Job ID: 2502151
Location: SPRINGFIELD, VA, US
Date Posted: 2025-02-18
Category: Cyber
Subcategory: Cyber Engineer
Schedule: Full-time
Shift: Day Job
Travel: No
Minimum Clearance Required: None
Clearance Level Must Be Able to Obtain: Top Secret
Potential for Remote Work: No
Description
The Vanguard 2.2.1 contract provides enterprise IT services to the Department of State (DOS) Diplomatic Technology Bureau. The contract currently has an opening for a Public Key Infrastructure (PKI) system engineer. As a PKI Engineer, you will be joining the team to participate and lead in managing, securing, engineering, and governing DOS’s key and certificate management services, including supporting robust, enterprise-grade Public Key Infrastructure (PKI), certificate lifecycle management (CLCM), infrastructure automation and credential management (CMS) systems. Your expertise in developing, implementing, and maintaining PKI solutions will be key to ensuring the integrity and reliability of DOS’s digital communications. You will be a member of a team tasked with providing cryptography expertise, including encryption (at-rest and in-transit) and key management services, as well as design, build and operate PKI related systems on-prem and in Cloud.
This role may allow some remote work, but is primarily onsite in Springfield, VA. Subject to change based on the customer’s request.
REQUIRED EDUCATION & EXPERIENCE:
- Bachelor’s degree in information technology, engineering, computer science, or related field and 5 years or Master’s and 3 years. May accept additional experience in lieu of degree.
- Experience in PKI, IT security, or related roles, with a strong focus on one or all of these certification authorities (EJBCA , Microsoft CA, Entrust). May accept less with very strong cloud experience.
- Deep understanding of cryptographic protocols and algorithms.
- Proficiency with either EJBCA, Entrust, or Microsoft Certificate Authority.
- Familiarity with industry standards such as X.509, PKCS, and others.
- Virtualization technologies – VMWare ESXI, vCenter, VMWare NSX.
- Working knowledge of external storage solutions, storage area networks (SANs), and Fiber Channel networks.
- Ability to troubleshoot and resolve network/application/operating system issues.
- Excellent MS-Windows Server administration & maintenance skills.
PREFERRED SKILLS:
- Proficiency in enabling self-service workflow, orchestration, and compliance control.
- Scripting Skills (PowerShell, Bash &/or Python): Proficiency in scripting with Bash and/or Python. Capable of writing and maintaining scripts for automating routine PKI tasks, enhancing operational efficiency, and reducing manual errors.
- Experience with one or more Credential Management Systems (CMS) with experience integrating with all facets of certificate lifecycle.
- Monitoring Expertise: Experience with monitoring tools and technologies. Skilled in setting up and managing systems to monitor the health and performance of the PKI infrastructure, ensuring high availability and proactive issue resolution.
- Automation Abilities: Demonstrated experience in automating IT processes. Ability to implement automation solutions that streamline PKI operations and improve system reliability and security.
- Splunk Proficiency: Knowledge of Splunk for log management and analysis. Capable of leveraging Splunk to gain insights into PKI system operations and security, enhancing situational awareness and decision-making.
- Ability to configure and optimize PKI enrollment and operation protocols such as (SCEP, EST, TLS, etc..), ensuring the latest security standards are met and maintained in our PKI infrastructure.
- Experience supporting/securing cloud-based services and implementing AWS and Azure cryptography, encryption and key management best practices and policies.
- Must be able to effectively perform both independently and collaboratively as a strong team contributor.
- Strong analytical and problem-solving skills.
- Excellent communication and collaboration abilities with attention to detail.
SAIC accepts applications on an ongoing basis and there is no deadline.
Covid Policy: SAIC does not require COVID-19 vaccinations or boosters. Customer site vaccination requirements must be followed when work is performed at a customer site