Keeper Security

Staff Software Engineer, Certificate Lifecycle Management

Keeper Security
Apply
30 days ago
Remote, United StatesStaff+

Responsibilities

  • Architect and develop certificate lifecycle management capabilities covering discovery, inventory, enrollment, issuance, deployment, renewal, rotation, and revocation.
  • Design scalable backend services and APIs for certificates, machine identities, and cryptographic metadata.
  • Build certificate discovery and automation workflows across cloud platforms, Kubernetes, web servers, load balancers, databases, network devices, and other infrastructure.
  • Design integrations with public and private certificate authorities and enterprise PKI environments.
  • Develop secure workflows for certificate enrollment, key handling, trust validation, and certificate deployment.
  • Address certificate chains, trust stores, expiration, ownership, policy enforcement, and cryptographic compliance challenges.
  • Design automated certificate renewal and remediation systems that minimize operational disruption.
  • Provide technical leadership on PKI architecture, machine identity, cryptographic standards, and certificate automation.
  • Partner with Product and Engineering leadership on strategy, architecture, requirements, and platform direction.
  • Lead technical design reviews, mentor engineers, and establish engineering standards for security-sensitive capabilities.
  • Evaluate emerging PKI, machine identity, and cryptographic technologies and recommend architectural approaches.
  • Use AI-assisted development tools such as Claude, ChatGPT, and GitHub Copilot to improve research, development, debugging, documentation, and efficiency.

Requirements

  • 8+ years of professional software engineering experience, including significant experience building backend, infrastructure, or security-focused systems.
  • Deep hands-on experience with certificate lifecycle management, PKI, machine identity security, or a closely related domain.
  • Strong understanding of X.509 certificates, certificate authorities, certificate chains, trust stores, private keys, and public key cryptography.
  • Experience with certificate discovery, enrollment, issuance, deployment, renewal, rotation, revocation, and expiration management.
  • Knowledge of ACME, SCEP, EST, OCSP, CRLs, and TLS.
  • Strong backend software engineering experience using Java, Go, Python, C++, C#, or similar languages.
  • Experience designing scalable APIs, distributed systems, and automation workflows.
  • Experience integrating with enterprise PKI systems, certificate authorities, cloud platforms, or infrastructure technologies.
  • Understanding of secure key handling, authentication, authorization, and cryptographic trust.
  • Experience with cloud-native and enterprise infrastructure environments.
  • Ability to lead architecture discussions and make tradeoffs across security, scalability, reliability, and usability.
  • Proven ability to mentor engineers and influence technical direction across teams.
  • Ability and willingness to use AI-assisted tools for engineering, research, debugging, prototyping, and documentation.
  • Bachelor’s degree in Computer Science, Engineering, or a related field, or equivalent practical experience.
  • Preferred experience with commercial certificate lifecycle management, PKI, or machine identity platforms.
  • Preferred familiarity with Keyfactor, DigiCert, Venafi, AppViewX, Sectigo, or similar technologies.
  • Preferred experience with Microsoft Active Directory Certificate Services and other enterprise certificate authority environments.
  • Preferred experience automating certificate management across Kubernetes, cloud workloads, CI/CD pipelines, web servers, load balancers, or service meshes.
  • Preferred familiarity with hardware security modules, key management systems, and cloud key management services.
  • Preferred experience with cryptographic policy, algorithm transitions, crypto-agility, non-human identity, secrets management, privileged access management, workload identity, or security-sensitive enterprise SaaS products.

Benefits

  • 100% remote position, with hybrid scheduling available for candidates in the Chicago, Illinois or El Dorado Hills, California metro areas.
  • Medical, dental, and vision coverage, including domestic partnerships.
  • Employer-paid life insurance and supplemental life insurance for employees, spouses, and children.
  • Voluntary short-term and long-term disability insurance.
  • Roth or traditional 401(k).
  • Generous paid time off, including paid bereavement and jury duty leave.
Keeper Security

About Keeper Security

501-1,000 employees

Keeper Security builds a cloud-based, zero-knowledge platform for password management, secrets management, privileged access management and secure remote connections for individuals and organizations. The privately held company, founded in 2011 and headquartered in Chicago, sells its KeeperPAM suite as subscription software, is published in 23 languages and sold in over 150 countries, and supports integrations with common identity providers and enterprise tech stacks.

Contact me