公钥基础设施(PKI)架构师
Public Key Infrastructure (PKI) Architect
Capital Technology Group 提供专业的咨询、软件开发、数字化转型、以用户为中心的设计、数据分析与可视化以及网络安全服务。
我们的跨学科团队使用敏捷方法,与客户紧密合作,快速且逐步地交付价值。在过去十年中,我们一直被联邦政府和商业客户所信赖,以解决复杂的、关键任务的业务挑战。我们的工作质量通过加入数字服务联盟而得到认可,该联盟由在提供 IT 服务方面表现出色的前瞻性公司组成。
客户要求:申请人必须是美国公民,并能够获得公共信任许可
CTG 的体验
在 Capital Technology Group(CTG),我们的团队热衷于现代化联邦政府的软件交付方式。我们与联邦机构合作,构建安全、可扩展且以任务为导向的解决方案,对数百万人产生深远影响。CTG 被《华盛顿邮报》评为 2025 年和 2026 年的顶级工作场所。CTG 培养一种植根于核心价值观的文化。我们的价值观指导我们如何协作并互相支持,创造一个员工感到被信任、被赋予权力并被鼓励在个人和职业上成长的环境。
职位简介
CTG 正在寻找一名 PKI 架构师,负责设计、实施和现代化企业公钥基础设施(PKI)及身份信任服务,以支持关键任务的联邦系统。这个职位适合一位拥有深厚密码系统、身份安全和在复杂、高安全性环境中可扩展基础设施设计经验的高级技术架构师。
你将参与
- 设计、实施和演进 PKI 架构,以实现安全认证和零信任计划
- 在 AWS 和 Azure 环境中构建和维护云原生解决方案
- 使用 Ansible 和 CI/CD 流水线自动化基础设施、部署和运维流程
- 与安全和工程团队合作,实施 DevSecOps 实践和安全软件交付
- 支持符合 FIPS、NIST 800-53、FISMA 和零信任架构原则的合规性计划
- 使用安全和可观测性工具监控、排查和优化应用和平台性能
你具备
- 一位善于协作的工程师,喜欢解决复杂的技术和安全挑战
查看英文原文
Capital Technology Group provides expert consulting services software development, digital transformation, human-centered design, data analytics and visualization, and cybersecurity.
Our multidisciplinary teams use agile methodologies to rapidly and incrementally deliver value in close collaboration with our clients. For over a decade, we have been trusted by both federal and commercial clients to solve complex, mission-critical business challenges. The quality of our work has been recognized by our partners and peers through our inclusion in the Digital Services Coalition, a group of forward- thinking firms recognized for excellence in delivering IT services.
Client Requirements: applicants MUST BE US Citizens and be able to obtain Public Trust clearance
The CTG Experience
At Capital Technology Group (CTG), our teams are passionate about modernizing how the federal government delivers software. We partner with federal agencies to build secure, scalable, and mission-driven solutions that make a meaningful impact on millions of people. Recognized by The Washington Post as a Top Workplace in 2025 and 2026. CTG fosters a culture rooted in our core values. Our values guide how we work together and support one another, creating an environment where employees feel trusted, empowered, and encouraged to grow both personally and professionally.
About the Role
CTG is seeking a PKI Architect to design, implement, and modernize enterprise Public Key Infrastructure (PKI) and identity trust services supporting mission-critical federal systems. This role is ideal for a senior technical architect with deep expertise in cryptographic systems, identity security, and scalable infrastructure design across complex, highly secure environments.
You Will Get To
- Design, implement, and evolve PKI architectures that enable secure authentication and Zero Trust initiatives
- Build and support cloud-native solutions across AWS and Azure environments.
- Automate infrastructure, deployments, and operational processes using Ansible and CI/CD pipelines.
- Partner with security and engineering teams to implement DevSecOps practices and secure software delivery.
- Support compliance initiatives aligned with FIPS, NIST 800-53, FISMA, and Zero Trust Architecture principles.
- Monitor, troubleshoot, and optimize application and platform performance using security and observability tools.
Who You Are
- A collaborative engineer who enjoys solving complex technical and security challenges.
- Passionate about building scalable, secure, and reliable cloud-based solutions.
- Comfortable working across application development, cloud infrastructure, identity, and security domains.
- Skilled at balancing technical innovation with operational excellence and compliance requirements.
- An effective communicator who can work with cross-functional teams and stakeholders.
Qualifications
- Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, Engineering, Mathematics, or a related technical field (or equivalent experience)
- 4+ years of professional experience in PKI architecting, cybersecurity engineering, identity and access management (IAM), infrastructure/security architecture, or enterprise platform engineering (not limited to application development)
- Experience designing and supporting PKI solutions in FICAM and Federal PKI (FPKI) environments.
- Experience with X.509 certificate lifecycle management, automation, and policy development.
- Knowledge of X.509 certificate policies and CA/Browser Forum standards.
- Experience implementing certificate automation using ACME.
- Experience with Hardware Security Modules (HSMs) and cryptographic key management.
- Familiarity with Post-Quantum Cryptography (PQC) concepts and migration strategies.
- Experience with PKI platforms including DigiCert, Entrust, Microsoft AD CS, and Let's Encrypt.
- Experience supporting CAC/PIV smart cards, server, code-signing, and S/MIME certificates, including certificate trust chains and validation.
- Experience with cloud platforms such as AWS and/or Azure.
- Familiarity with DevSecOps practices, CI/CD pipelines, and source control platforms such as GitHub Enterprise.
- Understanding of security frameworks and standards including NIST, FISMA, FIPS, and Zero Trust principles.
Nice to Have
- Experience using Docker and Kubernetes.
- Experience with Shibboleth, CyberArk, or HashiCorp Vault.
- Experience with Splunk, Tenable, Checkmarx, SonarQube, or related security tooling.
- Experience with STIG hardening, vulnerability management, or compliance programs.
- Familiarity with PIV authentication and identity governance solutions.
- Experience supporting highly regulated environments, including federal or public sector organizations.
- Relevant cloud, security, or architecture certifications.
Client Requirements
- Applicants must be U.S. Citizens
- Ability to obtain a Public Trust clearance
Salary
We are committed to offering a competitive salary for this position, with an estimated range of $120,000 to $160,000 annually. Please note that this range is intended to provide a general idea of what to expect. The final offer may vary based on experience, skills, and other factors.
Full Time Employee Benefits
- Remote Work (Hybrid roles will be specified in the job post)
- Competitive Compensation Package
- Medical, Dental, and Vision
- Life Insurance, Short/Long Term Disability
- Employee Assistance Program
- 401(k) with 4% matching
- Liberal PTO vacation policy
- Generous Annual Continuing Education
- Annual Wellness Budget
- Bonus Incentive Programs (Employee referrals and performance-based rewards)
Thanks for your interest in Capital Technology Group!
Capital Technology Group is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law.
Originally posted on Himalayas