Belcan

PKI Governance and Configuration Manager

Belcan$145K — $170K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree with 9 years of relevant experience.
  • 8+ years in Cybersecurity, including 5 years in PKI and Federal Governance (GRC).
  • In-depth knowledge of X.509 certificates, HSMs, CRLs, and OCSP.
  • Expertise in NIST SP 800-53, NIST SP 800-37 (RMF), FIPS 140-2/3, NIST SP 800-157 (Rev-1), and FedRAMP requirements.
  • Demonstrated success in the entire A&A process for achieving ATO.
  • Proficient in identity systems (ADCS, Entrust, or EJBCA) and cloud security frameworks.

Responsibilities

  • Architect compliance for systems across Unclassified, Classified, and SaaS environments.
  • Direct the lifecycle governance for multiple PKI systems and credential hosting environments.
  • Ensure adherence to Certificate Policy (CP) and Certification Practice Statements (CPS).
  • Oversee NIST SP 800-53 security compliance assessments.
  • Develop and maintain a library of security artifacts (SSP, SAR, etc.).
  • Manage the end-to-end FedRAMP certification process for SaaS offerings.
  • Lead the Change Advisory Board evaluating security impacts of system modifications.

Benefits

  • Health care, dental, and vision insurance.
  • Life insurance coverage.
  • 401(k) retirement plan.
  • Education assistance for professional development.
  • Paid time off, including holidays and other legally required leave.
Full Job Description
Job Summary:

A PKI Governance and Configuration Manager job in Springfield, VA is currently available through Belcan at one of our key Federal Civilian clients. To be considered for this role, you will have a bachelor's degree and 9 years of relevant experience.

Job Duties:

This role is a hybrid of technical configuration management and high-level cybersecurity governance. You will be the primary architect of compliance, ensuring that all systems across Unclassified, Classified, and SaaS environments maintain their Authority to Operate (ATO). You will bridge the gap between technical PKI operations, engineering and federal regulatory requirements, specifically focusing on NIST SP 800-53, FedRAMP frameworks, and other applicable Federal standards.

PKI & Credential Systems Governance:
  • Direct the governance lifecycle for multiple PKI systems and Credential Hosting environments.
  • Enforce adherence to Certificate Policy (CP) and Certification Practice Statements (CPS).
  • Lead the development and implementation of PKI-related policies across diverse network fabrics.

Compliance & Artifact Development (NIST/FedRAMP):
  • Serve as the Lead for all NIST SP 800-53 security compliance assessments.
  • Author, review, and maintain a comprehensive library of security artifacts (SSP, SAR, POA&M, etc.).
  • Manage the end-to-end FedRAMP certification process for SaaS offerings.
  • Ensure continuous monitoring and timely remediation to maintain ATO status for all systems.

Configuration & Change Management:
  • Establish and manage strict Configuration Management (CM) baselines for PKI hardware and software.
  • Lead the Change Advisory Board (CAB) for identity services, evaluating the security impact of all system modifications.
  • Maintain rigorous documentation of system architectures and configuration settings.

Multi-Network Oversight:
  • Synchronize security postures across Unclassified (NIPR), Classified (SIPR), and Cloud/SaaS environments.
  • Coordinate with cross-functional teams to ensure seamless identity management and credential interoperability.

Required Qualifications:
  • Secret clearance with ability to obtain Top Secret clearance.
  • Bachelor's degree and 9 years of relevant experience.
  • 8+ years in Cybersecurity, with at least 5 years specifically focused on PKI and Federal Governance (GRC).
  • Deep understanding of X.509 certificates, HSMs (Hardware Security Modules), CRLs, and OCSP.
  • Mastery of NIST SP 800-53, NIST SP 800-37 (RMF), FIPS 140-2/3, NIST SP 800-157 (Rev-1), NIST SP 800-63, and FedRAMP Moderate/High requirements.
  • Proven track record of successfully taking a system through the full A&A (Assessment and Authorization) process to achieve an ATO.
  • Proficient in the following:
    • Identity Systems: Active Directory Certificate Services (ADCS), Entrust, or EJBCA.
    • Cloud Security: FedRAMP OSCAL, AWS/Azure Government Cloud security controls.
    • Tools: STIG Viewer, SCAP Compliance Checker, Nessus/ACAS, JIRA for CM.


Preferred Qualifications & Skills:
  • One or more certificates preferred: CISSP, CISM, or GSLC, ITIL, PMP, or specialized PKI certifications.


Compensation:

We provide a competitive pay and benefits package. This position is offering a salary range of $145,000 - $170,000. Belcan considers several factors when extending an offer, including but not limited to education, experience, geographic location, and discipline. Benefits offered may include health care, dental, vision, life insurance; 401(k); education assistance; paid time off including PTO, holidays, and any other paid leave required by law.

www.belcan.com

About Belcan

Belcan, LLC is a global supplier of engineering, supply chain, technical recruiting and information technology services to customers in the aerospace, defense, automotive, industrial and government sectors. Headquartered in Cincinnati, Ohio, Belcan has over 10,000 employees in 50 locations around the world.
Learn more about Belcan
Industry
Founded
1972

Similar Jobs

More Jobs at Belcan

  • Belcan
    Service Now/System Administrator
    $125K — $145K *
    Washington, DC 20011 (District Of Columbia County)
    Information Technology
    In-Person
  • Belcan
    QC Associate II
    $99K *
    Westborough, MA 01581 (Worcester County)
    Pharmaceuticals & Biotech
    In-Person
  • Belcan
    Manufacturing Engineer
    $130K *
    Ennis, TX 75119 (Ellis County)
    Manufacturing & Automotive
    In-Person
  • Belcan
    Quality Manager
    $120K — $140K *
    Rockaway, NJ 07866 (Morris County)
    Aerospace & Defense
    In-Person
  • Belcan
    Design Engineer
    $83K — $83K *
    Mossville, IL 61552 (Peoria County)
    Information Technology
    In-Person

More Information Technology Jobs

Find similar PKI Governance and Configuration Manager jobs: