PKI Lead Engineer
$122.9k - $150kASM Research, An Accenture Federal Services Company
The PKI Lead Engineer serves as the senior technical authority for the design, implementation, and sustainment of enterprise Public Key Infrastructure services that enable secure authentication, encryption, and digital signatures across the client's IT environment. This role leads the lifecycle management of digital certificates and cryptographic keys, ensuring resilient, compliant, and well-governed PKI capabilities that protect sensitive information and support mission critical access control.
Key Responsibilities
Lead the design, implementation, and ongoing operations of enterprise PKI infrastructures, including root and subordinate certificate authorities, registration authorities, and associated hardware and software components.
Manage the full lifecycle of digital certificates and cryptographic keys for users, devices, applications, and services, including issuance, renewal, suspension, and revocation with strong controls and automation.
Develop, document, and enforce PKI policies, certification practice statements, standards, and procedures aligned to enterprise security and regulatory requirements.
Integrate PKI services with identity and access management platforms, directory services, network security controls, and secure application architectures to enable strong authentication and encryption.
Monitor, audit, and assess PKI infrastructure health and compliance, performing regular reviews, root cause analyses, and remediation activities to maintain high availability and integrity.
Lead the evaluation, selection, and implementation of PKI related tools, including certificate discovery, management, and automation solutions, and recommend improvements to strengthen cryptographic services.
Collaborate with security operations and application teams to analyze and respond to PKI related incidents, vulnerabilities, and findings, including support for penetration testing and secure code initiatives.
Provide expert guidance, training, and mentoring to engineers and developers on PKI usage, certificate management best practices, and secure cryptographic design patterns in enterprise environments.
Required Qualifications
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or related technical discipline, or equivalent relevant experience.
Minimum of 8 years of experience in cybersecurity, security engineering, or network security roles, including significant hands-on exposure to PKI or cryptographic services.
Demonstrated experience designing, implementing, and operating enterprise PKI solutions, including certificate authorities, key management, and certificate lifecycle workflows.
Strong knowledge of authentication, authorization, and encryption concepts, including TLS, digital signatures, certificate based access control, and related standards (for example, X.509, OCSP, CRL).
Ability to obtain and maintain a Public Trust investigation, with US citizenship required in support of federal client requirements.
Proficiency with Unix/Linux or similar operating systems and enterprise infrastructure environments used to host PKI and security services.
Candidates must possess a current secret security clearance.
Preferred Qualifications
Advanced cybersecurity certifications such as CISSP, CISM, CISA, or CRISC demonstrating broad security architecture and governance expertise.
Experience integrating PKI with identity and access management platforms, federated identity standards (for example, SAML), and role based access control models in large enterprises.
Background supporting PKI and cryptographic services in complex federal or regulated IT environments with rigorous compliance requirements.
Handson experience with certificate discovery and management tools, hardware security modules, and automation frameworks for largescale certificate deployment.
Familiarity with secure software development practices, application security testing, and remediation of cryptographic vulnerabilities across web and service architectures.
Prior experience leading small technical teams or serving as a subject matter expert for enterprise security initiatives.
Job-Specific Skills
Enterprise PKI Architecture â?¯-- Designs and documents scalable PKI architectures, including root hierarchy, trust models, and integration patterns with enterprise systems.
Certificate Lifecycle Management â?¯-- Establishes and operates repeatable processes and automation for issuing, renewing, and revoking certificates for diverse identities and workloads.
Cryptographic Standards Expertise â?¯-- Applies industry cryptographic standards and algorithms to ensure strong encryption, signing, and key management practices in enterprise solutions.
Policy and Governance Development â?¯-- Authors and maintains PKI policies, standards, and certification practice statements, aligning them with organizational risk and compliance needs.
Security Integration Engineering â?¯-- Integrates PKI with identity, access management, network devices, and applications to enable secure, certificate based controls.
PKI Monitoring and Audit â?¯-- Implements monitoring, logging, and audit processes that provide visibility into PKI operations and support internal and external assessments.
Incident Response for PKI â?¯-- Leads investigation and remediation of PKI related incidents, including mis-issued certificates, key compromise, and cryptographic vulnerabilities.
Automation and Tooling â?¯-- Leverages scripting, configuration management, and PKI toolsets to streamline certificate issuance, enrollment, and inventory management.
Cross Functional Collaboration â?¯-- Works closely with security, infrastructure, application, and operations teams to align PKI capabilities with enterprise objectives and constraints.
Technical Mentorship â?¯-- Coaches junior engineers and developers on PKI concepts, secure implementation patterns, and operational best practices to uplift team capability.
Preferred Skills
Experience engineering PKI solutions in hybrid cloud and on premises environments, including integration with major cloud providers' identity and key management services.
