1

Contractual Pki Administrator Jobs (NOW HIRING)

Solutions Architect

Fort Belvoir, VA ยท On-site

$187K - $253K/yr

Direct, mentor, and empower a team of systems administrators, driving operational excellence ... Rather, salary will be set based on experience, geographic location and possibly contractual ...

next page

Showing results 1-20

Contractual Pki Administrator information

What is a contractual PKI administrator?

A Contractual PKI Administrator is a professional hired on a contract basis to manage and maintain Public Key Infrastructure (PKI) systems within an organization. Their primary responsibilities include overseeing digital certificate issuance, renewal, and revocation, managing encryption keys, and ensuring the security of communications and data. They also monitor PKI system performance, troubleshoot issues, and ensure compliance with security policies and standards. Since they work on a contractual basis, their employment is typically for a fixed term or specific project.

What are the key skills and qualifications needed to thrive as a contractual PKI administrator?

To thrive as a Contractual PKI Administrator, you need a solid understanding of cryptography, digital certificates, and network security, typically backed by a degree in computer science or a related field. Familiarity with PKI management tools (like Microsoft CA or OpenSSL), experience with HSMs, and relevant certifications such as CompTIA Security+ or CISSP are highly valued. Strong problem-solving skills, attention to detail, and effective communication are essential soft skills for this role. These competencies ensure the secure management of digital identities and trust infrastructures, which are critical for organizational data security and compliance.

What are some common challenges faced by a contractual PKI administrator, and how can they be addressed?

Contractual PKI Administrators often face challenges such as managing complex certificate lifecycles, ensuring compliance with evolving security standards, and coordinating with multiple stakeholders across departments. To address these, it's essential to establish clear communication channels, use automated certificate management tools, and stay updated with the latest PKI best practices. Proactively monitoring certificate expiration and maintaining detailed documentation also help minimize security risks and service disruptions.

What is the difference between Contractual Pki Administrator vs Network Security Specialist?

AspectContractual Pki AdministratorNetwork Security Specialist
CertificationsPKI, CompTIA Security+CISSP, CompTIA Security+
Work EnvironmentManaged PKI systems, certificate managementNetwork infrastructure, security protocols
Industry UsageIT, cybersecurity, enterprise securityIT, cybersecurity, network operations

The Contractual Pki Administrator focuses on managing Public Key Infrastructure and certificate issuance, while the Network Security Specialist oversees broader network security measures. Both roles require security certifications and work within IT and cybersecurity environments, but their core responsibilities differ in scope and focus.

What cities are hiring for Contractual Pki Administrator jobs?

Cities with the most Contractual Pki Administrator job openings:

What are the most commonly searched types of Pki Administrator jobs?

The most popular types of Pki Administrator jobs are:

What states have the most Contractual Pki Administrator jobs?

States with the most job openings for Contractual Pki Administrator jobs include:

Cyber PKI Administrator

SHR Consulting Group, LLC

Arlington, VA โ€ข On-site

$110K - $150K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted yesterday

New


Job description

About SHR Consulting Group

SHR Consulting Group, LLC is a small business delivering enterprise IT, cybersecurity, and program management services to the Department of Defense and federal civilian agencies. We support mission-critical infrastructure at the Pentagon and across the National Capital Region, and we invest in our people through competitive compensation, professional certification support, and long-term career growth on stable, multi-year programs.

Position Summary

We are a rapidly growing organization seeking an experienced Cyber PKI Administrator to provide specialized IT expertise for supporting a DISA environment. This position is responsible for the installation, configuration, operation, and maintenance of Public Key Infrastructure (PKI) services and Hardware Security Module (HSM) appliances that protect DoD identity, authentication, and encryption capabilities. The Cyber PKI Administrator ensures that HSM devices, Certificate Authorities, and supporting services are properly configured, maintained, and updated, and that the cryptographic environment adheres to DoD security standards, organizational values, and contractual performance requirements.

This role supports Government customers across one or more classification domains and may require work across standard business hours or on a shift/rotational schedule, depending on task order requirements. Because HSMs are designated mission-critical assets, the role demands strict adherence to two-person integrity, separation of duties, and disciplined audit and access controls. The Cyber PKI Administrator serves as the primary administrator of the cryptographic environment and works alongside designated backup administrators in the broader operations team who hold equivalent privileged credentials and emergency access.

