Principal Cryptography & PKI Engineer

Robert Walters — United Kingdom · Posted ~3 hours ago

Lead Visa History ✓

Skills

Cryptography PKI Certificate Authority Key Management Enterprise Security CA Hierarchies Trust Models Certificate Policies High Availability Automation

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

Lead the cryptographic trust infrastructure for a large-scale enterprise as a Principal Cryptography & PKI Engineer. Take technical ownership of PKI, certificate authorities, and key management across the organization. Design CA hierarchies, trust models, and certificate policies. Build highly available PKI systems operating at enterprise scale. Automate certificate issuance, renewal, revocation, and rotation. Serve as senior technical authority for cryptography and PKI, collaborating with security leadership and engineering teams.

Highlights

Technical ownership of cryptography and PKI at enterprise scale, senior technical authority role, design CA hierarchies and trust models, automate certificate lifecycle management, work with security leadership

Description

Principal Cryptography & PKI Engineer Build the cryptographic trust infrastructure behind a large-scale enterprise. We're looking for a Principal Cryptography & PKI Engineer to take technical ownership of cryptography, PKI and enterprise key management across our organisation. We're looking for someone who understands why the architecture works, where it can fail, how to operate it at scale, and how to automate it. You'll become a senior technical authority for cryptography and PKI, working directly with security leadership and engineering teams to build the infrastructure that establishes trust across applications, systems, workloads, devices and people. What you'll be doing You'll own the technical direction of our PKI and cryptographic capabilities, including: Designing CA hierarchies, trust models and certificate policies.Building highly available PKI capable of operating at enterprise scale.Automating certificate issuance, renewal, revocation and rotation.Designing and operating HSM and enterprise key-management architectures.Integrating PKI with cloud infrastructure, Kubernetes, CI/CD, applications and identity platforms.Defining enterprise standards for cryptographic algorithms, protocols and key management.Helping engineering teams implement TLS, mTLS, code signing and workload identity securely.Designing processes for key compromise, emergency rotation and recovery.Building the monitoring and operational controls required to run PKI as critical infrastructure.Developing our approach to cryptographic agility and post-quantum readiness.Acting as a technical authority for difficult cryptographic and PKI problems.The person we're looking for You understand things such as: Why does this certificate chain work on one platform but fail on another? What happens if an intermediate CA is compromised? How do you rotate millions of certificates without causing an outage? Where should a high-value private key actually live? How do you design a CA hierarchy that remains operationally manageable five years from now? How do you make cryptographic algorithm changes without having to redesign the entire enterprise? You'll bring: Deep practical knowledge of applied cryptography.Significant experience designing or operating PKI at scale.Strong understanding of X.509, TLS/mTLS, certificate chains and trust models.Experience with enterprise CA and certificate-management technologies.Hands-on experience with HSMs and/or enterprise key-management systems.Strong knowledge of key lifecycle management.Experience automating certificate and key-management processes.Experience working with cloud, Kubernetes, infrastructure or DevOps environments.The ability to troubleshoot complex PKI failures rather than simply escalate them.The ability to explain cryptographic concepts clearly to engineers, architects and senior security leaders.You'll stand out if you have experience with AD CS, OpenSSL or modern PKI platforms.HashiCorp Vault, Venafi or similar technologies.Cloud KMS and certificate-management services.ACME, SPIFFE/SPIRE or service-mesh identity.Code-signing infrastructure.Device or IoT identity.Secrets-management platforms.Software supply-chain security.HSM architecture and key ceremonies.Cryptographic agility.Post-quantum cryptography and migration planning.Designing security infrastructure that operates across multiple cloud and on-premise environments. Desired Skills and Experience You'll bring: * Deep practical knowledge of applied cryptography. * Significant experience designing or operating PKI at scale. * Strong understanding of X.509, TLS/mTLS, certificate chains and trust models. * Experience with enterprise CA and certificate-management technologies. * Hands-on experience with HSMs and/or enterprise key-management systems. * Strong knowledge of key lifecycle management. * Experience automating certificate and key-management processes. * Experience working with cloud, Kubernetes, infrastructure or DevOps environments. * The ability to troubleshoot complex PKI failures rather than simply escalate them. * The ability to explain cryptographic concepts clearly to engineers, architects and senior security leaders. You'll stand out if you have experience with * AD CS, OpenSSL or modern PKI platforms. * HashiCorp Vault, Venafi or similar technologies. * Cloud KMS and certificate-management services. * ACME, SPIFFE/SPIRE or service-mesh identity. * Code-signing infrastructure. * Device or IoT identity. * Secrets-management platforms. * Software supply-chain security. * HSM architecture and key ceremonies. * Cryptographic agility. * Post-quantum cryptography and migration planning. *Designing security infrastructure that operates across multiple cloud and on-premise environments. Robert Walters Operations Limited is an employment business and employment agency and welcomes applications from all candidates