Senior Software Engineer - PKI
Ford Motor Company · Dearborn, MI · 1 mo ago
HybridInformation Technology$119k–$199k/yrFull-time
Responsibilities
- Lead the full lifecycle of PKI and Key Management API services supporting our vehicle products and ecosystem — lead customer requirements gathering, architecture design, implementation, testing, deployment, monitoring, and post-launch support.
- Design and develop RESTful APIs and web services that are robust, secure, and scalable for various features and use cases: CRL/OCSP, ACME, Certificate Issuance, message encryption/decryption, software signing, key rotation and certificate lifecycle management, HSM integration with PKCS11.
- Implement access control methods that enforce least privilege access principles using OAuth or mTLS.
- Cryptographic Engineering: Implement and harden PKI and key services with deep knowledge of PKI industry standards, X.509, PKCS standards, elliptic curve cryptography (ECC) and RSA, post-quantum readiness, and hardware security module CSP integration. Apply hybrid encryption techniques with AES.
- Define and enforce PKI certificate policies and certificate profiles.
- Secure Systems Architecture: Design fault-tolerant, highly available PKI services with zero-downtime issuance, disaster recovery, and multi-region replication.
- Infrastructure and CI/CD Integration: Release and Deploy your apps through build server, CI/CD pipeline, and infrastructure involving on-premises and cloud Kubernetes.
- Security & Compliance: Monitor and address findings regularly in code base through SAST, DAST, software quality and security vulnerability scanning.
- Maintain and integrate with production PKI systems and supporting cryptographic interfaces.
- Monitor and Response: Actively assist in monitoring our systems and performing root cause analysis to address issues quickly. Implement robust application logging and integration with Splunk and security monitoring systems.
- Define and lead best practices for our software development process, perform code reviews, and mentor engineers while remaining hands-on in the codebase.
- Author and manage technical cybersecurity requirements and process documentation.
Qualifications
- Bachelor’s degree in Computer Science, Information Technology, OR a combination of education and experience.
- 5+ years of experience and proficiency in software engineering and secure coding practices using object oriented programming, including C#/C++, Java, Python or related languages.
- Experience and understanding of industry security standards and applying them in our software solutions and processes, including NIST, OWASP, and relevant ISO and IEEE standards.
- Strong knowledge and applicability of software architecture, development, methodologies and design principles including test-driven development.
- Application of Identity and Access Management principles in software services.
- Strong software testing skills that result in lasting quality solutions at scale.
- Proficient version control of development and release branches in Git.
- 3+ years of experience deploying and maintaining cloud infrastructure with Kubernetes or OpenShift, and managing database instances (SQL Postgres, Redis, MongoDB).
- 3+ years building, maintaining, and integrating with production PKI systems and supporting cryptographic interfaces.
- Strong knowledge of PKI and Key Management best practices.
- Excellent understanding and application of cybersecurity algorithms, standards, and strategies including RSA, ECC, AES, X.509, PKCS#11, ACME, OCSP, CRL, HSM integration.