Duties will vary based on position and area of focus:

HSM Operations and Administration

  • Install, configure, and maintain enterprise-class Hardware Security Module (HSM) appliances in accordance with vendor best practices, DoD security configuration baselines, and approved standard operating procedures (SOPs).
  • Monitor HSM health, performance, and availability; identify, troubleshoot, and resolve hardware, firmware, and client-side issues in a timely manner.
  • Perform HSM firmware updates, software patches, and supporting client software upgrades in compliance with DoD Information Assurance Vulnerability Management (IAVM) requirements and Government-directed maintenance windows.
  • Maintain HSM configuration documentation, baseline records, and change logs in accordance with configuration management processes.
  • Partition and Role Management: Create and manage HSM partitions, assign cryptographic officer and user roles, and enforce quorum (M of N) authentication controls so that no single individual can perform sensitive operations.
  • Key Lifecycle Management: Oversee the full lifecycle of cryptographic key material — generation, distribution, rotation, backup, escrow, restoration, and destruction — and maintain chain-of-custody documentation for all key operations.
  • Key Ceremony Execution: Plan and execute formal key ceremonies for Root and Issuing Certificate Authority events; develop and maintain ceremony scripts and witness logs.
  • Tamper Integrity: Maintain tamper-evident packaging, seal logs, and physical inspection records consistent with FIPS 140-2/140-3 operational guidance.

Public Key Infrastructure (PKI) and Certificate Management

  • Operate and maintain enterprise Certificate Authorities, Online Certificate Status Protocol (OCSP) responders, and Certificate Revocation List (CRL) distribution services across multiple classification domains.
  • Issue, renew, revoke, and replace DoD and National Security System (NSS) PKI certificates for web servers, domain controllers, Domain Name System (DNS) servers, and other infrastructure components.
  • Expiration Tracking: Build and maintain a comprehensive certificate expiration tracker; coordinate proactive renewal with affected system owners to prevent service disruption and report status to Government leadership on a recurring cadence.
  • Root and Policy CA Operations: Support Root and Policy Certificate Authority lifecycle events, including offline operations, approved key ceremonies, and Government-directed updates.
  • Smart Card and CAC Integration: Manage Common Access Card (CAC) and PKI integration for Government and contractor personnel, including user authentication, certificate mapping, and smart-card-based access controls.
  • PKI Consumer Coordination: Partner with Domain Services, application, database, and platform teams to ensure dependent systems consume PKI services correctly and remain compliant with cryptographic standards.

Physical and Logical Access Control

  • Enforce physical and logical access controls to HSM appliances; maintain access rosters and coordinate facility access with Government POCs.
  • Execute two-person rule procedures for sensitive cryptographic operations in partnership with designated backup administrators.
  • Train and qualify designated backup administrators from the broader operations team to maintain emergency access to the cryptographic environment, ensuring continuity of operations without compromising separation of duties.
  • Audit privileged access to the cryptographic environment on a recurring basis and report findings to Government leadership.

Cybersecurity and Compliance

  • Ensure all PKI and HSM systems maintain compliance with DoD Security Technical Implementation Guides (STIGs), Information Assurance Vulnerability Alerts (IAVAs), and applicable Command Cyber Tasking Orders (CCTOs).
  • Conduct and analyze vulnerability scans (e.g., ACAS/Nessus) of HSM management interfaces and PKI infrastructure; apply remediations including security patches, configuration changes, and STIG settings within Government-required timelines.
  • Support Risk Management Framework (RMF) activities including the development and maintenance of system security documentation, Plan of Action and Milestones (POA&Ms), and Assessment and Authorization (A&A) artifacts for the cryptographic environment.
  • Log Auditing: Review HSM and Certificate Authority audit logs on a recurring schedule, investigate anomalies, and coordinate with the defensive cyber operations team on any indicators of compromise.
  • Adhere to DoD 8570.01-M / DoD 8140 Information Assurance workforce requirements applicable to the assigned role.

Documentation and Communication

  • Develop, update, and maintain SOPs, Work Instructions (WIs), key ceremony scripts, and technical documentation for all supported cryptographic services.
  • Provide status updates, incident reports, and After Action Reports (AARs) as required by Government leadership.
  • Participate in configuration change control board (CCB) processes; coordinate all PKI and HSM changes through approved change management procedures.
  • Collaborate with network, cybersecurity, server operations, and application teams to resolve cross-functional issues.
  • Provide technical support and training to end users and junior staff as needed.