Advanced scripting or automation capability (for example, PowerShell, Python, or similar) used to integrate PKI workflows with enterprise tooling and CI/CD pipelines.
Familiarity with certificate based network access control, VPN, and device authentication architectures in large, distributed environments.
Experience conducting PKI focused security assessments, including configuration reviews, key protection evaluations, and readiness for external compliance audits.
Compensation Ranges
Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.
EEO Requirements
It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.
All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment.
Physical Requirements
The physical requirements described in "Knowledge, Skills and Abilities" above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, "light office duties' or "lifting up to 50 pounds" or "some travel" required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions.
Disclaimer
The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.
$122,900 - 150,000
EEO Requirements
It is the policy of ASM that an individual's race, color, religion, sex, disability, age, gender identity, veteran status, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.
All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, veteran status, disability, gender identity, or age. All decisions on employment are made to abide by the principle of equal employment.
$161k - $266k
...Lead, Cryptographic Security Engineer Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our... ...strategy, standards, and architecture for the cryptography, PKI and key management aspects of the SDLC including...SuggestedFull timeTemporary workPart timeWorldwideFlexible hours- ...strengthen and protect our nation's vital interests. Requisition #: 1636 Job Title: Senior Technical Lead - Mission Engineering Location: Arlington, VA Clearance Level: Secret, Must Have Clearance to Start Job Description...Suggested
- Job Description Job Description Technical Lead (Systems Engineer)Suggested
- ...Technical Lead – Program Principal Engineer (C++) Bethesda, Maryland Overview Black Canyon Consulting (BCC) is searching for a Technical Lead - Program Principal Engineer to support our work for the National Center for Biotechnology Information (NCBI) at the National...SuggestedFull timeWork experience placementWork at officeRemote work
- ...Overview Sedaro is hiring a Lead DevOps Engineer to build our culture of operational excellence. In this role, you will integrate CI/CD, security, and observability tools and automation for our Kubernetes-based multi-cloud environment, as well as rallying your...SuggestedPermanent employmentFlexible hours3 days per week
$85.15k - $153.93k
...and mission success, ensuring the Navy is prepared for the challenges of tomorrow. Position Overview We are seeking a Lead Systems Engineer to become the requirements, capabilities, and test evaluation subject matter expert for the US Navy's preemineet surface fleet...Interim roleLocal areaImmediate start$43 - $48 per hour
...Learn more about American University Department: Operating Engineering 1 Time Type: Full time Job Type: Regular... ...Union: Excluded Job Description: Summary: The Lead Operating Engineer serves as a Team Lead and oversees the work...Hourly payFull timeLocal areaShift workAfternoon shift$38.25 - $45 per hour
...Job Title Lead Operating Engineer Job Description Summary Responsible to ensure the proper efficient operations and maintenance of the mechanical electrical and plumbing systems for the assigned facility. The performance of all necessary maintenance and operational...Minimum wageFor contractorsApprenticeshipWork at officeLocal areaImmediate startFlexible hoursShift work$165k - $175k
...Lead Engineer Opportunity HHAeXchange is the leading technology platform for home and community-based care. Founded in 2008, HHAeXchange was born out of an idea to create an end-to-end homecare solution to help people who are aging or have disabilities thrive in their...Full timeLocal areaFlexible hoursNight shift$161k - $266k
...products and services that help people, businesses and governments realize their greatest potential. Title and Summary Lead Software Engineer Mastercard's Portfolio Intelligence program is seeking a Lead Software Engineer to play a pivotal role in the...Full timePart timeWorldwideFlexible hours3 days per week$135.06k - $155.06k
...diversity and inclusion are core to our business. Join Evolent for the mission. Stay for the culture. What You’ll Be Doing: Lead Software Engineer (Arlington, VA) - Telecommuting Permissible. (multiple positions). Lead and participate in all aspects of software...Immediate startRemote work- ...Lead Cybersecurity Engineer Washington, DC Type: Contract Category: Security Industry: Government Reference ID: JN -062026-107232 Date Posted: 06/04/2026 Shortcut: Description Recommended Jobs Description: Hybrid 2 Days Onsite/3 Days...Hourly payContract workLocal areaRemote workNight shift
- ...Lead Software Engineer BaaS Team Anywhere Type: Contract-to-Hire Category: Development Industry: Financial Services Workplace Type: Remote Reference ID: JN -052026-106955 Date Posted: 05/12/2026 Shortcut: Description Recommended Jobs...Hourly payContract workLocal areaRemote workFlexible hours
- ...Job Description Job Description Position Overview: The Lead VOIP Engineer will serve as the primary technical authority responsible for the planning, design, deployment, maintenance, and support of the Voice over Internet Protocol (VOIP) systems. This role involves...Contract workFor contractorsRemote work
