Occasional lifting of IT equipment up to 50 lbs may be required.
  • Personnel may be required to support 24x7 operations via scheduled shifts or on-call arrangements.
  • Travel to alternate Government sites may be required on an as-needed basis.
Benefits:
  • Competitive salary based on experience
  • Comprehensive benefits package including health, dental, vision, and retirement plans
  • Paid time off and holidays


We are an Equal Opportunity Employer and consider all qualified applicants without regard to protected characteristics under applicable law. EEO/AA Employer/Veteran/Disabled.
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Cyber PKI Administrator in Arlington, VA vacancy
  •  ...opportunity for a Sr. Infoblox DHCP DNS Administrator requiring a Public Trust located in Washington...  ..., Network Protocols, Network Encryption, PKI, Cisco, AWS Route 53, and Azure is...  ...Software Engineering, Cloud Solutions, Cyber Security and IT Managed Services. With 24... 
    Cyber
    Immediate start

    ActioNet

    Washington DC
    6 days ago
  •  ...enterprise IT, including cloud services: cyber, software, advanced analytics, and AI....  ...seeking experienced Core Services Systems Administrators (multiple openings) to operate and...  ...and endpoint analysis. Maintain DoD/NSS PKI server certificates and ensure they are... 
    Cyber
    Local area

    Shrgroup.net

    Arlington, VA
    5 days ago
  • A cybersecurity firm based in Washington, DC, is looking for a Cyber Security Administrator. You will be responsible for managing the organization's security infrastructure, configuring security systems, monitoring network traffic, and ensuring compliance with security... 
    Cyber

    Beyond SOF

    Washington DC
    2 days ago
  •  ...The contractor shall have expert level experience designing, deploying, and supporting PKI environments in a Windows domain. Candidate must have experience deploying internal certificate authorities. Must have experience issuing external certificates from external certificate... 
    Suggested
    For contractors

    Nicholson Strategic Solutions

    Washington DC
    4 days ago
  • $35.6 - $51.83 per hour

     ...Deskside Administrator II Location US-VA-Arlington ID 2026-4459 Category IT / Cyber Security / Network Systems Position Type Full-Time Remote No Clearance Required Secret Overview Now Hiring... 
    Cyber
    Full time
    Contract work
    Work at office
    Immediate start
    Remote work

    American Systems

    Arlington, VA
    2 days ago
  • $116k - $119k

    Responsibilities Responsible for the day-to-day management and support of encryption technologies and Public Key Infrastructure (PKI) systems across DoD environments. Administer encryption keys, certificates, and secure communications protocols to ensure data confidentiality... 
    Full time
    Part time

    Akima

    Alexandria, VA
    2 days ago
  • Conduct customer outreach to predict and understand client's organizational needs and user needs. Track cyber security tool usage and make recommendations about future tool investments. Use techniques from quality management to learn from prior development activities and... 
    Cyber
    Temporary work
    Work at office
    Relocation package

    ENS Solutions, LLC

    Washington DC
    18 hours ago
  •  ...Advanced Analytics, Artificial Intelligence/Machine Learning, Cyber Security and Cutting-Edge Technology across the US Government....  ...requirements. Certifications: Microsoft 365 Certified: Endpoint Administrator Associate, Microsoft Certified: Azure Administrator Associate,... 
    Cyber
    Flexible hours

    Halvik

    Alexandria, VA
    4 days ago
  •  ...We are seeking an experienced  PKI Engineer/IAM Engineer  to support enterprise Identity...  ...ideal candidate will have strong Linux administration skills, deep understanding of...  ...Management (ICAM), Software Development, Cyber and Network Security, System Engineering... 
    Cyber
    Temporary work
    Relocation package

    Enssolutions

    Washington DC
    5 days ago
  •  ...a fast‑growing firm, specializes in IT/Digital Modernization, Cyber Security, NextGen IT, Emerging Technology, and Mission Operations...  ...of all decisions and actions. We are seeking a Corporate Administrator to partner closely with the Chief Executive Officer (CEO) and... 
    Cyber
    Contract work
    Temporary work

