Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
IT Labs

Senior PKI Engineer

IT Labs

. Implement and support machine certificate-based authentication for Windows endpoints .

Posted 10/7/2026full-timeRemote • United StatesSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in Public Key Infrastructure (PKI) management, including certificate lifecycle management, secure device authentication, and integration with enterprise systems like Microsoft Intune and Active Directory. Proficient in troubleshooting certificate and connectivity issues within high-security environments.

Highest-signal resume keywords
Public Key Infrastructure (PKI)Microsoft Active Directory Certificate ServicesCertificate Lifecycle ManagementPalo Alto GlobalProtectWindows Endpoint Management

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Certificate EnrollmentCertificate RenewalCertificate RevocationX.509 CertificatesPrivate Key ManagementCRL / OCSPPowerShell ScriptingMachine/Device CertificatesTPM-Backed CertificatesAlways-On VPN
Soft Skills
Strong Troubleshooting SkillsCollaboration
Tools & Technologies
Microsoft IntunePalo Alto GlobalProtectPrisma AccessMicrosoft DefenderCrowdStrikeTaniumQualys
Industry Keywords
High-Security EnvironmentsSecurity-Conscious EnterpriseCertificate-Based VPN Authentication

About the role

Key responsibilities & impact
  • Implement and support machine certificate-based authentication for Windows endpoints
  • Integrate an existing enterprise PKI environment with Palo Alto GlobalProtect Pre-Logon
  • Support secure device authentication before Windows user login
  • Configure and troubleshoot certificate enrollment, renewal, expiration, and revocation
  • Work with Microsoft Intune, Active Directory, and Windows endpoint management
  • Ensure certificates and private keys are securely stored and protected, including TPM-backed key scenarios where applicable
  • Support CRL and OCSP validation and certificate revocation processes
  • Configure and troubleshoot GlobalProtect certificate authentication and pre-logon connectivity
  • Support the transition from machine/device identity to authenticated user identity
  • Work with network and security teams on Prisma Access, firewall policies, and secure endpoint connectivity
  • Troubleshoot certificate, authentication, and connectivity issues across endpoints
  • Support resilience and failover scenarios across GlobalProtect / Prisma Access gateways
  • Document technical configurations, operational processes, and troubleshooting procedures
  • Collaborate with endpoint, networking, identity, and security teams

Requirements

What you’ll need
  • Strong hands-on experience with Public Key Infrastructure (PKI) in enterprise environments
  • Strong knowledge of Microsoft AD CS / Certificate Services or comparable enterprise PKI solutions
  • Experience with machine/device certificates
  • Experience with certificate enrollment and auto-enrollment
  • Experience with certificate lifecycle management
  • Experience with certificate renewal and revocation
  • Experience with CRL / OCSP
  • Experience with X.509 certificates
  • Experience with private key management
  • Strong experience with Windows enterprise environments
  • Experience with Active Directory
  • Experience with Microsoft Intune or another enterprise endpoint management platform
  • Strong troubleshooting skills across certificates, authentication, endpoint configuration, and network connectivity
  • Experience working in security-conscious enterprise environments
  • U.S. citizenship is required
  • Must be based in the United States
  • Ability to work on an Individual Contractor or B2B contract basis
  • Experience with Palo Alto GlobalProtect, Prisma Access, and GlobalProtect Pre-Logon preferred
  • Experience with certificate-based VPN authentication preferred
  • Understanding of Always-On VPN / Always-On GlobalProtect architectures preferred
  • Experience with TPM-backed certificates and hardware-protected private keys preferred
  • Experience with Microsoft Entra ID preferred
  • Experience with CrowdStrike, Microsoft Defender, Tanium, or Qualys preferred
  • PowerShell scripting experience preferred
  • Experience working in regulated or high-security environments preferred

Benefits

Comp & perks
  • Paid Time Off (PTO) included as part of the engagement
  • Remote work arrangement
  • Full-time commitment aligned with the client's business hours and project needs