PKI Operations Engineer
August Schell is seeking a PKI Operations Engineer to sustain and operate a DoD enterprise Public Key Infrastructure for our DISA customer. This role focuses on operating and hardening a live Red Hat Certificate System (RHCS) environment, supporting high-volume certificate authority operations, and driving initiatives like post-quantum cryptography (PQC) migration.
About the role
While our PKI Software Engineer builds next-generation certificate systems, this role ensures the infrastructure remains reliable: operating the live RHCS environment, onboarding new customers and enclaves, remediating CVEs, monitoring system health, and automating operational tasks. The engineer collaborates with commercial product engineering, government operations teams, and other program contractors. Hybrid work is required, with on-site presence at Fort Meade as needed.
Responsibilities
- Operate and sustain the production PKI environment on Red Hat Certificate System (RHCS), ensuring CA availability, certificate lifecycle operations, and issuance pipeline health.
- Run RA/CRL/OCSP operations and certificate lifecycle management, including transitioning to shorter-lived certificates with higher issuance volume (ACME automation).
- Onboard new customers, enclaves, and use cases onto the PKI, including configuration, integration, and secure hardening to program standards.
- Own CVE remediation and patch management for the PKI stack and underlying RHEL hosts, including tracking, testing, scheduling, and applying security patches with minimal disruption.
- Monitor system health and performance; build and maintain alerting, logging, and dashboards; respond to and resolve operational incidents; and lead root-cause analysis.
- Operate and troubleshoot HSM integrations (Entrust nShield / Thales Luna) supporting CA operations and key escrow.
- Automate operational tasks (health checks, backups, certificate/CRL monitoring, deployment, and configuration) using scripting and CI/CD tooling to reduce toil and manual error.
- Support the program’s PQC migration from an operations standpoint, including algorithm rollout, version transition, and validation in the live environment.
- Provide development support in an operational capacity—small fixes, config-as-code, tooling, and issue reproduction for the product engineering team—without owning the core feature-development backlog.
- Communicate clearly across government operations stakeholders, commercial vendor engineering, and program contractors; document runbooks and escalate risks and blockers before they impact operations.
Requirements
- Active Secret clearance minimum (Top Secret preferred and may be required).
- Local to the DMV area with the ability to work on-site at Fort Meade as requested.
- Five (5)+ years of relevant systems/operations engineering experience (flexible for candidates with exceptional PKI depth).
- Strong Linux (RHEL) systems administration and operations background, including patch management and system hardening.
- Knowledge or experience with Linux containers and container orchestration (Podman / Docker) and VMs (KVM).
- Hands-on experience operating PKI, x.509, cryptography, and system/software security technologies.
- Direct experience operating Red Hat Certificate System (RHCS). Dogtag PKI experience (RHCS’s upstream open-source project) is an accepted alternative, as is comparable enterprise CA platform operations (EJBCA, Microsoft AD CS, Entrust Authority, ISC CertAgent, or similar).
- Scripting/automation proficiency (Python, Bash, or similar) for operational tooling.
- DoD 8570/8140 IAT Level II certification (Security+ or equivalent).
- Strong written and verbal communication skills, with a habit of documenting runbooks and operational procedures.
Skills that stand out
- Prior DISA or DoD PKI program operations experience (Purebred, derived credentials, RA/CRL/OCSP operations at scale).
- HSM operations experience (Entrust nShield, Thales Luna)—the customer runs Entrust HSMs.
- ACME protocol and certificate automation at scale.
- Post-quantum cryptography familiarity (ML-DSA/Dilithium, Kyber, CNSA 2.0 timelines) from a migration/operations lens.
- Configuration management and infrastructure-as-code (Ansible, or similar).
- Directory Server / LDAP operations experience.
- Monitoring/observability tooling (Prometheus/Grafana, ELK, or similar) and incident response.
- Agile / ITSM operating rhythms (Scrum, JIRA, change management).
Schedule: Full-time, hybrid.