PKI / TLS Certificate Engineer

Merrifield, VA

Apply Apply with LinkedIn
Save

Type: Contract

Experience: 0

Category: Information Technology

Contractor Work Model: Remote

Brand: System One

Job ID: 348451

Date Posted: 03/27/2026

Shortcut: http://jobs.systemone.com/ry7Fnk


Job Title: PKI / TLS Certificate Engineer
Location: REMOTE
Pay Rate: Open to Both C2C and W2 options
Position Type: Multiyear Contract


Certificate Management Engineering (CME) is seeking a DevOps-focused contractor to support Operations and Automation workstreams across enterprise certificate lifecycle management. This role will help design, build, and run automation that reduces manual certificate work, improves reliability, and strengthens security outcomes-covering X.509 certificate inventory/renewal automation, notification and escalation workflows, and integrations with operational ticketing processes.
The contractor will also support modernization initiatives that expand CME capabilities into Kubernetes certificate automation and code/container signing, including integration patterns and tooling used to manage certificates and machine identities in cloud/Kubernetes environments.

Key Responsibilities:
Operations Enablement (Reliability)

• Support day-to-day operational execution for certificate lifecycle work (issuance, renewal, replacement, decommission) with a strong focus on reducing manual handling and preventing certificate-expiration risk.
• Enhance operational workflows that include scripted Outlook notification/escalation logic and operational integrations (e.g., ticket/task creation).
• Partner with engineering and operations stakeholders to standardize repeatable procedures and ensure traceability of changes.
Automation Engineering (Build and Scale)
• Develop and maintain automation that expands certificate coverage and reduces manual renewal effort, building on existing code-based automations and monitoring/notification patterns.
• Implement or improve automation around certificate deployment patterns in modern platforms, including Kubernetes environments using components such as TLS for Kubernetes (TLSPK) and cert-manager.
• Contribute to automation patterns for code/container signing processes and pipelines, helping establish consistent standards and repeatable workflows.
Platform & Tooling Support
• Support and enhance automations and operational improvements for CyberArk (formerly Venafi) Certificate Manager within CMEs ecosystem.
• Assist in enabling cloud/Kubernetes certificate management approaches that leverage machine identity management tooling referenced by the team (e.g., Workload Identity Manager / Venafi Firefly references in CME materials).

Must-Have Qualifications (Required)
• Certificates / X.509 lifecycle management experience (request/issue/renew/replace/decommission, inventory/monitoring, risk reduction).
• PKI fundamentals (CAs, chains, key usage, SANs, revocation, policy constraints; ability to troubleshoot certificate path and deployment issues).
• PowerShell (advanced scripting for automation, error handling, logging, packaging, scheduling, and secure credential handling).
• DevOps/automation mindset with production support experience (building reliable runbooks, monitoring/alerting hooks, and operational handoffs).
• Ability to work cross-functionally with security, infrastructure, and platform teams to deliver automation that is operationally supportable.

Nice-to-Have Skills (Preferred)
• Venafi Trust Protection Platform / CyberArk Certificate Manager - Self Hosted
• CyberArk Certificate Manager - Kubernetes
• CyberArk Code Sign Manager
• Kubernetes cert-manager
• SPIFFE / SPIRE
• ServiceNow
• Python
• Ansible
• Golang
• Bash
• vcert

Deliverables & Success Measures
• Operational reduction of manual certificate tasks via automation improvements and measurable decreases in human touchpoints (especially renewal and deployment workflows).
• Improved notification/escalation effectiveness and reduced surprise expirations via scripted communication and integrated tasking.
• Working automation patterns for Kubernetes certificate management using components like cert-manager and related Kubernetes TLS enablement approaches referenced by CME.
• Supportable automation artifacts: source-controlled scripts, documentation/runbooks, and operational readiness for change-management expectations.

Working Relationships
• Works closely with CME engineering leadership and peer engineers supporting certificate automation, Kubernetes enablement, and signing initiatives.
• Coordinates with platform and change stakeholders to ensure automation is production-ready and appropriately documented.


System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.


System One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law.

Ref: #851-Rockville-S1

  • Senior Kubernetes Engineer / Platform Administrator

    Washington, District Of Columbia

    Senior Kubernetes Engineer / Platform Administrator Washington, DC (Bolling AFB) - onsite Active Top Secret with SCI eligibility We are seeking a highly experienced Senior Kubernetes Engineer / Platform Administrator to lead the design, deployment, and...

    Date Posted: 03/20/2026 Recommended

  • AEM Developer Architect

    Centennial , Colorado

    Tittle: AEM Developer Architect Location : Centennial, Colorado Mode : Hybrid (3days in office – 2 days remote) Duration : Contract to Hire Years Of Exp Required : 14+ Years Roles/Responsibilities: Design and implement enterprise-grade AEM solutions wi...

    Date Posted: 04/10/2026 Recommended

  • Mid Level DevOps Engineer

    McLean, VA

    Mid-Level DevOps Software Analyst Remote Candidates must be able to work without sponsorship W2 Employment only What You Will Do: As the DEVOPS Software Analyst you will be responsible for mission critical support of all department owned applications a...

