PKI Subject Matter Expert - ICAM, Federation & Enablement w/Secret Clearance
TekSynap · Fort Meade, MD · 2 days ago
OTHRFull-time
Responsibilities
- Serve as the primary technical authority for enabling cryptographic infrastructure, ensuring interoperability with federal ICAM architectures and compliance with DoDI 8520.02.
- Provide smart card and authenticator enablement expertise, including direct configuration of smart card middleware, Common Access Card (CAC) and PIV credentials, and Derived Credentials for mobile devices such as Purebred.
- Apply mastery of directory services and relying party integration, including LDAP, Active Directory, and Active Directory Certificate Services (ADCS), to facilitate automated certificate enrollment (EST/ACME) and group policy-driven deployments.
- Configure and advise on federation and trust relations, including cross-certification, bridge certification, and federated trust models that enable secure collaboration with external mission partners and federal agencies.
- Support DoD and federal partner Zero Trust compliance by advising Only Locally Trusted (OLT) PKI operators on interoperability and compliance for the PKI-related Zero Trust activities, identifying OLT unique requirements and assessing enterprise PKI suitability to meet those requirements.
- Document methods to modernize DoD PKI to reduce reliance on OLT PKIs, and develop, document, and maintain guidance on Zero Trust requirements as reference architecture and NIST direction evolve.
- Lead External PKI Interoperability support for external DoW agencies and federal partners, including partner assessment, trust establishment, and interoperability validation.
- Provide senior Tier III PKE consultation and engineering support to end users, system and network administrators, developers and integrators, and privileged users across NIPRNet and SIPRNet, including on-site support for enterprise programs designing architectures to accept and validate ECA, DoD PKI, and DoD-approved certificates.
- Provide technical advice and guidance on the correct use of DoD PKI certificates in the development and review of policy, directives, instructions, and emerging capabilities documentation, including DISA STIGs (estimated 3-4 per month), DISA Advisory Messages, and PKI policy reviews.
- Support External Certificate Authority (ECA) PKI activities, including vendor coordination, Approved Device List (ADE) maintenance, and interoperability validation.
- Contribute recommendations to DoD PKI PMO Support that improve the usability and efficiency of the DoD PKI and support external PKI integration.
- Author and review PKE implementation documentation, reference guides, and information papers that communicate engineering results to the DoD community.
Qualifications
- Ten (10) or more years of hands-on PKI, ICAM, or identity and credential engineering experience, including at least five (5) years in DoD or federal high-security environments.
- Hands-on, low-level technical proficiency in cryptographic infrastructure, identity federation, and system integration within high-security environments, with demonstrated capability to engineer solutions for complex hardware and legacy software integrations.
- Direct experience configuring smart card middleware, CAC and PIV credentials, and Derived Credentials for mobile devices (e.g., Purebred).
- Demonstrated mastery of LDAP, Active Directory, and Active Directory Certificate Services (ADCS), including automated certificate enrollment (EST/ACME) and group policy-driven certificate deployment.
- Demonstrated experience configuring cross-certification, bridge certification, and federated trust models with external mission partners or federal agencies (e.g., Federal Bridge, PIV-I interoperability).
- Working knowledge of federal ICAM architectures and DoDI 8520.02 compliance requirements.
- Familiarity with DoD Zero Trust reference architecture and the PKI-related Zero Trust activities, with the ability to provide advisory guidance to PKI operators.
- Experience delivering senior-level technical consultation and Tier III support to enterprise programs and privileged users across NIPRNet and SIPRNet.
- Experience reviewing or authoring technical policy, guidance, STIG content, or implementation documentation for a DoD or federal customer.