About the Role
We are looking for an experienced PKI Architect / Engineer to transform an existing EJBCA-based Proof of Concept into a secure, production-ready Public Key Infrastructure for device identities.
The PKI will support the issuance and lifecycle management of Manufacturer Device Certificates (IDevID) according to IEEE 802.1AR, including certificate enrollment, issuance, renewal, revocation and status validation. The existing Proof of Concept already demonstrates the complete certificate lifecycle via CMP; your responsibility will be to take this foundation to production — with robust security, governance, resilience, operational processes and a clean handover to the operations team.
This is a hands-on architecture and engineering role. You will own the PKI design and implementation from the target architecture and key ceremony through hardening, integration, backup/recovery testing, operational documentation and transition into production operations.
Key Responsibilities
PKI Architecture & Design
...- Design and implement the target PKI architecture and CA hierarchy, including:
- Offline Root CA
- Issuing / Subordinate CAs
- Appropriate trust boundaries and security zones
- Certificate profiles and extensions
- CRL and OCSP architecture
- Root and subordinate CA lifecycle management
- Define the strategy and technical approach for Root CA rollover and trust-anchor transition.
- Translate the existing EJBCA Proof of Concept into a scalable, maintainable production architecture.
- Define security, availability and operational requirements for the PKI platform.
- Assess and design high availability, including database-level HA where required.
EJBCA Implementation & Certificate Lifecycle
- Install, configure, harden and operate EJBCA in a production environment.
- Configure CA hierarchies, certificate profiles, end entity profiles, publishers and validation services.
- Implement certificate lifecycle processes including:
- Registration
- Enrollment
- Issuance
- Renewal
- Revocation
- CRL generation and distribution
- OCSP validation
- Design and implement CMP-based certificate enrollment, with particular consideration for RFC 4210 and, where applicable, the Lightweight CMP Profile according to RFC 9483.
- Ensure certificates and extensions comply with X.509 / RFC 5280 requirements.
- Support device identity use cases based on IEEE 802.1AR, with potential integration into BRSKI, 802.1X and NAC environments.
Key Management & Key Ceremony
- Define and implement secure key-management procedures for Root and Issuing CAs.
- Design the required use of:
- HSMs / secure key storage
- Offline systems
- Cryptographic separation
- Administrative controls
- Dual control / split knowledge
- Prepare, coordinate and lead the CA key ceremony, including:
- Ceremony procedures
- Roles and responsibilities
- Security controls
- Evidence and documentation
- Key generation and backup
- CA initialization and trust-anchor creation
- Ensure that all critical cryptographic operations are performed according to documented and auditable procedures.
Identity, Access Management & Enterprise Integration
- Integrate the PKI with Microsoft Active Directory and Microsoft Entra ID.
- Implement appropriate authentication and authorization mechanisms, including OIDC where applicable.
- Design strong administrative authentication and privileged-access controls.
- Establish clear role separation and least-privilege access, including separation of CA administration, security administration, operations and auditing.
- Define and implement procedures for privileged access, account lifecycle and emergency access.
Security Architecture & Hardening
- Harden the PKI infrastructure, including EJBCA, operating systems, databases and supporting services.
- Design and implement appropriate network segmentation and security zones.
- Secure internal communication using appropriate encryption and certificate-based trust.
- Establish secure administration paths and restrict management interfaces.
- Implement comprehensive audit logging, monitoring and security-relevant event handling.
- Apply secure configuration baselines and document deviations and compensating controls.
- Support security assessments, penetration tests and remediation activities where required.
Backup, Recovery & Business Continuity
- Design and implement a complete backup, restore and disaster-recovery strategy for the PKI.
- Define backup requirements for:
- CA configuration
- EJBCA configuration and data
- Database
- Cryptographic material / key backups
- Supporting infrastructure
- Critical documentation
- Develop documented Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO).
- Define recovery procedures for individual components as well as complete PKI loss scenarios.
- Execute and document real recovery and restore tests, not merely theoretical procedures.
- Verify that a recovered PKI can successfully issue and validate certificates and resume normal operations.
- Maintain tested fallback and emergency procedures.
Operations, Maintenance & Lifecycle Management
- Develop the complete PKI operating model, including:
- Daily / weekly / monthly operational procedures
- Certificate and CA monitoring
- CRL and OCSP monitoring
- Backup verification
- Log review
- Capacity management
- Security monitoring
- Incident handling
- Define patch and upgrade strategies for EJBCA, operating systems, databases and supporting components.
- Establish rollback / fallback procedures for upgrades and configuration changes.
- Define maintenance windows and change-management procedures.
- Establish procedures for certificate profile changes, CA configuration changes and cryptographic lifecycle events.
- Prepare the environment for long-term operational ownership by the internal operations team.
Documentation, Knowledge Transfer & Handover
- Produce documentation that can be used independently by third parties and operations teams.
- Develop and maintain:
- PKI architecture documentation
- Network and security architecture
- CA hierarchy documentation
- Certificate profiles
- CP/CPS
- Key Ceremony documentation
- Operating procedures
- Backup and recovery procedures
- Disaster-recovery procedures
- Patch and upgrade procedures
- Incident and emergency procedures
- Troubleshooting guides
- Conduct technical workshops and operational training.
- Transfer knowledge and responsibility to the operations team.
