3 months ago
Base Salary
$149k - $238k/yr
Responsibilities
- Design, deploy, and operate PKI infrastructure for secure authentication, encryption, and certificate lifecycle management.
- Manage certificates, secrets, encryption keys, trust stores, and access controls, including issuance, renewal, rotation, and revocation.
- Build, maintain, and secure Kubernetes clusters hosting PKI and secrets-management services.
- Automate certificate lifecycle, secret rotation, and infrastructure operations using Infrastructure-as-Code, CI/CD pipelines, and Kubernetes-native tooling.
- Monitor, troubleshoot, and perform root cause analysis and remediation for PKI, certificate, secret, and Kubernetes infrastructure issues.
- Integrate PKI and secrets management into cloud-native applications and services with SRE, platform, security, and engineering teams.
- Maintain PKI architecture documentation, runbooks, operational procedures, security best practices, and disaster recovery procedures.
- Participate in on-call rotations, incident response, and operational improvement initiatives.
Requirements
- 7+ years of experience in infrastructure, platform, SRE, or security engineering roles.
- Strong production experience managing and securing Kubernetes clusters and containerized workloads.
- Hands-on experience with PKI platforms, certificate lifecycle management, secrets management, and encryption technologies.
- Experience with cloud-native security solutions such as AWS KMS, Azure Key Vault, HashiCorp Vault, EJBCA, Smallstep, or Venafi.
- Strong understanding of Linux systems, networking, distributed systems, and Kubernetes security best practices.
- Experience with automation, scripting, Infrastructure-as-Code, and CI/CD pipelines for PKI and infrastructure operations.
- Familiarity with IAM and access management platforms such as Okta, Entra ID, Keycloak, or similar solutions.
- Experience with monitoring, logging, alerting, and troubleshooting distributed infrastructure and security systems.
- Strong communication and collaboration skills across engineering, operations, and security teams.
Benefits
- Hybrid schedule based in the Boston, MA office, onsite Tuesdays through Fridays and remote Mondays unless accommodation is approved.
- Competitive salary and 401k with employer match.
- Discretionary paid time off and paid parental leave for all.
- Medical, dental, and vision plans.
- Fitness programs and emotional and mental wellness support.
- Learning and development programs and office snacks.
