Chevron Corp logo

Cloud Engineer

Chevron Corp

  • Houston, TX
  • 8 days ago

    Highlights

    The role enables secure certificate lifecycle management, key protection, and identity-driven security controls, supporting Zero Trust adoption, phishing-resistant authentication, and protection of critical business workloads. This is a senior hands-on engineering role within Chevron's Digital Identity organization responsible for designing, operating, and modernizing enterprise-scale Public Key Infrastructure (PKI) and cryptographic services across cloud and hybrid environments.

    Numbers & Facts

    LocationHouston, TX
    IndustryEnergy and Utilities
    Company Size10,000 employees or more
    Year Founded1876
    Websitehttps://www.chevron.com/

    Description

    Chevron is accepting online applications for the Cloud Engineer position through August 26, 2026, at 11:59 p.m. (Central Time).

    Overview

    This is a senior hands-on engineering role within Chevron's Digital Identity organization responsible for designing, operating, and modernizing enterprise-scale Public Key Infrastructure (PKI) and cryptographic services across cloud and hybrid environments. The role enables secure certificate lifecycle management, key protection, and identity-driven security controls, supporting Zero Trust adoption, phishing-resistant authentication, and protection of critical business workloads.

    Responsibilities for this position may include but are not limited to:

    • PKI & Certificate Services

    • Design, deploy, and manage enterprise PKI platforms (Microsoft ADCS, DigiCert, NDES, cloud-integrated services)

    • Own certificate lifecycle management (issuance, renewal, revocation, compliance, automation)

    • Implement post-quantum cryptography capabilities aligned to business and regulatory requirements

    • Manage HSM-backed key protection and integration with key management systems

    • Cloud & Hybrid Identity Integration

    • Integrate PKI with Active Directory and Microsoft Entra ID for hybrid identity scenarios

    • Enable certificate-based authentication for workloads, APIs, devices, VPN, and service accounts

    • Align PKI services with Azure and multi-cloud security architectures

    • Security Engineering & Zero Trust

    • Implement phishing-resistant authentication using FIDO2, PIV, and certificate-based methods

    • Support Conditional Access policies leveraging identity, device posture, and risk signals

    • Advance Zero Trust maturity and continuous security posture improvement

    • Privileged Access & Operational Security

    • Integrate PKI with PAM solutions (e.g., Delinea) for secure service account authentication

    • Support privileged access workstations and hardened admin environments

    • Lead break-glass and recovery scenarios using secure access controls

    • Automation, Reliability & Operations

    • Drive automation using scripting, APIs, and orchestration to reduce manual processes

    • Lead disaster recovery exercises, upgrades, and PKI platform modernization

    • Provide advanced engineering support, incident response, and root cause analysis

    • Leadership & Stakeholder Engagement

    • Serve as a PKI subject matter expert within Digital Identity - Protection

    • Collaborate across security, cloud, and operations teams

    • Mentor engineers and contribute to standards and operational excellence

    Required Qualifications:

    • Bachelor's degree in computer science, Information Security, Engineering, or related field (or equivalent experience)

    • 12-15 years in Identity & Access Management, PKI, or security infrastructure engineering

    • Proven experience operating large-scale enterprise PKI environments

    • Strong understanding of cryptography, authentication, and trust models

    • Hands-on expertise with PKI platforms, HSM, key management, automation, Active Directory, and Microsoft Entra ID

    Preferred Qualifications:

    • Industry certifications in security or cloud (e.g., CISSP, Azure Security)

    • Experience in regulated industries such as oil & gas or energy

    • Knowledge of Zero Trust architecture, Conditional Access, and identity security engineering

    • Familiarity with ITIL and operational processes in regulated environments

    Relocation Options

    Relocation will be considered.

    International Considerations

    Expatriate assignments will not be considered.

    Chevron regrets that it is unable to sponsor employment Visas or consider individuals on time-limited Visa status for this position.

    About Company

    Chevron Corp (Chevron) is an integrated oil and gas company. It operates in the oil and gas value chain including exploration and production, storage and pipeline transportation to refining, marketing and distribution of oil and gas products. It explores for, produces and transports crude oil and natural gas; refines, markets and distributes transportation fuels and lubricants; and sells petrochemicals and additives. Chevron has interests in gas to liquid facilities in its operating regions. The company has an operational presence in North America, South America, Europe, Asia, the Middle East and Africa. Chevron is headquartered in San Ramon, California, the US.

    Similar Jobs

    See more jobs