SonicJobs Logo
Left arrow iconBack to search

PKI Engineer - Active TS/SCI with CI Poly

ENS Solutions, LLC
Posted 5 months ago, valid for 14 days
Location

College Park, Prince George's 20742, MD

Salary

Competitive

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • The IAM Engineer position involves supporting large-scale Identity and Access Management projects while interfacing with stakeholders and engineering teams.
  • Candidates should have a minimum of 3 years of experience in PKI within the cybersecurity field and possess an active TS/SCI clearance.
  • The role requires expertise in Active Directory Certificate Services, security best practices, and certificate lifecycle management.
  • The salary for this position is competitive, with additional benefits including free medical coverage, a 401k contribution from day one, and paid time off.
  • Essential Network Security Solutions, LLC is a veteran-owned IT consulting firm that provides innovative solutions primarily for the Department of Defense and Intelligence Community.

We are seeking an experienced PKI Engineer/IAM Engineer to support enterprise Identity and Access Management (IAM), PKI, and Zero Trust initiatives. In this role, you will design, implement, automate, and maintain secure identity and cryptographic infrastructure solutions for large-scale enterprise environments.

You will work closely with stakeholders, security teams, and infrastructure engineers to support authentication, authorization, certificate management, and credential lifecycle processes. The ideal candidate will have strong Linux administration skills, deep understanding of certificate lifecycle management, and experience building secure PKI solutions in enterprise environments. 

Key Responsibilities

  • Design, implement, configure, and maintain enterprise PKI environments
  • Administer and support Linux-based systems hosting PKI services and related infrastructure
  • Manage certificate lifecycle operations including issuance, renewal, revocation, validation, and expiration monitoring
  • Develop and maintain automation for certificate deployment and lifecycle management using Ansible and Bash scripting
  • Configure and manage LDAP integrations and directory services related to PKI environments
  • Define and maintain policies, standards, and operational procedures
  • Troubleshoot PKI-related issues involving certificates, trust chains, TLS/SSL configurations, and cryptographic services
  • Collaborate with security and infrastructure teams to ensure compliance with enterprise security standards and best practices
  • Implement monitoring, auditing, backup, and disaster recovery procedures for PKI systems
  • Support asymmetric cryptography implementations and secure communications across enterprise platforms
  • Create and maintain technical documentation, architecture diagrams, and operational playbooks
  • 5+ years of experience in PKI engineering, infrastructure security, or systems administration
  • 8570/8140 Certification
  • Strong Linux system administration experience
  • Hands-on experience with:
    • Public Key Infrastructure (PKI)
    • Certificate Authority design, setup, and operations
    • LDAP administration and integrations
    • Ansible automation
    • Bash scripting
  • Experience with certificate lifecycle management and automation
  • Knowledge of certificate policies, certificate profiles, and certificate contents/extensions
  • Strong understanding of:
    • Asymmetric cryptography concepts
    • TLS/SSL certificates and trust models
    • Linux security principles and system hardening
  • Experience troubleshooting certificate and authentication-related issues in enterprise environments
  • Strong written and verbal communication skills

Preferred Qualifications

  • Experience working with Hardware Security Modules (HSMs)
  • Familiarity with ACME protocol and automated certificate enrollment solutions
  • Knowledge of compliance frameworks and security standards related to cryptography and certificate management
  • Experience with DevOps or Infrastructure-as-Code practices
  • Experience with Amazon Web Services (AWS)
  • Familiarity with enterprise identity and access management solutions

Essential Network Security (ENS) Solutions, LLC is a service-disabled veteran owned, highly regarded IT consulting and management firm. ENS consults for the Department of Defense (DoD) and Intelligence Community (IC) providing innovative solutions in the core competency area of Identity, Credential and Access Management (ICAM), Software Development, Cyber and Network Security, System Engineering, Program/Project Management, IT support, Solutions, and Services that yield enduring results. Our strong technical and management experts have been able to maintain a standard of excellence in their relationships while delivering innovative, scalable and collaborative infrastructure to our clients.

Why ENS?

  • Free Platinum-Level Medical/Dental/Vision coverage, 100% paid for by ENS
  • 401k Contribution from Day 1
  • PTO + 11 Paid Federal Holidays
  • Long & Short Term Disability Insurance
  • Group Term Life Insurance
  • Tuition, Certification & Professional Development Assistance
  • Workers’ Compensation
  • Relocation Assistance

Candidate AI Usage Policy

AI tools are an important part of daily work at ENS Solutions, and we are committed to their responsible and ethical use. To ensure a fair and equitable candidate evaluation based on individual skills, knowledge, and experience, candidates are not permitted to use artificial intelligence or other assistive tools during interviews, whether in person or virtual, unless explicit permission has been granted in advance.




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.