PKI Subject Matter Expert w/Secret Clearance
TekSynap · Fort Meade, MD · 2 days ago
OTHRFull-time
Responsibilities
- Serve as the senior technical and cryptographic authority, the technical trust anchor for implementation, for algorithm evolution and Post-Quantum Cryptography across the DoD PKI Portfolio.
- Recommend approaches that steer the PKI program away from legacy, vulnerable cryptographic implementations.
- Develop and execute the plan to migrate DoD PKI to stronger cryptographic algorithms in accordance with NIST SP 800-131A Rev3 and the CNSA 2.0 PQC timeline, addressing encryption, digital signing, key agreement, key derivation, key wrapping, key transport, hash functions, and message authentication codes.
- Apply practical knowledge of NIST-standardized quantum-resistant algorithms, including ML-KEM and ML-DSA, and define the engineering steps required to transition existing systems to quantum-safe states.
- Maintain cryptographic agility across the portfolio in response to evolving NIST standards and Executive Order 14412, so algorithm changes are absorbed by configuration and re-test rather than re-architecture.
- Coordinate with COTS vendors (approximately 15 in the current ecosystem) to test feasibility and assess the timeliness of product transition plans; maintain the vendor tracking report and raise capability gaps to the coordination cell and Component CIOs.
- Develop and deploy PKE lab environments supporting Algorithm Evolution and PQC integration testing; document and report results to DoD working groups including the Certificate Validation Tiger Team.
- Evaluate HSM platforms for PQC readiness; HSM hardware refresh is within contract scope and the current environment uses Entrust HSMs.
- Provide Non-Person Entity (NPE) certificate management expertise, automating certificate lifecycles for routers, firewalls, microservices, and Kubernetes clusters using automated certificate management protocols such as EST and ACME.
- Support Certificate Authority Development, including CA architecture analysis, deficiency identification, Analysis of Alternatives development, and CA deployment across 42 NIPRNet and 31 SIPRNet Red Hat Certificate Authorities supporting approximately 10,000 certificate issuances per day.
- Provide input to CA deployment plans and develop and document Change Requests to modify software and hardware configurations, submitted through the PKI Configuration Management process and Remedy.
- Provide Tier III technical support for the most complex cryptographic and infrastructure issues, and review and update PKE enablement documentation as cryptographic changes are released.
Qualifications
- Ten (10) or more years of hands-on PKI, cryptographic engineering, or cryptographic infrastructure experience, including at least five (5) years in DoD or federal high-security environments.
- Hands-on, low-level technical proficiency in cryptographic infrastructure and system integration within high-security environments, with demonstrated capability to engineer solutions for complex hardware and legacy software integrations.
- Demonstrated understanding of the mathematics, protocols, and hardware that drive public key cryptography.
- Practical, demonstrable knowledge of NIST post-quantum standards (FIPS 203 ML-KEM, FIPS 204 ML-DSA, FIPS 205 SLH-DSA) and the engineering steps to migrate production systems to quantum-safe states.
- Expertise automating certificate lifecycles for Non-Person Entities (routers, firewalls, microservices, Kubernetes) using automated certificate management protocols (ACME, EST).
- Hands-on experience with Hardware Security Modules (Entrust, Thales, SafeNet), key ceremonies, and HSM lifecycle or refresh activities.
- Experience with Certificate Authority platforms, preferably Red Hat Certificate System, including CA stand-up, configuration, and certificate profile management across classified and unclassified domains.
- Working knowledge of DoD PKI policy, DoDI 8520.02, STIG application, and the DoD PKI Authority to Operate (ATO) accreditation process.
- Familiarity with the DoD PKE custom tool suite (e.g., InstallRoot, FileSigner, CRL Auto Cache, PITT) and software development in C++, C#, Java, Python, or Rust is strongly preferred.