We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results

Principal Engineer - PKI & Certificate Management

Early Warning Services LLC
parental leave, paid time off, 401(k), retirement plan
United States, Illinois, Chicago
8745 West Higgins Road (Show on map)
May 30, 2025

At Early Warning, we've powered and protected the U.S. financial system for over thirty years with cutting-edge solutions like Zelle, Paze, and so much more. As a trusted name in payments, we partner with thousands of institutions to increase access to financial services and protect transactions for hundreds of millions of consumers and small businesses.

Positions located in Scottsdale, San Francisco, Chicago, or New York follow a hybrid work model to allow for a more collaborative working environment.

Candidates responding to this posting must independently possess the eligibility to work in the United States, for any employer, at the date of hire. This position is ineligible for employment Visa sponsorship.

Overview

The Principal Engineer - PKI & Certificate Management is a technical domain expert as well as a critical program manager responsible for managing and monitoring all aspects of public key infrastructure (PKI) services at EWS. Initially, this role will be a hands-on, technical lead providing subject matter expertise to implement KPI solutions and best practices. Longer term, the role will apply in-depth knowledge of PKI products, technologies, and best practices to help scale the PKI organization.

Essential Functions

  • Leads the infrastructure protection strategy to create, evolve, and secure our internal Public Key Infrastructure (PKI) and credential management security strategy. Is the SME and technical lead for Internal Certificate Authority and PKI implementation.

  • Provides subject matter expertise in resolving complex problems related to infrastructure and PKI.

  • Collaborates with cross-functional teams to integrate certificate management solutions into existing infrastructure, including cloud, on-premises, and hybrid environments.

  • Implements and maintains automations scripts and tools using platforms such as Hashicorp Vault, Venafi, or similar certificate management systems.

  • Manages, secures, engineers and provides governance for key and certificate management services, including supporting robust, enterprise-grade Public Key Infrastructure (PKI), certificate lifecycle management (CLCM), infrastructure automation and credential management (CMS) systems.

  • Develops and deploys automated processes for the issuance, renewal, revocation, and monitoring of digital certificates across various platforms.

  • Creates design components, develops code, and tests changes using test-driven development methodologies.

  • Implements and maintains an automated certificate renewal program; captures use-cases for certificate revocation, enrollment & renewal processes.

  • Monitors creation of encryption keys to ensure they are protected against modification, and private keys are protected against unauthorized disclosure.

  • Contributes to the design of new Entra ID infrastructure from PKI perspective

  • Defines Trust Strategies and understands security and governance requirements for Certification Authorities.

  • Stays updated with latest trends in PKI, cryptography, and security automation to continuously improve the organization's certificate management strategy.

  • Supports the company's commitment to risk management and protecting the integrity and confidentiality of systems and data.

Minimum Qualifications

  • Education and/or experience typically obtained through the completion of a bachelor's degree in Information Technology, Computer Science, Computer Engineering, Cybersecurity, or related field.

  • 12+ years of IT experience; 8+ years' experience designing, deploying, and supporting PKI environments in a Windows domain.

  • In-depth knowledge of PKI principles with subject matter expertise in developing best practices around standardized management of access controls.

  • Experience deploying internal certificate authorities, issuing external certificates from external certificate authorities and installing certificates on systems, and building out and maintaining certificate authority databases, as well as designing, deploying, and supporting the use of smart cards for system authentication.

  • Sound knowledge and experience in Enterprise Architecture, Strategy, and IT Security.

  • Strong understanding of IAM domain including Access Management, Authentication, and Key Management implementations.

  • Strong experience with PKI automation and Certificate lifecycle management.

  • Demonstrated success at driving large projects and initiatives cross functionally as the central expert.

  • Understanding of IAM relevant technical security skills, such as Identity Governance, Single Sign-On and authentication, Multi-Factor Authentication, Microsoft and AD tools for Access Management and controls, Privileged access management, and AWS security.

  • Advanced understanding of the broader impact of Information Security from a business perspective.

  • Excellent analytical skills with high attention to detail and accuracy.

  • Strong problem-solving skills, with the ability to identify root causes and develop solutions.

  • Excellent leadership, communication, and collaboration skills.

  • Ability to articulate complex technical concepts, both verbal and written to non-technical stakeholders.

  • Strong interpersonal skills, with the ability to work with many levels of management and across multiple lines of business and corporate functions.

  • Experience managing vendors driving SLAs.

  • Ability to guide teams through complex issues and drive resolution for issues.

  • Ability to build project plans, translate directives, and present project deliverables to upper management.

  • Ability to think strategically, balancing long and short-term priorities.

  • Drug screen and background check.

Preferred Qualifications

  • Advanced degree preferred.

  • Relevant certifications (PKI, CISSP, KMS) is a plus.

  • Venafi, DigiCert or other external vendor, and MSCS .

Physical Requirements

Working conditions consist of a normal office environment. Work is primarily sedentary and requires extensive use of a computer and involves sitting for periods of approximately four hours. Work may require occasional standing, walking, kneeling and reaching. Must be able to lift 10 pounds occasionally and/or negligible amount of force frequently. Requires visual acuity and dexterity to view, prepare, and manipulate documents and office equipment including personal computers. Requires the ability to communicate with internal and/or external customers.

The above job description is not intended to be an all-inclusive list of duties and standards of the position. Incumbents will follow instructions and perform other related duties as assigned by their supervisor.

Early Warning Services is an affirmative action and equal opportunity employer.

The base pay scale for this position in:

Phoenix, AZ/ Chicago, IL in USD per year is: $180,000 - $220,000.

New York, NY/ San Francisco, CA in USD per year is: $190,000 - $230,000.

Additionally, candidates are eligible for a discretionary incentive plan and benefits.

This pay scale is subject to change and is not necessarily reflective of actual compensation that may be earned, nor a promise of any specific pay for any specific candidate, which is always dependent on legitimate factors considered at the time of job offer. Early Warning Services takes into consideration a variety of factors when determining a competitive salary offer, including, but not limited to, the job scope, market rates and geographic location of a position, candidate's education, experience, training, and specialized skills or certification(s) in relation to the job requirements and compared with internal equity (peers). The business actively supports and reviews wage equity to ensure that pay decisions are not based on gender, race, national origin, or any other protected classes.

Some of the Ways We Prioritize Your Health and Happiness

  • Healthcare Coverage-Competitive medical (PPO/HDHP), dental, and vision plans as well as company contributions to your Health Savings Account (HSA) or pre-tax savings through flexible spending accounts (FSA) for commuting, health & dependent care expenses.
  • 401(k) Retirement Plan-Featuring a 100% Company Safe Harbor Match on your first 6% deferral immediately upon eligibility.
  • Paid Time Off -Unlimited Time Off for Exempt (salaried) employees, as well as generous PTO for Non-Exempt (hourly) employees, plus 11 paid company holidays and a paid volunteer day.
  • 12 weeks of Paid Parental Leave
  • Maven Family Planning - provides support through your Parenting journey including egg freezing, fertility, adoption, surrogacy, pregnancy, postpartum, early pediatrics, and returning to work.

AndSOmuch more! We continue to enhance our program, so be sure tocheck our Benefits page here for the latest. Ourteamcan share more during the interview process!

Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Early Warning Services, LLC ("Early Warning") considers for employment, hires, retains and promotes qualified candidates on the basis of ability, potential, and valid qualifications without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote equal employment opportunity and affirmative action, in accordance with all applicable federal, state, and municipal laws. The company also prohibits discrimination on other bases such as medical condition, marital status or any other factor that is irrelevant to the performance of our employees.

Applied = 0

(web-67f776f9dc-pvlp6)