- ...Lead Software Engineer- CoStar- Arlington, VA Job Description Overview CoStar Group is a leading global provider of commercial and residential real estate information, analytics, and online marketplaces. Included in the S&P 500 Index, CoStar Group is on a mission...Full timeImmediate startWork from home
- ...Overview: Lead Software Engineer, Full Stack Position Responsibilities 5 DAYS ON SITE CONTRACT TO HIRE ROLE (NO SPONORSHIP) JSCRIPT/REACT FRONT-END GO- BACKEND About the Role seeking a talented Lead Full Stack Software Engineer to join our forward...Full timeContract workTemporary workWork at office
- ...The Lead Information Security Engineer supports the InfoSec mission of securing the patient experience. This position oversees and manages engineering of information security applications and systems to ensure compliance with Children's National Hospital IT standards....Work experience placement
$100k - $160k
...Location: Bethesda, MD ( 2 Days Onsite - May increase as Client needs change) Position Title: Lead Software Engineer - DevSecOps & Modernization Clearance: Public Trust Sponsorship: No Current or Future Sponsorship offered for this role. Job Overview: LCG...Work experience placementLocal areaImmediate start$82.9k - $217.25k
...Job Title Lead Enterprise Content Management Developer Job Description Leads the design, development, and support of modern... ...Management (ECM) and workflow automation. Applies modern engineering practices CI/CD, automated testing, infrastructure as code, and...Contract workWork at officeFlexible hours- ...value to clients through tailored solutions grounded in industry-leading practices. ProSidian provides enterprise services/solutions... ...Risk Management, Compliance, Business Process, IT Effectiveness, Engineering, Environmental, Sustainability, and Human Capital. We help...Full timeContract workFor contractorsWork at officeRemote work
$140k - $170k
...Job Description Job Description What Impact You'll Have We have an exciting opportunity for an experienced Lead LAN/WAN Engineer who will provide expert design, analysis, research, and operation support to exceptionally complex networking problems and processes....Contract workLocal areaImmediate start- ...Duties, responsibilities and activities may change at any time with or without notice Responsibilities We are seeking a Lead Engineer to join our team supporting Joint Service Provider (JSP) Engineering and Development for the Enterprise (ED-E) contract in Arlington...Full timeContract workTemporary workWork at officeLocal areaMonday to FridayWeekend workDay shiftAfternoon shift
- ...Lead Engineer Responsible to ensure the proper efficient operations and maintenance of the mechanical, electrical, and plumbing systems for the assigned facility. The performance of all necessary maintenance and operational tasks are developed to assure maximum life...For contractorsApprenticeshipWork at officeImmediate startFlexible hoursShift work
- ...Lead Security Engineer At B&A, we foster and embrace a distinct set of values that we live by and instill in all aspects of our organization: dedication, commitment, partnership, trust, and recognition. We have incorporated these values into successful delivery...Full timeWork at officeLocal area
- ...Lead Security Engineer This position supports Revolutional's federal customer as part of an application transformation and modernization initiative. This program is driving a large-scale transformation of systems into a data-centric, cloud-native ecosystem capable...For contractors
- ...Lead Security Engineer Job Description Overview CoStar Group is a leading global provider of commercial and residential real estate information, analytics, and online marketplaces. Included in the S&P 500 Index, CoStar Group is on a mission to digitize the...Full timeWork at officeWork from homeMonday to Thursday
$140k - $155k
...Lead Security Engineer (Active Top Secret Clearance Required) Washington, D.C. Clear Creek Federal is part of the Seneca Nation Group (SNG) portfolio of companies. SNG is Seneca Holdings' federal government contracting business that meets mission-critical needs...Full timeContract workFlexible hours- ...Intelligence Community, and Law Enforcement agencies. Job Summary We are seeking a Subject Matter Expert (SME)–level Lead Security Engineer to lead application security across a large-scale, cloud-native federal modernization program supporting the U.S. Census...Contract workWork at officeFlexible hours
- ...Immediate Position Overview We are seeking a Senior Software Engineer to support a mission-critical program within the Intelligence... ...and mentorship responsibility: the successful candidate will lead the development of reusable Helm charts, GitOps templates, and deployment...Full timeImmediate start
- ...Lead Engineer/Project Manager As a Lead Engineer/Project Manager at MPR, you will serve as both an engineer and project leader, applying engineering expertise to solve complex challenges while managing project scope, schedule, budget, and client relationships. Consulting...Permanent employmentFull timeImmediate start
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to PKI Lead Engineer. Be the first to apply!
- lead engineer Washington DC
- lead security engineer Washington DC
- lead network engineer Washington DC
- lead infrastructure engineer Washington DC
- lead operating engineer Washington DC
- lead system engineer Washington DC
- lead maintenance engineer
- lead sharepoint developer
- lead piping engineer
- lead automation engineer



