Specialist - CyberSecurity
LTM · Atlanta, GA · 4 days ago
On-siteInformation Technology$110k–$130k/yrFull-time
Atlanta, Georgia (Onsite) • Full Time
About the role
PKI Senior Security Engineer responsible for maintaining and operating PKI platforms, ensuring certificate lifecycle management, and supporting cryptographic standards and compliance.
Responsibilities
- Maintain and operate PKI platforms including Certificate Authorities (CAs), HSMs, and certificate management systems.
- Ensure availability, resiliency, and patching of PKI infrastructure.
- Support certificate issuance, renewal, revocation, and lifecycle management.
- Manage large-scale certificate environments across applications and infrastructure.
- Ensure timely renewal and replacement of certificates.
- Support trust store management and certificate chain integrity.
- Build and implement automation for certificate lifecycle management.
- Integrate PKI services with enterprise platforms, CI/CD pipelines, cloud services, and applications.
- Deploy and operationalize tools such as connectors and automation pipelines.
- Enforce security policies related to certificate usage and cryptography.
- Define and maintain standards for certificate issuance, validity, and usage.
- Support compliance with regulatory frameworks (e.g., NIST, CMMC, PCI, TSA directives).
- Partner with application and infrastructure teams to enable certificate automation.
- Provide guidance and supporting tooling while ensuring clear ownership boundaries.
- Assist teams with onboarding to PKI services and automation.
- Identify and remediate risks related to certificate expiration, misconfiguration, or trust failures.
- Support incident response involving certificate or encryption issues.
- Improve visibility and reporting for certificate health and compliance.
- Support adoption of new cryptographic standards (e.g., post-quantum cryptography).
- Assist in modernization of PKI architecture and tooling.
- Evaluate new solutions for scalability and resilience.
Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, or related field, or equivalent experience.
- 3-7 years in PKI, cybersecurity engineering, or infrastructure security.
- Hands-on experience with certificate lifecycle management.
- Experience with PKI tools/platforms (e.g., Venafi, DigiCert, Microsoft CA, AWS ACM).
- Understanding of TLS/SSL, cryptographic principles, and key management.
Preferred Qualifications
- Experience with HSMs and key custody operations.
- PKI automation, APIs, pipelines, and scripting.
- Cloud certificate services (AWS, Azure).
- Knowledge of compliance frameworks (NIST, PCI-DSS, CMMC).
- Experience scaling PKI in large enterprise environments.
- Familiarity with trust store management across distributed systems.
Pay
$110,000 – $130,000 per annum. Actual compensation within the range will be dependent upon skills, experience, performance, and internal equity. Additional forms of compensation, such as an annual performance-based bonus or sales incentive pay, may be provided.
Benefits
- Comprehensive medical, dental, and vision plan.
- Short-term and long-term disability coverage.
- 401(k) plan with company match.
- Life insurance.
- Vacation time, sick leave, and paid holidays.
- Paid paternity and maternity leave.