Phia LLC

Senior Cybersecurity Engineer - PKI Security

Phia LLC United States · $111K–$163K/yr

Computer and Network Security · 11-50 employees

8 h ago
Remote security Principal (10+ yrs) Full-time United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Senior Cybersecurity Engineer will provide technical expertise for PKI administration, certificate lifecycle management, and operations within complex enterprise environments. They will also support certificate automation efforts, mentor the PKI team, and provide strategic guidance on encryption standards and security best practices.

What they look for

PKI Administration Certificate Authority Operations Encryption Technologies Automation Scripting PowerShell Python Venafi CyberArk REST API Active Directory Ansible Git TLS/SSL Hardware Security Modules Post Quantum Cryptography

Requirements

Candidates must have 9 to 12+ years of experience in cybersecurity and IT administration, along with a bachelor's degree in a related field. Proficiency in PKI, scripting, automation tools, and the ability to obtain a Public Trust security clearance are required.

Benefits

Medical Insurance Dental Insurance Vision Insurance Life Insurance Short Term Disability Long Term Disability 401k Retirement Savings Plan Paid Holidays Paid Time Off Tuition Assistance Professional Development Assistance

Full description

At phia we hire talented and passionate people who are focused on collaborative, meaningful work, providing technical and operational subject matter expertise and support services to our partners and clients.

phia is hiring a Senior Cybersecurity Engineer (PKI Security) to support cyber protection engineering and operations at a large Federal agency. This role focuses on providing technical expertise for PKI Administration and Certificate Authority operations across complex enterprise environments. The ideal candidate will have deep experience with encryption technologies, PKI administration and operations, and configuration automation and scripting.

This position offers REMOTE work flexibility. Qualified candidates will be U.S. Citizens and located in the United States, able to achieve Public Trust security vetting approval.

What You’ll Do:

  • Support internal and external customers with certificate-related issues across USPS applications and services.
  • Provide guidance and training to key stakeholders on PKI lifecycle management, processes, and procedures.
  • Review complex PKI and certificate-related issues, determine effective solutions, and recommend improvements to ensure efficient, reliable, and sustainable operations.
  • Support certificate automation using Venafi/CyberArk Trust Protection Platform (TPP) identifying opportunities to incorporate AI into automation efforts.
  • Create reports and documentation using AI and other automation tools.
  • Provide mentorship and management support for the PKI team, develop project requirements for complex and critical applications, provides sound strategic advice, technical expertise, and guidance to program and project staff
  • Stay current on encryption technologies and standards, with particular focus on PKI and CA productions, solutions, and operational best practices.
  • Provide status and activity reporting and plans to management.

Who You Are / What You Bring:

  • Extensive automation and scripting experience and capabilities
  • Strong knowledge of REST API integration, Simple Certificate Enrollment Protocol (SCEP), and Microsoft AD auto-enrollment
  • Familiarity with technologies such as VCERT, Portable Git, Ansible, and Visual Studio Code
  • Proficiency in PowerShell and Python scripting
  • Strong understanding of Public Key Infrastructure (PKI) including:• Certificate Authority (CA) Administration
  • Certificate Enrollment Web Service & Policy Web Service
  • Active Directory Certificate Services (ADCS) monitoring
  • Infrastructure experience in one or more of the following areas: IT or server administration, networking, Active Directory/LDAP, Unix/Linux, virtualization, or access control administration
  • Strong communication skills with IT customers, developers, and system administrators
  • Strong experience with certificate management tools, preferably Venafi/CyberArk, Microsoft Certificate Authority, and Hardware Security Modules (HSMs)
  • Heavy experience troubleshooting digital certificate issues, with an interest in advancing automation and AI-driven solutions
  • Knowledge of Post Quantum Cryptography (PQC)
  • Ability to work independently, work in a fast-paced environment, and attention to detail
  • Excellent communication, organizational, and interpersonal skills

Preferred Skills:

  • Experience with ServiceNow or other Change/Incident/Problem management ticketing technology
  • IT system administration experience (systems management, networks, firewalls) in an enterprise environment
  • Experience with user directory technologies for authentication (e.g., LDAP, Active Directory)
  • Experience with Microsoft Windows Server configuration, deployment, and troubleshooting
  • Experience with Unix and Linux configuration and troubleshooting
  • Experience with technologies that use TLS/SSL encryption (e.g., F5, Netscaler, IIS, Apache, WebLogic, WebSphere, etc.)
  • Proficiency with server virtualization technologies (VMWare, HyperV)
  • Database administration (MSSQL) experience

Required Education + Experience:

  • BA/BS in cybersecurity, IT or related field, with 9+ years of direct experience in cybersecurity and IT administration/engineering

...or...

  • 12+ years of experience in cybersecurity and IT administration/engineering

Certifications (desired, or similar):

  • CyberArk / Venafi Security Administrator (VSA)
  • Entrust nShield Certified Systems Engineer (nCSE)
  • EC-Council Certified Encryption Specialist (ECES)
  • Core cybersecurity certifications (e.g. CISSP, CompTIA Security+)
  • Core networking certifications (e.g. CompTIA Network+, CCNA, CCENT)

Security Clearance/Vetting:

  • U.S. Citizenship required
  • Ability to obtain Public Trust clearance

Who We Are

phia LLC ("phia") is a Northern Virginia based, small business established in 2011 with focus in Cyber Intelligence, Cyber Security/Defense, Intrusion Analysis & Incident Response, Cyber Architecture & Capability Analysis, Cyber Policy & Strategy, Information Assurance/Security, Compliance, Certification & Accreditation, Communications Security, Traditional Security, and Facilities Security. phia also provides cyber operations support functions such as: Program and Process Management, Engineering, Development, and Systems Administration that allows for Cyber Operations to efficiently integrate our customer’s missions and objectives. phia supports various agencies and offices within the Department of Defense (DoD), Federal government, and private/commercial entities.

phia offers excellent benefits to enhance work-life balance, including the following:

  • Medical Insurance
  • Dental Insurance
  • Vision Insurance
  • Life Insurance
  • Short Term & Long Term Disability
  • 401k Retirement Savings Plan with Company Match
  • Paid Holidays
  • Paid Time Off (PTO)
  • Tuition and Professional Development Assistance

#LI-PH1

Similar roles