PKI Engineer

Saxon GlobalDenver, CO

About The Position

The role requires deep knowledge (300-400 level) in the following technology areas: PKI and Active Directory Active Directory Certificate Services: Strong understanding of cryptographic algorithms and protocols Experience working with certificate authorities and registration authorities such as NDES and CEP/CES Proficiency in key management and renewal Experience designing, implementing, and maintaining secure PKI solutions in large scale enterprise environments (two and three tier PKI hierarchies (>1 issuer) Knowledge of integrating PKI with other security technologies such as HSMs, TLS inspection, 802.1x, etc... Experience conducting PKI audits and monitoring Ability to troubleshoot and resolve issues related to certificate issuance and management Knowledge of best practices for securing device and user certificates Experience configuring Intune to work with a certificate authority to issue device and user certificates Expertise in certificate lifecycle management Expertise with autoenroll and manual certificate issuance Knowledge of certificate templates and their configuration Experience with scripted installations Expertise with database cleanup options & PKI domain maintenance Cross-forest implementations (Desired) Active Directory Domain Services: Active Directory replication Active Directory troubleshooting Group Policy implementation, design, and troubleshooting Fundamental networking knowledge – IP, DHCP, DNS, WINS, routing etc. The following areas may also be beneficial: Active Directory Scripting Active Directory Disaster Recovery Active Directory Monitoring Tools Azure AD Connect Azure Active Directory

Requirements

  • Deep knowledge (300-400 level) in PKI and Active Directory
  • Strong understanding of cryptographic algorithms and protocols
  • Experience working with certificate authorities and registration authorities such as NDES and CEP/CES
  • Proficiency in key management and renewal
  • Knowledge of best practices for securing device and user certificates
  • Expertise in certificate lifecycle management
  • Expertise with autoenroll and manual certificate issuance
  • Knowledge of certificate templates and their configuration
  • Experience with scripted installations
  • Expertise with database cleanup options & PKI domain maintenance
  • Active Directory replication
  • Active Directory troubleshooting
  • Group Policy implementation, design, and troubleshooting
  • Fundamental networking knowledge – IP, DHCP, DNS, WINS, routing etc.

Nice To Haves

  • Cross-forest implementations
  • Active Directory Scripting
  • Active Directory Disaster Recovery
  • Active Directory Monitoring Tools
  • Azure AD Connect
  • Azure Active Directory

Responsibilities

  • Designing, implementing, and maintaining secure PKI solutions in large scale enterprise environments (two and three tier PKI hierarchies (>1 issuer)
  • Integrating PKI with other security technologies such as HSMs, TLS inspection, 802.1x, etc...
  • Conducting PKI audits and monitoring
  • Troubleshooting and resolving issues related to certificate issuance and management
  • Configuring Intune to work with a certificate authority to issue device and user certificates
  • Managing certificate lifecycle
  • Performing autoenroll and manual certificate issuance
  • Configuring certificate templates
  • Performing scripted installations
  • Managing database cleanup options & PKI domain maintenance
  • Implementing cross-forest implementations (Desired)
  • Managing Active Directory replication
  • Troubleshooting Active Directory
  • Implementing, designing, and troubleshooting Group Policy
  • Utilizing fundamental networking knowledge – IP, DHCP, DNS, WINS, routing etc.
  • Active Directory Scripting (Beneficial)
  • Active Directory Disaster Recovery (Beneficial)
  • Active Directory Monitoring Tools (Beneficial)
  • Azure AD Connect (Beneficial)
  • Azure Active Directory (Beneficial)
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service