FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Senior Certificate Authority Architect
Cloudflare. Define and maintain the end-to-end technical architecture of Cloudflare's public Certificate Authority across certificate issuance, key management, transparency, revocation, renewal, and relying-party integration .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in designing and maintaining secure, resilient certificate authority systems, with a strong focus on key management, certificate lifecycle processes, and cryptographic protocols. Capable of leading architectural initiatives across teams while ensuring compliance with industry standards and security requirements.
Highest-signal resume keywords
Public Certificate Authority ExpertiseCertificate Lifecycle ManagementApplied CryptographyThreat ModelingArchitectural Leadership
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Certificate IssuanceKey ManagementTLS ProtocolsCertificate TransparencyHSM IntegrationKey RotationIncident ResponseSystem Trust BoundariesFailure Handling StrategiesCryptographic Attestations
Soft Skills
Strong CommunicationTechnical MentorshipCollaborative Problem SolvingAutonomous Decision-Making
Industry Keywords
Web PKISecurity-Critical SystemsAudit ControlsCA/Browser Forum RequirementsPublic Operational Telemetry
About the role
Key responsibilities & impact- Define and maintain the end-to-end technical architecture of Cloudflare's public Certificate Authority across certificate issuance, key management, transparency, revocation, renewal, and relying-party integration
- Design root and intermediate CA trust hierarchies, signing systems, HSM integration, key ceremonies, key rotation, backup, recovery, migration, and key-compromise response
- Architect secure, resilient, highly available issuance services operating at Internet scale across multiple geographic and failure domains
- Design certificate lifecycle systems around ACME, domain and IP validation, CAA, Certificate Transparency, pre-issuance linting, revocation, renewal, and large-scale certificate replacement
- Integrate Cloudflare’s Merkle Tree Certificate infrastructure, including CA logs, landmarks, cosigning or mirroring, and relying-party interactions
- Develop architectures for coexistence and migration between classical X.509 certificates and post-quantum authentication mechanisms
- Define trust boundaries, security properties, and threat models covering key compromise, unauthorized issuance, software supply-chain compromise, operator error, malicious insiders, infrastructure failure, split views, and cryptographic migration
- Design observable and independently verifiable CA behavior through transparency mechanisms, reproducible builds, cryptographic attestations, public operational telemetry, tamper-evident evidence, and audit controls
- Design failure containment and recovery mechanisms for certificate replacement, revocation, key rotation, and incident response
- Translate CA/Browser Forum requirements, browser and operating-system root-program policies, audit criteria, and certification requirements into technical and operational controls
- Review protocols, architecture, and implementations with an adversarial mindset
- Collaborate with cryptography, TLS, security, networking, infrastructure, compliance, product, and operations teams
- Provide architectural direction, design review, and technical mentorship to engineers
- Represent Cloudflare in standards and industry work with browser vendors, root programs, researchers, auditors, CA operators, and the Web PKI community
Requirements
What you’ll need- Substantial experience designing or operating security-critical systems, with deep expertise in at least one of: public Certificate Authorities, Web PKI, applied cryptography, TLS and Internet security protocols, Certificate Transparency, hardware-backed key management, or large-scale distributed security systems
- Strong knowledge of certificate trust chains, issuance and validation, revocation, key lifecycle management, and the security and availability implications of CA design decisions
- Experience defining system trust boundaries, threat models, security invariants, and failure-handling strategies
- Ability to reason about systems in which a subtle architectural or operational mistake can affect a significant fraction of the Internet
- Experience leading architecture across multiple engineering teams without relying solely on organizational authority
- Strong written and verbal communication, including the ability to explain cryptographic and architectural tradeoffs to engineers, auditors, standards participants, and senior stakeholders
- Comfort operating with substantial autonomy in an evolving technical and policy environment
- Offer may be conditioned on authorization to receive software or technology controlled under U.S. export laws without sponsorship for an export license
Benefits
Comp & perks- In-person interview within one of the Cloudflare Offices or Cloudflare Hubs may be required at the offer stage
- Equal employment opportunity and diversity and inclusiveness commitment
- Reasonable accommodations for qualified individuals with disabilities