    Date Posted: 04/27/2026 Recommended

  • Senior DevOps Engineer

    McLean, VA

    Sr. DevOps Engineer Candidates must be able to work in the U.S. without sponsorship 100% Remote W2 ONLY As the DEVOPS Software Analyst you will be responsible for mission critical support of all department owned applications and their infrastructure. Y...

    Date Posted: 04/28/2026 Recommended

  • Software Development Engineer (SDET)

    Merrifield, VA

    Job Title: Senior Software Development Engineer (SDET) Location: Hybrid Work Model Reporting to Vienna, VA, Pensacola, FL, San Diego, CA Pay Rate: Open to Both C2C and W2 options Position Type: Multiyear Contract Responsibilities Work with engineers to...

    Date Posted: 03/20/2026 Recommended

  • DevSecOps Engineer (AWS Cloud)

    Gaithersburg, MD

    DevSecOps Engineer (AWS Cloud) Hybrid-Remote Gaithersburg, MD Contract-to-Hire Compensation: $97/hour Security Clearance: Public trust required to start Overview We’re hiring a Mid-Level DevSecOps Engineer to help build and scale a Common Automation Pl...

    Date Posted: 04/28/2026 Recommended

  • Bus Systems Analyst Lead

    Farmers Branch, TX

    Title: Business Systems Analyst Lead Position Location: Dallas, TX/Pittsburgh, PA/ Cleveland, OH - 5 Days Onsite Function of the Group: Mitigates Risk Initiatives/Projects: The resource will assist with ongoing change requests, automation enhancements,...

    Date Posted: 03/09/2026 Recommended

  • AEM Developer Architect

    Centennial , Colorado

    Job Title: AEM Developer Architect Location: Centennial, Colorado Type: Contract To Hire Contractor Work Model: Onsite Responsibilities Lead the design and development of enterprise-grade AEM solutions focusing on modularity, scalability, and maintaina...

    Date Posted: 03/18/2026 Recommended

  • AEM Developer Architect

    Centennial , Colorado

    Job Title: AEM Developer Architect Location: Centennial, Colorado, United States Type: Contract To Hire Contractor Work Model: Onsite Hours: 40.0 Responsibilities Lead the design and development of enterprise-grade AEM solutions focusing on modularity,...

    Date Posted: 04/03/2026 Recommended

  • AI Mobile/ RPA SME

    Hampton, Virginia

    Job Title: AI / RPA Solutions SME (TS/SCI) Location: Hampton, VA Type: Direct Hire Work Model: Onsite Clearance: TS/SCI Required Overview We are seeking a TS/SCI-cleared AI / RPA Solutions SME to support Air Force modernization efforts by building and ...

    Date Posted: 04/21/2026 Recommended

  • AI RPA Solutions Architect

    Hampton , Virginia

    Title: AI/RPA Solutions Architect Location: Langley, AFB – On-site full-time Clearance: Active TS/SCI Contact: Crystal.dinnocenti@systemone.com POSITION OVERVIEW We are seeking a highly skilled AI/ML Engineer with Robotic Process Automation (RPA) exper...

    Date Posted: 04/01/2026 Recommended

  • UI UX Experience Designer Sr - Contractor

    Lakewood, CO

    Experience Designer Sr – Contractor Job ID: 71624 Work Type: Onsite (5 days/week) Duration: May 25, 2026 – Mar 31, 2027 (Potential Extension / Contract-to-Hire) Location (Preference Order) Pittsburgh, PA (Highly Preferred) Phoenix, AZ | Denver, CO | St...

    Date Posted: 04/23/2026 Recommended

  • Windows Administrator (Secret Clearance)

    Fort Belvoir, VA

    WINDOWS ADMINISTRATOR (SECRET CLEARANCE REQUIRED) Location: Fort Belvoir, VA Work model:Preferred onsite in Fort Belvoir, VA (for mission support), but open to hybrid or fully remote for the right candidate. Employment Type: Direct Hire Compensation: $...

    Date Posted: 03/31/2026 Recommended

  • Data Engineer (MDM specialization)

    Salt Lake City, Utah

    Data Engineer (MDM specialization) Location: Salt Lake City, UT – Onsite at client five days per week Start Date: ASAP End Date: one year, likely extension. (Conversion after six months.) Job Description: Client is seeking a highly skilled Data Enginee...

    Date Posted: 04/03/2026 Recommended

  • Business Systems Analyst

    Phoenix, AZ

    Position Title: Business Systems Analyst Position Location: Phoenix ,AZ Duration – 1 year Employment Type - This is for W2 Employment Industry background: Experience in governance, risk, compliance, or IT audit Roles and Responsibilities: Someone needs...

    Date Posted: 03/11/2026 Recommended

  • Quality Engineer

    Merrifield, VA

    Job Title: Quality Engineer (manual and automation) Location: Vienna, VA Work Model: hybrid, 3 days onsite Pay rate: W2 and established 1099 options Position type: multiyear contract We are looking for candidates with 8-10 years of professional experie...