    A3T (Agil3 Technology Solutions)

    Falls Church, VA
    2 days ago
  • $147.29k - $199.28k

     ...Infrastructure and Operations Skills: Multi-Factor Authentication (MFA),PKI Certificate Management,Public Key Infrastructure,Token Standards...  ...and authentication components Collaborate across engineering, cyber, and operations to integrate PKI into new technologies... 
    Cyber
    Temporary work
    Immediate start
    Worldwide
    Flexible hours

    General Dynamics Information Technology

    Washington DC
    2 days ago
  •  ...Job order - J1225-1860 - Permanent Full Time Title Information Systems Security Representative (ISSR) – Senior Level Category Cyber Security City Washington, District of Columbia, United States Job Description US CITIZENSHIP AND ACTIVE TOP SECRET OR TS/SCI CLEARANCE IS... 
    Cyber
    Permanent employment
    Full time
    Contract work
    Local area

    CGI Njoyn

    Washington DC
    1 day ago
  • $111.16k - $150.39k

     ...Trust/Other Required: None Job Family: Cyber and IT Risk Management Skills: Multi-Factor Authentication (MFA),PKI Certificate Management,Public Key...  ...Yes Job Description: PKI SYSTEMS ADMINISTRATOR YOUR IMPACT Own your opportunity to support... 
    Cyber
    Temporary work
    Immediate start
    Worldwide
    Flexible hours

    General Dynamics Information Technology

    Washington DC
    7 days ago
  • $96.57k - $130.65k

     ...edge of innovation. We operate across 50 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise... 
    Cyber
    Contract work
    Temporary work
    Immediate start
    Worldwide
    Flexible hours

    General Dynamics Information Technology

    Washington DC
    2 days ago
  • $110k - $130k

     ...Senior VDI Administrator Location: Washington, D.C.; Alexandria, VA; Colorado Springs, CO; Omaha, NE; Tampa, FL; or Millington, TN Clearance...  ...Community. We specialize in delivering advanced engineering, cyber, and intelligence solutions that drive mission success. Our... 
    Cyber
    Full time
    Contract work
    Remote work
    Afternoon shift

    Ennoble First, Inc.

    Alexandria, VA
    3 days ago
  • Overview ActioNet has an immediate opportunity for a n Splunk Administrator requiring a Public Trust - Level 5 Investigation , located in...  ...and expertise in Agile Software Engineering, Cloud Solutions, Cyber Security, and IT Managed Services. With 25+ years of stellar past... 
    Cyber
    Full time
    Immediate start
    Flexible hours

    ActioNet

    Washington DC
    8 hours ago
  •  ...portfolio of offerings includes high-end solutions in systems engineering and integration; enterprise IT, including cloud services; cyber; software; advanced analytics and simulation; and training. We are a team of 23,000 strong driven by mission, united purpose, and inspired... 
    Cyber
    Contract work
    For contractors
    Summer work
    Remote work

    SAIC

    Arlington, VA
    4 days ago
  • Overview We are looking for an experienced AWS Network Cloud Administrator who will be responsible for designing, deploying, and maintaining...  ...requirements Ensure all Virtual and Physical devices maintain Cyber Security Readiness Intrusion and Detection and Preventions... 
    Cyber
    Flexible hours

    HugoNet

    Arlington, VA
    4 days ago
  • $127.5k - $172.5k

     ...Job Qualifications: Skills: PKI Certificate Management, Public Key Infrastructure...  ...Yes Job Description: PKI Systems Administrator Advance how our customers...  ...in digital modernization, AI/ML, Cloud, Cyber and application development. Together with... 
    Cyber
    Temporary work
    Immediate start
    Remote work
    Worldwide
    Flexible hours

