ICA Engineer (.Net Fullstack Developer w. PKI)

Innova SolutionsChicago, IL
Onsite

About The Position

This is a contract role for an ICA Security Engineer with a duration of 12 to 18 months. The position requires the candidate to be onsite 5 days a week in Denver, Chicago, or Washington DC. The role involves designing, implementing, and operating enterprise-grade Public Key Infrastructure (PKI) services, with a strong emphasis on Microsoft Active Directory Certificate Services (AD CS) and Active Directory (AD) integration. The engineer will be responsible for hands-on implementation and integration of certificate lifecycle management, CA hierarchy governance, enrollment automation, HSM-backed key protection, CA backup/restore, migration, and integration with various platforms. The role also requires being a subject matter expert for cryptographic standards, certificate-based authentication, and PKI security controls across the organization.

Requirements

  • 8+ years in Security Engineering/Identity Infrastructure
  • 5+ years hands-on with Microsoft AD CS and enterprise Active Directory with managing CA infra
  • Proven experience designing, deploying, and operating multi-tier Microsoft PKI (offline root, issuing CAs) in large/complex environments.
  • Deep knowledge of X.509, CRL/OCSP, EKU/KU, SANs, key algorithms and sizes (RSA/ECC), hashing (SHA-2), and certificate validation paths.
  • Strong PowerShell and Windows Server administration; GPOs, autoenrollment, templates, AIA/CDP configuration.
  • Experience with 802.1X/EAP-TLS, TLS/mTLS, VPN auth, and device/user certificate issuance at scale.
  • HSM experience (e.g., nCipher/Entrust/Thales) for CA key management.
  • Must be able to be engaged on a W-2 basis.

Nice To Haves

  • 2+ years of experience on PowerShell
  • Integration with Azure AD/Entra ID
  • Experience with PQC (Post-Quantum Cryptography)
  • Experience with Intune, SCEP/NDES, ACME, or MDM connectors.

Responsibilities

  • Design and maintain enterprise PKI architectures (Root CA, Policy CA, Issuing CA) with offline/air gapped roots, secure key ceremonies, key usage, and issuance workflows and robust CRL/OCSP distribution.
  • Integrate PKI with Active Directory (incl. AD forests/domains, AD CS, AIA/CDP locations, GPOs), and Azure AD/Entra ID where applicable (e.g., certificate-based auth).
  • Engineer solutions for mutual TLS, 802.1X (wired/wireless/VPN), device identity, code signing, S/MIME, BitLocker, and disk/volume encryption certs.
  • Implement HSM-backed key storage for CAs and code signing; lead key ceremonies, disaster recovery designs.
  • Own certificate lifecycle management (issuance, renewal, revocation) including automation via Intune, GPO/Autoenrollment, SCEP/NDES, ACME, or MDM connectors.
  • Manage CRL/OCSP publication, monitoring, and availability, design highly available, geo-distributed revocation endpoints.
  • Implement scripting/automation (PowerShell, APIs) for bulk issuance, inventory, renewal, and drift detection.
  • Enable separation of duties for secure operation of PKI infrastructure.
  • Manage CA backup, restore, renewal, and migration strategy.
  • Apply strong key management practices (FIPS 140-2/140-3), certificate assurance levels, and secure CA hardening baselines.
  • Regularly perform PKI risk assessments, access reviews, and control testing (e.g., template permissions, EKU misuse, issuance constraints).
  • Lead root cause analysis and incident response for certificate/PKI-related outages or security events.
  • Maintain alignment with NIST, CAB Forum, Microsoft Security Baselines, and internal compliance frameworks (e.g., SOX, PCI, HIPAA, ISO 27001) as applicable.

Benefits

  • Medical & pharmacy coverage
  • Dental/vision insurance
  • 401(k)
  • Health saving account (HSA)
  • Flexible spending account (FSA)
  • Life Insurance
  • Pet Insurance
  • Short term and Long term Disability
  • Accident & Critical illness coverage
  • Pre-paid legal & ID theft protection
  • Sick time
  • Other types of paid leaves (as required by law)
  • Employee Assistance Program (EAP)
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service