    Date Posted: 04/28/2026 Recommended

  • Network Monitoring System Engineer

    Woodlawn, Maryland

    Job Title: Network Monitoring System Engineer Location: Woodlawn, Maryland Type: Contract Contractor Work Model: Hybrid Hours: 40 Security Clearance: Must be able to obtain US Public Trust Overview System One is seeking a Senior Network Monitoring Syst...

    Date Posted: 04/09/2026 Recommended

  • Senior Cloud Security Specialist (API) - onsite

    Washington, DC

    Senior Cloud Security Specialist (API) Washington, DC – onsite US citizenship required per government contact Must be able to obtain Public Trust clearance Type: Multi-year Contract Open to W2 and C2C Deadline to apply: May 5th We are seeking a Senior ...

    Date Posted: 04/24/2026 Recommended

  • Data Engineer Sr - Contractor

    Farmers Branch, TX

    Data Engineer Sr. Provide locations: Dallas, TX Length of Assignment: 1 year ROLE/RESPONSIBILITIES: Coordinate the collection, normalization and analysis of datasets across multiple data platforms. • Assist in designing and building data service infras...

    Date Posted: 04/14/2026 Recommended

  • Linux Administrator

    Fort Belvoir, VA

    Job Title: Linux Administrator Location: Fort Belvoir, VA Type: Direct Hire Contractor Work Model: Onsite Security Clearance: Active Secret Clearance Required Responsibilities Support, maintain, and enhance Linux-based systems and services that enable ...

    Date Posted: 03/30/2026 Recommended

  • Procurement Specialist

    Houston, TX

    Procurement Specialist II Houston, TX 77042 System One is seeking two Procurement Specialists with experience in the heavy industrial construction sector to be responsible for sourcing medium and high criticality materials and subcontracts across the f...

    Date Posted: 04/20/2026 Recommended

  • Lead Manufacturing Engineer

    Lakewood, NJ

    Job Title: Engineering Manager, Manufacturing & Projects Location: Lakewood, New Jersey Type: Direct Hire Compensation: $110,000 - $120,000 Contractor Work Model: Onsite (Lakewood, NJ) Hours: Monday - Friday, 7:00 AM - 3:30 PM Engineering Manager, Manu...

    Date Posted: 04/21/2026 Recommended

  • Case Manager

    Los Angeles, CA

    Job Title: Case Manager Location: Los Angeles, CA Type: Contract Compensation: $23 hourly Contractor Work Model: Onsite Time-Limited Subsidy (TLS) Case Manager The TLS Case Manager provides housing-focused case management to individuals and families ex...

    Date Posted: 04/22/2026 Recommended

  • Palantir Foundry Data Engineer & Architect

    NA, VA

    Job Title: Senior Palantir Foundry Data Engineer & Architect Locations: Arlington, VA | McLean, VA | New York, NY | Chicago, IL | San Antonio, TX | Atlanta, GA | Type: Remote – Must be willing to travel up to 25% Time Type: Full-time Clearance: Ability...

    Date Posted: 04/22/2026 Recommended

  • Lead Healthcare Business Analyst

    Reston, VA

    Job Title: Lead Healthcare Business Analyst Location: Reston, VA Type: Contract To Hire Compensation: $70/HR Contractor Work Model: Hybrid No C2C We’re searching for a Lead Business Analyst with deep experience in the health?insurance industry, ideally...

    Date Posted: 04/01/2026 Recommended

  • Application Architect

    Bethesda, MD

    Job Title: Application Architect Location: Bethesda, MD Type: Permanent salaried position Compensation: 170- 190K Contractor Work Model: Hybrid (2 to 3 days on site in Bethesda MD) The Senior Application Architect is responsible for developing and evol...

    Date Posted: 04/17/2026 Recommended

  • Project Manager - HVAC

    Mobile, Alabama

    System One is seeking a Project Manager to manage HVAC shipbuiding projects to manage operational resources necessary to meet contractual and company related obligations of the project to ensure profitability. The Project Manager will provide day-to-da...

    Date Posted: 03/26/2026 Recommended

  • Process Automation & Learning Technology Solutions Consultant

    Indianapolis, IN

    Job Title: LMS Administrator (AI & Automation) Location: Remote Hours/Schedule: Monday–Friday, 8 am to 5 pm Compensation: $65-69/hour DOQ Type: 18 month contract Overview We’re hiring an LMS Administrator (AI & Automation) to modernize and optimize ent...

    Date Posted: 04/28/2026 Recommended

  • Research Analyst

    Baltimore, Maryland

    Research Analyst Location: Baltimore, Maryland | Onsite Contract To Hire Compensation: $34-$36/h Role Overview This is a data-driven marketing analyst/research support role focused on turning campaign and business data into clear, actionable insights. ...

    Date Posted: 04/23/2026 Recommended

  • Electrical, Instrumentation, and Controls Technician

    Spring Grove, Pennsylvania

    Job Title: Electrical, Instrumentation, and Controls Technician Location: Spring Grove, Pennsylvania Type: Direct Hire Base Hourly Rate: E/I & C Level I: $42.32; E/I & C Note: all new hires begin at Level I. Advancement to Level II & III is dependent o...

    Date Posted: 04/16/2026 Recommended