高级PKI管理员 - 证书权威运营
Senior PKI Administrator - Certificate Authority Operations
描述
Dragonfli Group 是一家网络安全和 IT 咨询公司,为联邦机构和财富 100 强企业提供服务。总部位于华盛顿特区,Dragonfli 支持客户在本地、混合和完全远程环境中保护关键任务系统。
Dragonfli 正在寻找一位高级别 PKI 安全管理员/专家,以支持大型联邦机构的公钥基础设施(PKI)和证书颁发机构(CA)运营。该职位为完全远程工作,负责证书服务的日常健康状况——从证书颁发机构管理、Active Directory 证书服务(ADCS)监控到对内部和外部利益相关者的证书生命周期指导——同时推动 PKI 计划中的自动化和人工智能辅助改进。理想的候选人具备 9 年以上相关经验,对 Venafi 和/或 CyberArk TPP 有深入的实战经验,熟悉 Microsoft 证书颁发机构和硬件安全模块(HSMs),并能够监督 PKI 团队,同时就复杂、关键任务的证书问题向项目和计划利益相关者提供建议。
这是一项涉及大型美国联邦机构的多年合同职位。有之前联邦承包经验的候选人优先考虑。需要美国公民身份或永久居留权。如果被录用,所有与该职位相关的工作必须在美国本土进行。
职责:
- 为机构的应用程序和服务中的证书相关问题提供内部和外部客户的支持。
- 为关键利益相关者提供 PKI 生命周期管理、流程和程序的指导和培训。
- 使用人工智能和其他自动化工具创建报告和文档。
- 审查复杂的 PKI 和证书相关问题,确定有效的解决方案,并推荐改进措施,以确保高效、可靠和可持续的运营。
- 使用 Venafi/CyberArk TPP 支持证书自动化,识别将人工智能纳入自动化工作的机会。
- 监督 PKI 团队,为复杂和关键的应用程序制定项目需求,并为项目和计划人员提供可靠的策略建议、技术专长和指导。
- 在快节奏的环境中独立工作,注重细节。
- 要求
- 必备条件:
- 计算机、IT 或安全相关领域的学士学位;或同等经验。
- 9 年以上相关的 PKI/证书管理经验
查看英文原文
Description
Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.
Dragonfli is seeking a Senior-Level PKI Security Admin / Subject Matter Expert to support Public Key Infrastructure (PKI) and Certificate Authority (CA) operations for a large federal agency. This fully remote role owns the day-to-day health of certificate services — from Certificate Authority administration and Active Directory Certificate Services (ADCS) monitoring to certificate lifecycle guidance for internal and external stakeholders — while driving automation and AI-assisted improvements across the PKI program. The ideal candidate brings 9+ years of relevant experience, deep hands-on expertise with Venafi and/or CyberArk TPP, Microsoft Certificate Authority, and Hardware Security Modules (HSMs), and is comfortable supervising a PKI team while advising program and project stakeholders on complex, mission-critical certificate issues.
This is a multi-year contract position involving a large US federal agency. Candidates with previous federal contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S.
Responsibilities:
- Support internal and external customers with certificate-related issues across the agency's applications and services.
- Provide guidance and training to key stakeholders on PKI lifecycle management, processes, and procedures.
- Create reports and documentation using AI and other automation tools.
- Review complex PKI and certificate-related issues, determine effective solutions, and recommend improvements to ensure efficient, reliable, and sustainable operations.
- Support certificate automation using Venafi/CyberArk TPP, identifying opportunities to incorporate AI into automation efforts.
- Supervise the PKI team, develop project requirements for complex and critical applications, and provide sound strategic advice, technical expertise, and guidance to program and project staff.
- Work independently in a fast-paced environment with strong attention to detail.
Requirements
Must-Have:
- Bachelor's degree in computers, IT, or a Security-related field; or equivalent experience.
- 9+ years of relevant PKI/certificate management experience.
- Strong knowledge of REST API integration, Simple Certificate Enrollment Protocol (SCEP), and Microsoft AD auto-enrollment.
- Familiarity with VCERT, Portable Git, Ansible, and Visual Studio Code.
- Proficiency in PowerShell scripting.
- Strong understanding of PKI, including Certificate Authority Administration, Certificate Enrollment Web Service & Policy Web Service, and Active Directory Certificate Services (ADCS) monitoring.
- Infrastructure experience in one or more of: IT/server administration, networking, Active Directory/LDAP, Unix/Linux, virtualization, or access control administration.
- Strong experience with certificate management tools, preferably Venafi/CyberArk, Microsoft Certificate Authority, and Hardware Security Modules (HSMs).
- Heavy experience troubleshooting digital certificate issues, with an interest in advancing automation and AI-driven solutions.
- Knowledge of Post-Quantum Cryptography.
- Strong communication skills with IT customers, developers, and system administrators.
Preferred / Nice-to-Have:
- Experience with ServiceNow or other Change/Incident/Problem management ticketing technology.
- IT system administration experience (systems management, networks, firewalls) in an enterprise environment.
- Experience with directory technologies for authentication (LDAP, Active Directory).
- Experience with Microsoft Windows Server configuration, deployment, and troubleshooting.
- Experience with Unix and Linux configuration and troubleshooting.
- Experience with TLS/SSL-based technologies (F5, Netscaler, IIS, Apache, WebLogic, WebSphere, etc.).
- Proficiency with server virtualization technologies (VMware, Hyper-V).
- Database administration (MSSQL) experience.
- Relevant training/certifications: A+, Network+, Security+, nCSE, Venafi/CyberArk Admin, Certified Encryption Engineer, CCENT, CCNA.
Skill(s)
Technical Skills:
- Public Key Infrastructure (PKI) administration and Certificate Authority operations
- Certificate lifecycle management (issuance, renewal, revocation)
- Venafi / CyberArk TPP certificate automation
- Microsoft Certificate Authority & Active Directory Certificate Services (ADCS)
- REST API integration and PowerShell scripting
- SCEP and Microsoft AD auto-enrollment
- Hardware Security Modules (HSMs)
- Post-Quantum Cryptography awareness
Soft Skills:
- Strong stakeholder communication and training/mentorship ability
- Independent, self-directed work style in a fast-paced environment
- Attention to detail and structured problem-solving
- Team supervision and technical leadership
- Ability to translate complex technical issues into clear guidance for non-technical stakeholders
Benefits
- Medical — Multiple POS health plan options including an HSA-compatible plan
- Dental — PPO coverage for preventive, basic, and major services
- Vision — Annual exam, frames, lenses, and contact lens allowance
- 401(k) — Employer match up to 5% of eligible compensation
- Long-Term Disability — 100% employer-paid coverage at 50% of pre-disability earnings
- Life Insurance & AD&D — 100% employer-paid coverage valued at $10,000 each
- PTO — 15–25 days annually based on tenure
- Paid Federal Holidays — All 11 federal holidays observed
Originally posted on Himalayas