
Overview
Digital trust infrastructure is the silent foundation of modern government, finance, and critical systems. When it fails, nothing else works. Enovise designs, deploys, and audits PKI and digital trust architectures for sovereign governments, defence agencies, and regulated enterprises — environments where cryptographic integrity and unbroken chain of trust are non-negotiable. As a Senior PKI / Trust Engineer, you will lead the design and implementation of certificate authority hierarchies, hardware security module integrations, and digital identity frameworks that meet the most demanding assurance requirements in the world. This is infrastructure that outlasts administrations and protects what cannot be replaced.
Responsibilities
- Design and implement multi-tier PKI architectures including root CA, issuing CA, and policy CA configurations for sovereign and enterprise clients.
- Deploy and manage HSM infrastructure (Thales Luna, Entrust nShield, or equivalent) for cryptographic key protection.
- Define certificate policies, certificate practice statements, and PKI governance documentation to meet regulatory and sovereign requirements.
- Lead PKI health assessments and trust framework audits for government and financial sector clients.
- Integrate PKI with enterprise identity systems, code signing pipelines, TLS infrastructure, and S/MIME deployments.
- Advise on post-quantum cryptography migration strategies and quantum-resistant algorithm adoption timelines.
- Provide technical leadership and mentoring to PKI engineers and security architects across engagements.
Requirements
- 6+ years of hands-on PKI engineering experience with a track record of delivering enterprise or sovereign-grade deployments.
- Deep knowledge of X.509 standards, certificate lifecycle management, CRL/OCSP, and CT log requirements.
- Experience with Microsoft AD CS, EJBCA, Venafi, or equivalent CA platforms in production environments.
- Strong HSM integration experience — key ceremony design, operator card management, and backup/recovery procedures.
- Understanding of cryptographic protocols: TLS 1.3, S/MIME, code signing, and document signing.
- Ability to produce CPS, CP, and PKI governance documentation to WebTrust or equivalent audit standards.
- Eligibility and willingness to undergo EMEA government security clearance vetting.
Nice to Have
- Experience with NIST SP 800-57 key management guidelines and FIPS 140-2/3 compliance.
- Familiarity with post-quantum cryptography standards (CRYSTALS-Kyber, CRYSTALS-Dilithium, SPHINCS+).
- Experience supporting national PKI or eID programmes.
- CISSP, CISM, or PKI-specific certification from a recognised body.