
Staff Software Engineer, Certificate Lifecycle Management
Keeper SecurityResponsibilities
- Architect and develop certificate lifecycle capabilities covering discovery, inventory, enrollment, issuance, deployment, renewal, rotation, and revocation.
- Design scalable backend services and APIs for certificates, machine identities, and cryptographic metadata across enterprise environments.
- Build certificate discovery and automation workflows across cloud platforms, Kubernetes, web servers, load balancers, databases, network devices, and other infrastructure.
- Design integrations with public and private certificate authorities and enterprise PKI environments.
- Develop secure workflows for certificate enrollment, key handling, trust validation, and certificate deployment.
- Address certificate chains, trust stores, expiration, ownership, policy enforcement, and cryptographic compliance challenges.
- Design automated certificate renewal and remediation systems that minimize operational disruption.
- Provide technical leadership on PKI architecture, machine identity, cryptographic standards, and certificate automation.
- Partner with Product and Engineering leadership on technical strategy, architecture, requirements, and long-term platform direction.
- Lead technical design reviews, mentor engineers, establish engineering standards, and evaluate emerging PKI, machine identity, and cryptographic technologies.
- Use AI-assisted development tools such as Claude, ChatGPT, and GitHub Copilot to improve research, development, debugging, documentation, and engineering efficiency.
Requirements
- 8+ years of professional software engineering experience, including significant experience building backend, infrastructure, or security-focused systems.
- Deep hands-on experience with certificate lifecycle management, PKI, machine identity security, or a closely related domain.
- Strong understanding of X.509 certificates, certificate authorities, certificate chains, trust stores, private keys, and public key cryptography.
- Experience with certificate lifecycle operations including discovery, enrollment, issuance, deployment, renewal, rotation, revocation, and expiration management.
- Strong knowledge of ACME, SCEP, EST, OCSP, CRLs, and TLS.
- Strong backend software engineering experience using Java, Go, Python, C++, C#, or similar languages.
- Experience designing scalable APIs, distributed systems, and automation workflows.
- Experience integrating with enterprise PKI systems, certificate authorities, cloud platforms, or infrastructure technologies.
- Strong understanding of secure key handling, authentication, authorization, and cryptographic trust.
- Experience with cloud-native and enterprise infrastructure environments.
- Ability to lead architecture discussions and make technical tradeoffs across security, scalability, reliability, and usability.
- Proven ability to mentor engineers and influence technical direction across teams.
- Ability and willingness to use AI-assisted tools for engineering, research, debugging, prototyping, and documentation.
- Bachelor’s degree in Computer Science, Engineering, or a related field, or equivalent practical experience.
- Preferred: experience with commercial certificate lifecycle management, PKI, or machine identity platforms.
- Preferred: familiarity with Keyfactor, DigiCert, Venafi, AppViewX, Sectigo, or similar technologies.
- Preferred: experience with Microsoft Active Directory Certificate Services or other enterprise certificate authority environments.
- Preferred: experience automating certificate management across Kubernetes, cloud workloads, web servers, load balancers, or service meshes.
- Preferred: familiarity with hardware security modules, key management systems, and cloud key management services.
- Preferred: experience with cryptographic policy, algorithm transitions, crypto-agility initiatives, non-human identity, secrets management, privileged access management, workload identity, or security-sensitive enterprise SaaS products at scale.
Benefits
- 100% remote position, with hybrid scheduling available for candidates in the Chicago, Illinois or El Dorado Hills, California metro areas.
- Medical, dental, and vision insurance, including domestic partnerships.
- Employer-paid life insurance and supplemental life insurance for employees, spouses, and children.
- Voluntary short- and long-term disability insurance.
- Traditional and Roth 401(k).
- Generous paid time off, including paid bereavement and jury duty leave.
- Above-market annual bonuses.
About Keeper Security
Keeper Security is transforming cybersecurity for millions of individuals and thousands of organizations globally. Built to protect against today’s threats and tomorrow’s challenges, our unified, cloud-native cybersecurity platform is trusted by Fortune 100 companies to protect every user, on every device, in every location. Keeper is a pioneer of zero-knowledge and zero-trust security built for any IT environment. Our core offering, KeeperPAM®, is an AI-enabled, cloud-native platform that protects all users, devices and infrastructure from cyber attacks. Recognized in the Gartner Magic Quadrant for Privileged Access Management (PAM), Keeper continues to lead in cybersecurity innovation, securing passwords and passkeys, infrastructure secrets, remote connections and endpoints with role-based enforcement policies, least privilege and just-in-time access. As threats evolve and environments scale, Keeper is redefining modern cybersecurity to deliver the visibility, control and intelligence organizations need to operate confidently and securely. Our security and compliance standards include: - The longest-standing SOC 2 and ISO 27001 certifications in the industry - FedRAMP and GovRAMP Authorization - FIPS 140-3 validation - SOC 3, PCI DSS and ISO 27001, 27017 and 27018 certification Learn more at keepersecurity.com.