Назад
Company hidden
обновлено 60 минут назад

SME Systems Engineer (Cloud PKI)

135 000 - 172 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
SME Systems Engineer (Cloud PKI) (ICAM/PKI): Designing and operating secure identity, credential, and access control frameworks for U.S. Coast Guard enterprise architectures with an accent on cloud PKI, federation, Zero Trust, and certificate management. Focus on engineering DigiCert and cloud HSM solutions, creating certificate templates, planning YubiKey integration for NIST AAL3, and resolving complex PKI incidents.

Location: Alexandria, Virginia, United States; hybrid position

Salary: $135,000–$172,000 annually

Company

hirify.global delivers IT services and technology solutions that support the modernization of government agencies.

What you will do

  • Serve as a technical authority for enterprise identity management and access control frameworks supporting U.S. Coast Guard modernization.
  • Modernize legacy access controls and engineer ICAM solutions covering directories, federation, authentication, authorization, and SSO.
  • Architect identity lifecycles, provisioning workflows, privilege management, MFA, PAM, and federated identity services.
  • Design and deploy Zero Trust identity principles based on NIST SP 800-207 across enterprise networks.
  • Lead engineering and management of the DigiCert platform and cloud HSMs, including enterprise certificate templates.
  • Plan future YubiKey integration for NIST AAL3 requirements and serve as the final escalation point for PKI outages and issues.

Requirements

  • 10+ years of experience or equivalent experience, with a high school diploma or higher.
  • DoD 8570 IAT Level II or higher certification, such as Security+ CE, CySA+, or a vendor-specific identity certification.
  • Deep understanding of federated identity concepts, including SAML, OAuth, OIDC, Active Directory, and LDAP.
  • Hands-on experience with Smart Card/CAC authentication and PKI certificate validation.
  • Experience applying federal Zero Trust identity guidelines, including NIST SP 800-207, within enterprise networks.
  • Active Secret clearance is required.

Nice to have

  • Experience supporting U.S. Coast Guard or Department of Homeland Security identity management programs.
  • Experience integrating data governance frameworks with ICAM solutions and enforcing data-level access controls.
  • Experience with SailPoint, Okta, Microsoft Entra ID, Ping Identity, DigiCert, or Power BI.
  • Advanced knowledge of RESTful API authorization, secure gateways, and data schema security standards.

Culture & Benefits

  • Flexible work environment and collaborative work culture.
  • Employee Assistance Program and corporate discounts.
  • Learning and development platform with certification preparation content.
  • Training, education, and certification assistance for full-time employees.
  • Referral bonus, internal mobility program, and pet insurance.

Hiring process

  • Virtual video interview with the hiring manager and/or team; camera use and valid photo identification are required.
  • Enhanced biometric identity verification screening.
  • Background check covering criminal history, education, and employment history verification.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →