PKI Operations Engineer
PKI Operations Engineer
Ft. Meade, MD — Full Time (Hybrid)
August Schell is looking for a PKI Operations Engineer to sustain and operate DoD enterprise Public Key Infrastructure in support of our DISA customer. This is a Red Hat Certificate System (RHCS) solution. Where our PKI Software Engineer builds the next-generation certificate-systems code, this role keeps the infrastructure running: operating and hardening the live RHCS environment, standing up new customers and enclaves, driving CVE remediation and patch cycles, monitoring system health, and automating the operational toil that keeps a high-volume CA reliable. The engineer works hand-in-hand with commercial product engineering, government operations teams, and other program contractors — including through the environment's post-quantum cryptography (PQC) migration.
Individuals in this role must be able to work hybrid and go on site at Fort Meade as requested.
Responsibilities Include
Operate and sustain the production PKI environment on Red Hat Certificate System (RHCS) — CA availability, certificate lifecycle operations, and the day-to-day health of the issuance pipeline
Run RA/CRL/OCSP operations and certificate lifecycle management, including the transition to shorter-lived certificates at higher issuance volume (ACME automation)
Onboard new customers, enclaves, and use cases onto the PKI — configuration, integration, and secure hardening of new environments to program standards
Own CVE remediation and patch management for the PKI stack and its underlying RHEL hosts — track, test, schedule, and apply security patches with minimal disruption to CA operations
Monitor system health and performance; build and maintain alerting, logging, and dashboards; respond to and resolve operational incidents, and lead root-cause analysis
Operate and troubleshoot HSM integrations (Entrust nShield / Thales Luna) supporting CA operations and key escrow
Automate operational tasks — health checks, backups, certificate/CRL monitoring, deployment and configuration — using scripting and CI/CD tooling to reduce toil and manual error
Support the program's PQC migration from an operations standpoint (algorithm rollout, version transition, validation in the live environment)
Provide development support in an operational capacity as additional value — small fixes, config-as-code, tooling, and reproduction of issues for the product engineering team — without owning the core feature-development backlog
Communicate clearly across government operations stakeholders, commercial vendor engineering, and program contractors; document runbooks and escalate risks and blockers before they impact operations
Requirements
Active Secret clearance minimum (Top Secret preferred and may be required)
Local to the DMV area with the ability to work on site at Fort Meade as requested
Five (5)+ years of relevant systems/operations engineering experience (flexible for candidates with exceptional PKI depth)
Strong Linux (RHEL) systems administration and operations background, including patch management and system hardening
Knowledge or experience with Linux containers and container orchestration (Podman / Docker) and VMs (KVM)
Hands-on experience operating PKI, x.509, cryptography, and system/software security technologies
Direct experience operating Red Hat Certificate System (RHCS) — this is a Red Hat solution. Dogtag PKI experience (RHCS's upstream open-source project) is an accepted alternative skillset, as is comparable enterprise CA platform operations (EJBCA, Microsoft AD CS, Entrust Authority, ISC CertAgent, or similar)
Scripting/automation proficiency (Python, Bash, or similar) for operational tooling
DoD 8570/8140 IAT Level II certification (Security+ or equivalent)
Strong written and verbal communication skills, with a habit of documenting runbooks and operational procedures
Stand Out With
Prior DISA or DoD PKI program operations experience (Purebred, derived credentials, RA/CRL/OCSP operations at scale)
HSM operations experience (Entrust nShield, Thales Luna) — the customer runs Entrust HSMs
ACME protocol and certificate automation at scale
Post-quantum cryptography familiarity (ML-DSA/Dilithium, Kyber, CNSA 2.0 timelines) from a migration/operations lens
Configuration management and infrastructure-as-code (Ansible, or similar)
Directory Server / LDAP operations experience
Monitoring/observability tooling (Prometheus/Grafana, ELK, or similar) and incident response
Agile / ITSM operating rhythms (Scrum, JIRA, change management)