- Support the transition from project implementation into stable production operations.
Mandatory Qualifications
Proven Production PKI Experience
- Demonstrable experience building at least one production PKI from the ground up, with personal responsibility across the complete lifecycle:
- Architecture
- Implementation
- CA key generation / key ceremony
- Certificate profiles
- Security hardening
- Integration
- Backup and recovery
- Production deployment
- Operational handover
- Experience operating a PKI in a security-critical enterprise environment.
PKI & Cryptography
- Deep understanding of X.509 and RFC 5280.
- Strong understanding of CA hierarchies, trust models, certificate policies, extensions, revocation and validation.
- Practical experience with CRL and OCSP.
- Strong understanding of cryptographic key management and CA key protection.
- Experience with HSMs and offline CA architectures.
EJBCA
- Strong practical experience with EJBCA installation, configuration and production operation.
- Experience configuring CAs, certificate profiles, end entity profiles, publishers and validation services.
- Ability to troubleshoot EJBCA and its underlying infrastructure independently.
Governance & Documentation
- Experience creating and maintaining Certificate Policy (CP) and Certification Practice Statement (CPS) documentation.
- Proven ability to create operational and technical documentation to a professional, audit-ready standard.
- Experience defining backup, recovery and business-continuity concepts and performing documented restore tests.
Infrastructure & Integration
- Practical experience integrating PKI with Microsoft Active Directory and Microsoft Entra ID.
- Experience with identity and authentication technologies, including OIDC.
- Strong Linux administration skills.
- Practical experience with container technologies.
- Sound understanding of relational databases and database administration concepts.
- Experience with network segmentation and secure infrastructure design.
- Experience implementing system hardening and secure communications.
Nice to Have
- Practical experience with CMP / RFC 4210.
- Knowledge of the Lightweight CMP Profile / RFC 9483.
- Experience with IEEE 802.1AR and Manufacturer Device Certificates / IDevID.
- Knowledge of BRSKI and related device onboarding concepts.
- Experience with 802.1X, NAC and certificate-based network access control.
- Experience managing certificates in OT, industrial or manufacturing environments.
- Knowledge of IEC 62443, NIS2 or comparable cybersecurity and regulatory requirements.
- Experience supporting external or internal audits.
- Experience with Ansible or comparable infrastructure automation technologies.
- Experience designing or operating high-availability database architectures.
- Experience with PKI monitoring, SIEM integration and security-event analysis.
- Experience with infrastructure-as-code and automated configuration management.
Technical Environment
The role is expected to work across a broad technology stack, including:
PKI / Cryptography
- EJBCA
- X.509 / RFC 5280
- CMP / RFC 4210 / RFC 9483
- CRL / OCSP
- HSM
- Offline Root CA
- IEEE 802.1AR
Identity & Access
- Microsoft Active Directory
- Microsoft Entra ID
- OIDC
- Strong authentication / MFA
- RBAC / least privilege
Infrastructure
- Linux
- Containers
- Relational databases
- High-availability architectures
- Network segmentation
- TLS / encrypted internal communication
Automation & Operations
- Ansible or equivalent
- Monitoring and logging
- Backup / restore
- Disaster recovery
- Patch and upgrade management
- Change and incident management
What Success Looks Like
You will be successful when the existing EJBCA Proof of Concept has been transformed into a secure, resilient and operationally sustainable production PKI.
Specifically:
- A formally defined and documented CA hierarchy is in place.
- The Root CA is securely operated offline.
- CA keys are protected using appropriate cryptographic controls.
- The production EJBCA environment is hardened and securely segmented.
- Certificate profiles and lifecycle processes are formally defined.
- AD / Entra ID integration and strong administrative authentication are operational.
- CP/CPS and operational procedures are complete and usable.
- Backup and recovery procedures have been executed and successfully tested.
- Root rollover and CA lifecycle procedures are defined.
- Patch, upgrade and rollback procedures are established.
- Audit logging and operational monitoring are implemented.
- The key ceremony has been successfully executed and fully documented.
- The operations team has been trained and is capable of independently operating the PKI.
- The complete solution has passed the transition from project delivery into stable production operation.
Profile
We are looking for a person who combines PKI architecture expertise with hands-on engineering capability.
You should be comfortable moving between cryptographic concepts, CA architecture, EJBCA configuration, Linux administration, network security, identity integration and operational processes. You understand that a production PKI is not simply a CA installation: it is a security-critical system with defined trust boundaries, controlled cryptographic operations, documented processes, tested recovery procedures and accountable operations.
You work independently, document your decisions clearly and are able to challenge existing designs where necessary. You can lead a key ceremony as confidently as you can troubleshoot an EJBCA deployment or design a recovery test.
Most importantly, you have personally taken a PKI from design through implementation and key ceremony into production and operational handover.
Engagement Focus
Primary objective:
Transform the existing EJBCA-based device identity Proof of Concept into a production-grade PKI for IEEE 802.1AR device certificates, including architecture, security, implementation, operational readiness and handover.
Expected seniority: Senior PKI Engineer / PKI Architect
Core expertise: EJBCA · X.509 · RFC 5280 · CA Architecture · HSM · Offline Root CA · CMP · IEEE 802.1AR · AD · Entra ID · Linux · Containers · Database · Hardening · Backup & Recovery · CP/CPS · PKI Operations