DescriptionSupport and sustain enterprise Public Key Infrastructure (PKI) operations for the National Airspace System (NAS), administering the full certificate lifecycle and ensuring secure, standards-compliant certificate issuance and validation across a diverse operational environment.
You will configure, harden, and administer PKI management tools and platforms, troubleshoot certificate chain and trust store issues, and integrate digital certificates into servers, applications, network devices, and cloud services to enable secure TLS/SSL communications - automating issuance, renewal, and deployment at scale.
This role also involves implementing Multi-Perspective Issuance Corroboration (MPIC) capabilities in support of CA/Browser Forum Baseline Requirements, reviewing FAA program documentation to identify PKI dependencies and risks, and supporting day-to-day operations including ticketing, documentation, and NIST-aligned security policy compliance.
Key Responsibilities- PKI Environment Design & Certificate Lifecycle Management
Design, deploy, administer, and maintain PKI environments, encompassing the full certificate lifecycle from issuance and renewal through revocation (CRL/OCSP), rekeying, and archival, ensuring configurations align with security policy, operational risk tolerance, and long-term sustainment goals.
- PKI Platform Configuration & Hardening
Configure, harden, and administer PKI management tools and platforms across diverse system environments to support secure certificate issuance and validation workflows, troubleshoot certificate chain and trust store errors, and maintain consistent, standards-based configurations across heterogeneous operational environments.
- Multi-Perspective Issuance Corroboration (MPIC)
Implement and maintain MPIC capabilities to validate domain control from multiple geographically and topologically diverse network vantage points, ensuring compliance with CA/Browser Forum Baseline Requirements and related industry standards governing certificate issuance integrity and validation assurance.
- Certificate Integration & Automation
Integrate digital public certificates into servers, applications, network devices, and cloud-based services to enable secure TLS/SSL communications, including automating certificate issuance, renewal, and deployment processes to reduce manual effort, minimize error rates, and support faster, more reliable certificate provisioning at scale.
- Program Support & Operations
Review FAA program and project documentation to identify PKI, digital certificate, and dependencies and risks, coordinating with program offices and technical stakeholders to align certificate management practices and automation initiatives with FAA program schedules and requirements. Support day-to-day operations including ticketing systems, documentation, NIST-aligned security policy compliance, and backup coverage to ensure operational redundancy and continuity.
- Industry Engagement & Outreach
Contribute to working groups and standards bodies, and represent the organization externally through publications, conference presentations, and panel participation.
- Strategic Insight & Opportunity Identification
Stay current on government and industry activities to identify emerging trends, gaps, and innovation opportunities. Contribute ideas that support growth and new business opportunities.
Requirements- Bachelor's degree in Engineering, Computer Science, or a related field, plus 15+ years of relevant experience.
- Experience designing, deploying, administering, and maintaining PKI environments across the full certificate lifecycle (issuance, renewal, revocation via CRL/OCSP, rekeying, archival).
- Experience configuring, hardening, and administering PKI management tools and platforms across diverse system environments.
- Experience troubleshooting certificate chain and trust store errors and maintaining standards-based configurations across heterogeneous environments.
- Experience implementing Multi-Perspective Issuance Corroboration (MPIC) capabilities in compliance with CA/Browser Forum Baseline Requirements.
- Experience integrating digital public certificates into servers, applications, network devices, and cloud-based services for secure TLS/SSL communications.
- Experience automating certificate issuance, renewal, and deployment processes.
- Experience reviewing program and project documentation to identify PKI and identity management dependencies and risks, and coordinating with program offices and technical stakeholders.
- Familiarity with NIST-aligned security policy compliance and day-to-day operational support (ticketing systems, documentation, backup coverage).
Preferred Qualifications- Experience working with FAA or other government programs.
- Familiarity with Non-Personnel Entity (NPE) Identity Management Systems.
- Certifications such as CISSP, Security+, or equivalent.
- Experience with PKI/CA platforms (e.g., EJBCA, Venafi, Microsoft ADCS).
- Scripting or automation experience (e.g., Python, PowerShell, Ansible) for certificate lifecycle automation.
- Awareness of or experience with post-quantum cryptography (PQC).