Description:
Grant Leading Technology is seeking a candidate for an Intermediate Cyber Security Engineer Public Key Infrastructure (PKI) to join our dynamic team. The candidate will provide advanced engineering, administration, and operational support for a large-scale Department of Defense (DOD) PKI environment supporting the Defense Logistics Agency (DLA). This position is responsible for engineering secure PKI solutions, maintaining trusted operating system baselines, implementing cryptographic technologies, and supporting enterprise certificate lifecycle management across on-premises and cloud environments.
The engineer will support the design, implementation, testing, deployment, and maintenance of PKI infrastructure while ensuring compliance with DOD cybersecurity requirements. The position requires collaboration with cybersecurity, infrastructure, cloud, and application teams to ensure secure identity management and certificate services across enterprise systems.
This position is located at DLA facilities near Richmond, VA and requires on-site support for classified DOD PKI environments.
Candidates must possess an active Secret Security Clearance and a High Risk, Critical Sensitive Tier 5 (SSBI) investigation prior to start.
This position will be onsite, and the hours are 8 am to 5 pm EST.
Responsibilities
Engineer, implement, administer, and maintain enterprise PKI environments supporting DLA mission systems
Design, configure, and maintain Certificate Authorities (CAs), Registration Authorities (RAs), Online Certificate Status Protocol (OCSP), Certificate Revocation Lists (CRLs), and related PKI components
Support enterprise deployment, migration, and lifecycle management of PKI applications and services
Configure, test, deploy, and troubleshoot Hardware Security Modules (HSMs) supporting certificate authorities and cryptographic operations
Support Enterprise Key Management activities utilizing two-person integrity controls
Support Key Ceremonies utilizing multi-person integrity procedures in accordance with Trusted Operating System requirements
Develop and maintain Server-Based Certificate Validation Protocol (SCVP) policies and certificate validation services
Install, configure, secure, and maintain Windows Server 2019 through current supported versions supporting PKI services
Develop, test, deploy, and maintain FDCC Windows 11 and FSCC Windows Server baselines
Perform operating system installations, upgrades, migrations, and system hardening
Test and deploy operating system patches, service packs, and application updates
Maintain enterprise test environments supporting PKI engineering and validation activities
Monitor system performance, conduct tuning activities, and implement engineering best practices
Configure, deploy, and manage enterprise certificates supporting users, applications, servers, and non-person entities (NPE)
Support Device Certificates for NIPRNet and SIPRNet Non-Key Terrain systems
Maintain Windows Trust Stores and Untrusted Certificate Stores
Support Public Key Enablement (PKE) for enterprise web applications and services
Support Federal Bridge interoperability and integration of PKI services into enterprise applications
Configure, administer, and maintain cloud-based Key Management Systems including:
Microsoft Azure Key Vault
AWS Key Management Service (KMS)
Future approved cloud cryptographic services
Integrate cloud-based certificate management with enterprise PKI services
Support secure hybrid cloud identity and certificate architecture
Review and analyze hardware, software, firmware, and operating system changes for security impacts
Evaluate security alerts, vulnerabilities, and vendor advisories affecting PKI infrastructure
Apply CERT-directed patches using Windows Server Update Services (WSUS)
Ensure compliance with:
DISA STIGs
DOD Cybersecurity requirements
FDCC
FSCC
Trusted Operating System standards
Participate in PKI compliance assessments and security audits
Research, evaluate, test, and recommend emerging PKI technologies
Conduct proof-of-concept testing for new cryptographic products and capabilities
Develop engineering documentation, implementation guides, standard operating procedures, and technical recommendations
Provide Tier III engineering support for enterprise PKI infrastructure
Troubleshoot complex PKI, certificate, middleware, and cryptographic issues
Support production, development, and test PKI environments
Collaborate with cybersecurity, cloud, infrastructure, and application teams to ensure secure integration of PKI services
Qualifications And Education Requirements
Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Engineering, or a related field
Minimum seven (7) years supporting enterprise PKI or cybersecurity engineering
Must possess a Secret Security Clearance including High Risk, Critical Sensitive, Tier 5 (SSBI) investigation
Must possess a current DOD Approved 8570/8140 Baseline Certification (CASP+, CISSP, CCNP Security (as applicable under DOD guidance), GCED, GCIH, or Other DOD-approved IAT Level III certifications
Must possess one of the following current certifications:
Microsoft Certified Solutions Expert (MCSE): Cloud Platform and Infrastructure
Microsoft Certified: Windows Server Hybrid Administrator Associate
Microsoft Certified: Azure Solutions Architect Expert (or equivalent Microsoft Azure certification meeting contract requirements)
Must live in a commutable distance of Richmond, Virginia or Ogden, Utah and be authorized to work in the United States
| Organization | Grant Leading Technology |
| Industry | IT / Telecom / Software Jobs |
| Occupational Category | Cyber Security Engineer |
| Job Location | Maryland,USA |
| Shift Type | Morning |
| Job Type | Full Time |
| Gender | No Preference |
| Career Level | Experienced Professional |
| Experience | 7 Years |
| Posted at | 2026-07-24 7:55 pm |
| Expires on | 2026-09-07 |