    General Dynamics Information Technology

    Washington DC
    6 days ago
  • $99k - $166.5k

     ...Network Mapper (NMAP), and/or similar applications A bachelor's or advanced degree in Computer Science, Cybersecurity, or other cyber discipline is preferred Active Top-Secret security clearance Desired Skills & Experience ~ Experience supporting a federal law... 
    Cyber
    Contract work
    Work experience placement
    H1b

    SMX Corporation

    Washington DC
    6 days ago
  • $70.66k - $74k

     ...Regulations (FAR), Microsoft Office, Proposals, Subcontracts Administration Certifications: None Experience: 2 + years of related...  ...leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we... 
    Cyber
    Contract work
    Temporary work
    For subcontractor
    Work at office
    Local area
    Immediate start
    Remote work
    Worldwide
    Flexible hours
    3 days per week

    General Dynamics Information Technology

    Falls Church, VA
    3 days ago
  • $157.25k - $212.75k

     ...None Job Family IT Infrastructure and Operations Job Description PKI Systems Engineer Advance how our customers operate while you...  ...offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive... 
    Cyber
    Temporary work
    Immediate start
    Remote work
    Worldwide
    Flexible hours

    General Dynamics Information Technology

    Washington DC
    2 days ago
  •  ...organizations from unknown threats using its proprietary AI. The Darktrace Active AI Security Platform delivers a proactive approach to cyber resilience to secure the business across the entire digital estate from network to cloud to email. Breakthrough innovations from our... 
    Cyber
    Work at office
    Remote work

    Darktrace

    Arlington, VA
    27 days ago
  •  ...organizations from unknown threats using its proprietary AI. The Darktrace Active AI Security Platform delivers a proactive approach to cyber resilience to secure the business across the entire digital estate from network to cloud to email. Breakthrough innovations from our... 
    Cyber
    Work at office
    Immediate start
    Remote work

    Darktrace

    Arlington, VA
    18 hours ago
  • $110.8k - $184.6k

     ...Google, our solutions focus on business outcomes with embedded cyber resiliency and AI to protect today and enable tomorrow backed...  ...family of companies. We are searching for a Senior Data Center Administrator or Data Center Administrator II who is a hands-on operational... 
    Cyber
    Work at office

    Cox Communications

    Washington DC
    2 days ago
  •  ...Job Description ECS is seeking a Cloud Administrator - Journeyman to support the Army National Guard's enterprise IT infrastructure...  ...required S. Citizenship required DoD 8140.03 Compliance: DoD Cyber Workforce Framework (DCWF) Work Role 651-Enterprise Architect-... 
    Cyber
    Contract work
    Night shift

    ECS

    Fairfax, VA
    6 days ago
  • $113k - $188k

    Job Family: IT Cyber Security Travel Required: None Clearance Required: Active Top Secret (TS) What You Will Do Our Cybersecurity Consultants are a team of business integrators with extensive consulting and industry experience who help our clients solve their complex... 
    Cyber
    Temporary work
    Flexible hours

    Guidehouse

    Arlington, VA
    18 hours ago
  •  ...Description We are seeking a highly skilled Senior PKI Governance & Configuration Manager to oversee the integrity, security, and...  ...engineering and integration; enterprise IT, including cloud services; cyber; software; advanced analytics and simulation; and training. We... 
    Cyber

    SAIC

    Springfield, VA
    3 days ago
  •  ...innovation, global expansion, and feature-rich multifunctionality. Our mission is to empower organizations to stay ahead of evolving cyber threats. Enterprises around the world are increasingly selecting SOCRadar to achieve proactive security by understanding their... 
    Cyber
    Remote work
    Flexible hours

    SOCRadar Extended Threat Intelligence

    Washington DC
    2 days ago
  •  ...IAM systems, and ensuring access requirements are met. Ideal candidates have over 3 years of cybersecurity experience, particularly in PKI, and must hold a Top Secret clearance. Support for obtaining Security+ certification is provided. Competitive salary and... 

    Phase2 Technology

    Arlington, VA
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cyber PKI Administrator. Be the first to apply!