Us3 Consulting
Security Engineer (PKI/IAM)
Us3 ConsultingNetherlands3 days ago
ContractInformation Technology

Role Title: PKI Engineer

Location: Eindhoven, Netherlands


Role Description:

As a PKI Engineer with strong consultancy skills, you will be part of a Scrum (SAFe) team managing and operating the IAM PKI landscape — a platform currently transitioning from on-premises infrastructure to cloud-based solutions.

The team owns the technical design, development, and operations of PKI, cryptography, and certificate management. Automation and self-service are key pillars to enhance user experience without compromising security.

You will collaborate closely with the Product Owner, Scrum Master, and IAM System Architect to ensure robust, scalable, and secure PKI services.


Key Responsibilities:

  • Develop, manage, and evolve the PKI landscape to meet business and security objectives.
  • Provide technical support and solutions for PKI-related issues and user queries.
  • Contribute to the IAM PKI roadmap in alignment with organizational goals.
  • Validate and implement functional and non-functional requirements in line with IT and security principles.
  • Design, develop, and configure new IAM functionalities in adherence to architectural standards.
  • Promote standardization, automation, and proactive improvements in PKI operations.
  • Participate actively in Scrum/SAFe ceremonies and collaborate in a DevOps setup.
  • Coordinate and ensure delivery of designed capabilities according to specifications.
  • Drive CI/CD-based automation and continuous improvement initiatives.
  • Create and maintain technical documentation for PKI processes, procedures, and configurations.


Required Skills and Experience:

  • 6–8 years of professional experience in PKI engineering and security infrastructure.
  • Strong expertise with PKI, certificates, OpenSSL, TLS stacks, and related protocols (SCEP, EST, ACME).
  • Deep understanding of cryptography and algorithms such as RSA, DSA, ECC, DH, and AES.
  • Experience with Active Directory, Active Directory Certificate Services (ADCS), NDES, and cloud technologies (Azure AD, Azure Key Vault).
  • Hands-on experience with CyberArk, HSMs, and identity lifecycle automation.
  • Working knowledge of PGP, Docker, Git, GitLab, Terraform, Ansible, Python, and RESTful APIs.
  • Strong background in Windows and Linux systems, and network technologies (DNS, TCP/IP).
  • Proven experience in Agile/DevOps environments, preferably with Scrum/SAFe methodologies.
  • Proficient in developing CI/CD automation pipelines.
  • Familiarity with scripting languages such as PowerShell, Bash, or Python.
  • Strong understanding of security best practices, frameworks, and compliance requirements.
  • Excellent communication and documentation skills, with a consultancy-driven mindset.


Desirable Skills:

  • Experience in test automation within PKI and IAM environments.
  • Knowledge of identity governance, access management, and cloud security.
  • Experience in process improvement and technology modernization initiatives.


Competencies:

  • Public Key Infrastructure (PKI)
  • Cryptography & Certificate Management
  • Cloud Security (Azure)
  • Automation & DevOps (CI/CD, Terraform, Ansible)
  • IAM Systems Integration

Key Skills

Ranked by relevance