Intermediate Cyber Security Engineer - PKI
Onsite - Ogden, UT
Grant Leading Technology is seeking a candidate for an Intermediate Cyber Security Engineer Public Key Infrastructure (PKI) to join our dynamic team. The candidate will provide advanced engineering, administration, and operational support for a large-scale Department of Defense (DOD) PKI environment supporting the Defense Logistics Agency (DLA). This position is responsible for engineering secure PKI solutions, maintaining trusted operating system baselines, implementing cryptographic technologies, and supporting enterprise certificate lifecycle management across on-premises and cloud environments.
The engineer will support the design, implementation, testing, deployment, and maintenance of PKI infrastructure while ensuring compliance with DOD cybersecurity requirements. The position requires collaboration with cybersecurity, infrastructure, cloud, and application teams to ensure secure identity management and certificate services across enterprise systems.
This position is located at DLA facilities in Ogden, Utah and requires on-site support for classified DOD PKI environments.
Candidates must possess an active Secret Security Clearance and a High Risk, Critical Sensitive Tier 5 (SSBI) investigation prior to start.
This position will be onsite, and the hours are 8 am to 5 pm EST.
Responsibilities:
Engineer, implement, administer, and maintain enterprise PKI environments supporting DLA mission systems
Design, configure, and maintain Certificate Authorities (CAs), Registration Authorities (RAs), Online Certificate Status Protocol (OCSP), Certificate Revocation Lists (CRLs), and related PKI components
Support enterprise deployment, migration, and lifecycle management of PKI applications and services
Configure, test, deploy, and troubleshoot Hardware Security Modules (HSMs) supporting certificate authorities and cryptographic operations
Support Enterprise Key Management activities utilizing two-person integrity controls
Support Key Ceremonies utilizing multi-person integrity procedures in accordance with Trusted Operating System requirements
Develop and maintain Server-Based Certificate Validation Protocol (SCVP) policies and certificate validation services
Install, configure, secure, and maintain Windows Server 2019 through current supported versions supporting PKI services
Develop, test, deploy, and maintain FDCC Windows 11 and FSCC Windows Server baselines
Perform operating system installations, upgrades, migrations, and system hardening
Test and deploy operating system patches, service packs, and application updates
Maintain enterprise test environments supporting PKI engineering and validation activities
Monitor system performance, conduct tuning activities, and implement engineering best practices
Configure, deploy, and manage enterprise certificates supporting users, applications, servers, and non-person entities (NPE)
Support Device Certificates for NIPRNet and SIPRNet Non-Key Terrain systems
Maintain Windows Trust Stores and Untrusted Certificate Stores
Support Public Key Enablement (PKE) for enterprise web applications and services
Support Federal Bridge interoperability and integration of PKI services into enterprise applications
Configure, administer, and maintain cloud-based Key Management Systems including:
o Microsoft Azure Key Vault
o AWS Key Management Service (KMS)
o Future approved cloud cryptographic services
Integrate cloud-based certificate management with enterprise PKI services
Support secure hybrid cloud identity and certificate architecture
Review and analyze hardware, software, firmware, and operating system changes for security impacts
Evaluate security alerts, vulnerabilities, and vendor advisories affecting PKI infrastructure
Apply CERT-directed patches using Windows Server Update Services (WSUS)
Ensure compliance with:
o DISA STIGs
o DOD Cybersecurity requirements
o FDCC
o FSCC
o Trusted Operating System standards
Participate in PKI compliance assessments and security audits
Research, evaluate, test, and recommend emerging PKI technologies
Conduct proof-of-concept testing for new cryptographic products and capabilities
Develop engineering documentation, implementation guides, standard operating procedures, and technical recommendations
Provide Tier III engineering support for enterprise PKI infrastructure
Troubleshoot complex PKI, certificate, middleware, and cryptographic issues
Support production, development, and test PKI environments
Collaborate with cybersecurity, cloud, infrastructure, and application teams to ensure secure integration of PKI services
Qualifications and Education Requirements:
Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Engineering, or a related field
Minimum seven (7) years supporting enterprise PKI or cybersecurity engineering
Must possess a Secret Security Clearance including High Risk, Critical Sensitive, Tier 5 (SSBI) investigation
Must possess a current DOD Approved 8570/8140 Baseline Certification (CASP+, CISSP, CCNP Security (as applicable under DOD guidance), GCED, GCIH, or Other DOD-approved IAT Level III certifications
Must possess one of the following current certifications:
Microsoft Certified Solutions Expert (MCSE): Cloud Platform and Infrastructure
Microsoft Certified: Windows Server Hybrid Administrator Associate
Microsoft Certified: Azure Solutions Architect Expert (or equivalent Microsoft Azure certification meeting contract requirements)
Must live in a commutable distance of Richmond, Virginia or Ogden, Utah and be authorized to work in the United States
Preferred Skills:
Experience supporting DLA environments
Experience supporting Federal Bridge Certification Authority (FBCA) integration
Experience supporting SIPRNet and NIPRNet PKI implementations
Experience administering Hardware Security Modules (Entrust, Thales, Luna, or equivalent)
Experience with PowerShell automation and scripting
Familiarity with Zero Trust Architecture and modern identity management solutions
About Grant Leading Technology:
Grant Leading Technology (GLT) is a verified Service-Disabled Veteran Owned Small Business (SDVOSB) government contracting firm. GLT provides expert knowledge and skills to deliver agile enterprise solutions and innovative technologies to our clients at the Federal Aviation Administration (FAA), Internal Revenue Service (IRS), Federal Emergency Management Agency (FEMA), National Aeronautics and Space Administration (NASA), and other federal and state agencies. We possess exceptional capabilities including, but not limited to, project management, cyber security, construction management, design, and management technology. GLT has been recognized for three consecutive years by Inc. 5000 as one of the fastest-growing private companies in America.
Our employees are at the heart of GLTs success. We value and fully embrace the diversity of individuals and ideas within our workforce. GLT provides a competitive compensation package with benefits that are immediately available. Our base healthcare plan is 100% employer paid and our 401k plan is immediately vested. We also offer paid time off, 11 federal holidays, short/long-term disability, 401k matching, and opportunities for professional development.
www.grantleadingtechnology.com
*Grant Leading Technology is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. Reasonable accommodations will be provided to those who are unable to utilize our online application system due to a disability. Please email recruiting@grantleadingtechnology.com with the subject line Accommodation
