Blue Origin

Senior PKI & Certificate Management Engineer

Blue Origin • $230K — $322K *
Telecommunications & Hardware
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in a related technical discipline (Computer Science, Cybersecurity, etc.)
  • 5+ years of experience in PKI or cryptographic infrastructure
  • Experience in designing or administering enterprise PKI
  • Strong knowledge of X.509 certificates and certificate lifecycle management
  • Understanding of cryptographic principles and key-management processes
  • Experience with Hardware Security Modules (HSMs)
  • Collaborative skills to work across various technical teams

Responsibilities

  • Design and maintain PKI and certificate-management infrastructure for TeraWave devices.
  • Automate the lifecycle management of digital certificates including issuance and revocation.
  • Configure and integrate cryptographic services with HSMs and hardware security interfaces.
  • Monitor and troubleshoot HSM performance, including maintaining documentation and logs.
  • Manage the lifecycle of cryptographic keys securely and efficiently.
  • Participate in secure key ceremonies with proper chain-of-custody documentation.
  • Collaborate with cross-functional teams to integrate necessary security capabilities.

Benefits

  • Comprehensive medical, dental, and vision insurance coverage
  • Paid parental leave and short/long-term disability benefits
  • 401(k) plan with company match up to 5%
  • Education Support Program for continuous learning
  • Stock options for all regular employees
  • Generous paid time off policy including up to four weeks annually
  • Eligibility for individual contribution bonuses and incentives.
Full Job Description
Application close date:
Applications will be accepted on an ongoing basis until the requisition is closed.

Job Description

As part of a hardworking team of engineers and specialists, you will design, implement, automate, and operate the Public Key Infrastructure (PKI), certificate management, Hardware Security Module (HSM), and cryptographic key-management infrastructure supporting TeraWave custom silicon, devices, and systems.

You will be responsible for securely managing certificates and cryptographic key material throughout their lifecycle and will work closely with security, silicon, firmware, software, manufacturing, and infrastructure teams to deploy scalable and reliable security infrastructure across development, manufacturing, and production environments.

Special Mentions
  • Relocation provided
  • Travel expected up to 20% of the time
  • Interviews will include a technical assessment

Responsibilities include but are not limited to:
  • Design, implement, administer, and maintain PKI and certificate-management infrastructure supporting TeraWave devices and infrastructure.
  • Automate and oversee the issuance, renewal, revocation, rotation, and replacement of digital certificates.
  • Configure hardware security interfaces, token management, and cryptographic service integrations for applications and HSMs.
  • Install, configure, administer, and maintain enterprise-class Hardware Security Module (HSM) appliances in accordance with vendor best practices, approved operating procedures, and applicable industry standards.
  • Monitor HSM health, performance, and availability and identify, troubleshoot, and resolve hardware, firmware, software, and client-side issues.
  • Perform HSM firmware updates, software patches, supporting client software upgrades, and configuration changes.
  • Maintain HSM configuration documentation, baseline records, audit information, and change logs in accordance with configuration-management processes.
  • Manage the full lifecycle of cryptographic key material, including generation, distribution, rotation, backup, escrow, restoration, revocation, and secure destruction.
  • Maintain appropriate chain-of-custody documentation and controls for cryptographic key operations.
  • Plan, execute, and participate in secure key ceremonies.
  • Develop automation and tooling for PKI, certificate-management, HSM, and cryptographic key-management operations.
  • Work with software, firmware, silicon, manufacturing, security, and infrastructure teams to integrate certificate and key-management capabilities into TeraWave systems.
  • Evaluate third-party PKI, HSM, certificate-management, and key-management solutions and contribute to technical build-versus-buy decisions and vendor selection.
  • Support deployment and operation of cryptographic infrastructure across development, manufacturing, and production environments.

Minimum Qualifications
  • Bachelor's degree in Computer Science, Computer Engineering, Electrical Engineering, Cybersecurity, or a related technical discipline.
  • 5+ years of relevant experience in PKI, cryptographic infrastructure, security infrastructure, or related engineering.
  • Demonstrated experience designing, implementing, or administering enterprise Public Key Infrastructure (PKI).
  • Strong knowledge of X.509 certificates, certificate authorities, trust chains, cryptographic algorithms, key management, certificate revocation, and certificate lifecycle management.
  • Strong understanding of cryptography, including encryption, digital signatures, hashing, key exchange, and secure communications.
  • Experience managing cryptographic key material and understanding key-generation, distribution, storage, rotation, backup, recovery, and destruction processes.
  • Experience working with Hardware Security Modules (HSMs) or similar cryptographic hardware.
  • Strong troubleshooting, documentation, and operational skills for security-critical infrastructure.
  • Ability to work collaboratively across security, software, firmware, silicon, infrastructure, and manufacturing teams.
  • Must be a U.S. citizen or national, U.S. permanent resident (current Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum.

Preferred Qualifications
  • Experience automating HSM, PKI, certificate-management, or key-management operations using Python or another scripting language.
  • Experience using PKCS#11 APIs from Python, Java, C/C++, or similar languages.
  • Experience configuring and administering enterprise-class HSM appliances.
  • Experience designing or operating Root CA and Issuing/Leaf CA infrastructure.
  • Experience conducting secure key ceremonies and maintaining chain-of-custody controls.
  • Experience with PKI and cryptographic infrastructure supporting embedded devices, custom silicon, or manufacturing environments.
  • Experience integrating HSMs with applications, services, and automated infrastructure.
  • Experience evaluating and integrating commercial PKI, HSM, certificate-management, or key-management platforms.


Base Pay Range for:
CA applicants is $230,398.00 - $322,556.85WA applicants is $230,398.00 - $322,556.85

Other site ranges may differ

Benefits
  • Benefits include: Medical, dental, vision, basic and supplemental life insurance, paid parental leave, short and long-term disability, 401(k) with a company match of up to 5%, and an Education Support Program.
  • Stock Options for all regular employees (working at least 20 hours/week)
  • Paid Time Off: Up to four (4) weeks per year based on weekly scheduled hours, and up to 14 company-paid holidays.
  • Dependent on role type and job level, employees may be eligible for benefits and bonuses based on the company's intent to reward individual contributions and enable them to share in the company's results, or other factors at the company's sole discretion. Bonus amounts and eligibility are not guaranteed and subject to change and cancellation. Please check with your recruiter for more details.

About Blue Origin

Blue Origin is an aerospace company that develops rockets and spacecraft for commercial and government customers. The company's products include the New Shepard suborbital vehicle and the New Glenn orbital rocket. Blue Origin was founded in 2000 by Jeff Bezos and is headquartered in Kent, Washington.
Learn more about Blue Origin
Size
3,000 employees
Industry
Founded
2000

Similar Jobs

More Jobs at Blue Origin

More Telecommunications & Hardware Jobs

Find similar Senior PKI & Certificate Management Engineer jobs: