IAM Senior Engineer Public Key Infrastructure; PKI
Listed on 2026-01-23
-
IT/Tech
Cybersecurity, Systems Engineer -
Engineering
Cybersecurity, Systems Engineer
IAM Senior Engineer Public Key Infrastructure (PKI)
1 day ago Be among the first 25 applicants
This role has been designed as ‘Hybrid’ with an expectation that you will work on average 2 days per week from an HPE office.
Who We AreHewlett Packard Enterprise is the global edge‑to‑cloud company advancing the way people live and work. We help companies connect, protect, analyze, and act on their data and applications wherever they live, from edge to cloud, so they can turn insights into outcomes at the speed required to thrive in today’s complex world. Our culture thrives on finding new and better ways to accelerate what’s next.
We know varied backgrounds are valued and succeed here. We have the flexibility to manage our work and personal needs. We make bold moves, together, and are a force for good. If you are looking to stretch and grow your career our culture will embrace you. Open up opportunities with HPE.
About our Cybersecurity Team
Are you ready to make an impact with one of the world’s leading technology companies? HPE’s Cybersecurity team is where you can do just that. We protect enterprise identities, systems, and data by engineering secure, scalable, and resilient solutions across our global ecosystem. If you’re passionate about securing digital trust and building next‑generation identity and cryptographic systems, we’d love to have you on our team.
AboutThe Role
We are seeking a highly skilled Senior PKI Engineer to join our Identity and Access Management (IAM) organization. This role will be responsible for the design, implementation, and operational excellence of enterprise‑wide PKI and cryptographic services that enable secure authentication, encryption, and code signing across hybrid environments.
The ideal candidate will have deep expertise in certificate lifecycle management, cryptographic key management, Microsoft ADCS, and modern certificate‑based authentication solutions. You will collaborate closely with IAM, Infrastructure, Cloud, and Security Architecture teams to modernize and scale PKI services aligned with Zero Trust and regulatory compliance goals.
Key Responsibilities- Design, deploy, and maintain enterprise PKI architectures supporting both on‑premises and cloud environments (ADCS, AIA/CRL, OCSP, HSM, Root/Issuing CAs).
- Implement certificate lifecycle automation and governance for servers, endpoints, IoT, and application workloads.
- Lead modernization of PKI services to support phishing‑resistant authentication (FIDO2, smart cards, device certificates, mutual TLS, etc.).
- Integrate PKI with IAM solutions such as Entra , Okta, Cyber Ark, and Hashi Corp Vault for secure credential and key management.
- Manage and maintain Hardware Security Modules (HSMs) and key escrow solutions for signing and encryption workloads.
- Support code signing, device identity, and TLS/SSL certificate issuance in alignment with enterprise standards.
- Define and enforce policies, procedures, and security controls for key and certificate usage, issuance, and renewal.
- Collaborate with security operations and compliance teams to ensure audit readiness, incident response, and certificate‑related risk mitigation.
- Provide technical leadership, mentoring, and SME support to IAM and platform engineering teams.
- Bachelor’s degree in Computer Science, Engineering, or related field (or equivalent experience).
- 10+ years in IT or Cybersecurity, with 8+ years focused on PKI, cryptography, or identity security engineering.
- Proven hands‑on experience with Microsoft Active Directory Certificate Services (ADCS) and enterprise PKI management.
- Strong understanding of X.509, TLS/SSL, OCSP, CRL, HSM, and certificate policy frameworks.
- Experience with Digi Cert ONE, or similar certificate lifecycle automation tools like Venafi, AppViewX.
- Understanding of hardware root of trust, secure boot, and device identity models.
- Experience automating certificate issuance and renewal using Power Shell, Python, or API‑based workflows.
- Familiarity with cloud‑native certificate services (AWS PCA, Azure Key Vault, Google CA Service) and FIDO2/Web Authn implementations.
- Knowledge of integrating PKI with Identity and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).