Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
BLUE ORIGIN

Senior PKI, Certificate Management Engineer

BLUE ORIGIN

. Design, implement, administer, and maintain PKI and certificate-management infrastructure for TeraWave devices and infrastructure .

Posted 9/24/2026full-timeUnited StatesSenior💰 $230,398 - $322,557 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in designing, implementing, and managing Public Key Infrastructure (PKI) and cryptographic systems, with a strong focus on Hardware Security Modules (HSMs) and key management processes. Proficient in automation and integration of security solutions across diverse technical teams and environments.

Highest-signal resume keywords
Public Key Infrastructure (PKI)Cryptographic Key ManagementHardware Security Modules (HSMs)X.509 CertificatesAutomation Using Python

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
PKI Design and ImplementationCryptographic AlgorithmsKey Generation and DistributionCertificate Lifecycle ManagementHSM AdministrationTroubleshooting Security InfrastructureSecure Key CeremoniesChain-of-Custody ControlsDocumentation and Change LogsFirmware and Software Patching
Soft Skills
Collaborative WorkStrong Documentation SkillsOperational Skills
Tools & Technologies
PKCS#11 APIsCommercial PKI PlatformsCertificate Management ToolsHSM Integrations
Industry Keywords
Cryptographic InfrastructureSecurity InfrastructureDigital SignaturesSecure CommunicationsTrust Chains

Tech Stack

Tools & technologies
Cyber SecurityPython

About the role

Key responsibilities & impact
  • Design, implement, administer, and maintain PKI and certificate-management infrastructure for TeraWave devices and infrastructure
  • Automate and oversee digital certificate issuance, renewal, revocation, rotation, and replacement
  • Configure hardware security interfaces, token management, and cryptographic service integrations for applications and HSMs
  • Install, configure, administer, and maintain enterprise-class HSM appliances
  • Monitor HSM health, performance, and availability; troubleshoot hardware, firmware, software, and client-side issues
  • Perform HSM firmware updates, software patches, client software upgrades, and configuration changes
  • Maintain HSM configuration documentation, baseline records, audit information, and change logs
  • Manage the full lifecycle of cryptographic key material, including generation, distribution, rotation, backup, escrow, restoration, revocation, and secure destruction
  • Maintain chain-of-custody documentation and controls for cryptographic key operations
  • Plan, execute, and participate in secure key ceremonies
  • Develop automation and tooling for PKI, certificate-management, HSM, and cryptographic key-management operations
  • Integrate certificate and key-management capabilities into TeraWave systems with software, firmware, silicon, manufacturing, security, and infrastructure teams
  • Evaluate third-party solutions and contribute to build-versus-buy decisions and vendor selection
  • Support cryptographic infrastructure across development, manufacturing, and production environments
  • Travel up to 20% of the time

Requirements

What you’ll need
  • Bachelor's degree in Computer Science, Computer Engineering, Electrical Engineering, Cybersecurity, or a related technical discipline
  • 5+ years of relevant experience in PKI, cryptographic infrastructure, security infrastructure, or related engineering
  • Demonstrated experience designing, implementing, or administering enterprise Public Key Infrastructure (PKI)
  • Strong knowledge of X.509 certificates, certificate authorities, trust chains, cryptographic algorithms, key management, certificate revocation, and certificate lifecycle management
  • Strong understanding of cryptography, including encryption, digital signatures, hashing, key exchange, and secure communications
  • Experience managing cryptographic key material and key-generation, distribution, storage, rotation, backup, recovery, and destruction processes
  • Experience working with Hardware Security Modules (HSMs) or similar cryptographic hardware
  • Strong troubleshooting, documentation, and operational skills for security-critical infrastructure
  • Ability to work collaboratively across security, software, firmware, silicon, infrastructure, and manufacturing teams
  • Must be a U.S. citizen or national, U.S. permanent resident/current Green Card holder, or lawfully admitted into the U.S. as a refugee or granted asylum
  • Technical assessment required during interviews
  • Preferred: automation using Python or another scripting language; PKCS#11 APIs; enterprise HSM administration; Root CA and Issuing/Leaf CA infrastructure; secure key ceremonies and chain-of-custody controls; embedded-device, custom-silicon, or manufacturing PKI; HSM integrations; commercial PKI/HSM/certificate-management/key-management platforms

Benefits

Comp & perks
  • Relocation provided
  • Medical, dental, and vision insurance
  • Basic and supplemental life insurance
  • Paid parental leave
  • Short- and long-term disability
  • 401(k) with company match of up to 5%
  • Education Support Program
  • Stock options for all regular employees working at least 20 hours per week
  • Up to four weeks of paid time off per year based on weekly scheduled hours
  • Up to 14 company-paid holidays
  • Potential role- and job-level-dependent bonuses and other benefits