Minimum Qualifications

  • Hands-on experience administering enterprise PKI in a Windows Active Directory environment, including Certificate Authorities, OCSP, and CRL distribution.
  • Working knowledge of Hardware Security Modules (HSMs) and FIPS 140-2/140-3 operational requirements.
  • Experience with cryptographic key lifecycle management: generation, backup, cloning, restoration, escrow, and destruction.
  • Working knowledge of Windows Server operating systems (2016/2019/2022), Active Directory, Group Policy, and PowerShell scripting.
  • Understanding of cryptographic concepts: asymmetric and symmetric algorithms, hashing, digital signatures, X.509 certificate structure, and certificate chain validation.
  • Ability to apply DoD STIGs and IAVAs to maintain system compliance.
  • Ability to operate under strict two-person integrity, separation-of-duties, and audit controls.
  • Ability to create and maintain technical documentation, SOPs, and key ceremony scripts.
  • Ability to work shift hours, weekends, or on-call rotations as required by task order.
  • Strong oral and written communication skills; ability to brief technical topics to non-technical stakeholders.

Preferred Qualifications

  • Experience in a DoD, Intelligence Community, or Federal Government IT environment.
  • Direct hands-on experience with Thales Luna Network HSM or Luna PCIe HSM appliances and associated administrative tooling.
  • Experience operating Microsoft Active Directory Certificate Services (AD CS) at enterprise scale.
  • Experience with OCSP responders, CRL signing, and Certificate Transparency.
  • Experience supporting DoD PKI, NSS PKI, or External Certification Authority (ECA) programs.
  • Familiarity with HSM integration with VMware, Microsoft IIS, F5, and other PKI-consuming platforms.
  • Familiarity with DoD RMF processes, eMASS, and A&A documentation.
  • Knowledge of DoD Identity, Credential, and Access Management (ICAM) frameworks.
  • PowerShell, Python, or Bash scripting for PKI and HSM automation.

Education

  • One of the following is required:
  • Bachelor's degree in Computer Science, Computer Engineering, Information Technology, Information Systems, Cybersecurity, or a closely related technical field; OR
  • Associate's degree in a related technical field plus additional qualifying experience; OR
  • Equivalent combination of education, training, and directly relevant DoD IT experience as defined by labor category level below.
  • Mid (3-5 years - Works independently on most tasks; supports complex troubleshooting; mentors juniors
  • Senior (6+ years) - SME-level expertise; leads technical efforts; guides architecture and compliance decisions

Required Certifications

  • DoD Directive 8570.01-M / DoD 8140 baseline certification requirements applicable to their assigned Cyber IT/Cybersecurity role. The following certifications satisfy the minimum IAT Level II requirement:
  • CompTIA Security+ CE
  • Cisco CCNA Security
  • CySA+ (CompTIA Cybersecurity Analyst)
  • GIAC Security Essentials (GSEC)
  • Systems Security Certified Practitioner (SSCP)

Additional computing environment (CE) certifications may be required depending on the specific technologies managed (e.g., Microsoft, VMware, Red Hat, Cisco). Certifications must be current and maintained throughout the period of performance.

Desired Vendor Certification

In addition to the IAT Level II baseline above, the Thales Luna HSM Professional Engineer certification is strongly desired for this position. As an alternative pathway, a candidate who possesses the credentials and demonstrated experience to be granted Domain Administrator privileges may be considered, provided the candidate commits to achieving the Thales Luna HSM Professional Engineer certification within six (6) months of hire. Failure to obtain the certification within the agreed window may result in reassignment from the primary cryptographic administrator role.

Security Clearance

U.S. Citizenship and a minimum active Secret security clearance are required for this position. Certain task orders or work locations may require a Top Secret (TS) or TS/SCI clearance. All personnel must be able to obtain and maintain the required clearance level and must possess a valid DoD Common Access Card (CAC). Personnel may be required to access systems across multiple classification domains, including Unclassified (NIPR), Secret (SIPR), and Top Secret/Collateral networks.

Work Environment

100% onsite at a government facility within the National Capital Region (NCR), primarily at the Pentagon, Crystal Gateway, Taylor Building, Mark Center, or other JSP-designated alternate site. Must be local to the DC Metro Area with reliable transportation.

Benefits

  • Competitive salary commensurate with experience and clearance level.
  • Comprehensive medical, dental, and vision coverage.
  • 401(k) with company contribution.
  • Paid time off and eleven federal holidays.
  • Certification reimbursement and training support (DoD 8140 baseline and computing environment certifications).
  • Life and disability insurance.


SHR Consulting Group, LLC is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.