S

Senior PKI & Cloud Security Engineer (Full-time)

Visa Sponsorship
Apply Now
AI Summary

Lead the design, development, and maintenance of mission-critical PKI and cloud security services for a Fortune 500 and state government client. Own end-to-end cryptographic systems, secure APIs, and key management lifecycle while ensuring compliance with industry standards. Collaborate cross-functionally to deliver scalable, high-assurance solutions for connected vehicle ecosystems.

Key Highlights
Own end-to-end PKI and cryptographic systems for connected vehicle ecosystems
Design, develop, and secure RESTful APIs for certificate lifecycle management, HSM integration, and hybrid encryption
Lead full lifecycle from requirements gathering to deployment, monitoring, and post-launch support
Key Responsibilities
Design and implement PKI and key management services for connected vehicle ecosystems, including certificate issuance, revocation, and lifecycle management
Develop and maintain secure RESTful APIs and microservices using server-side languages (Java, Python, C#) for cryptographic operations and integration with HSMs
Collaborate with cross-functional teams to align architecture, integrate front-end components, and ensure compliance with NIST, OWASP, and ISO standards
Manage deployment, monitoring, security hardening, and disaster recovery for cloud and on-premises applications
Lead cryptographic engineering efforts, including hybrid encryption (AES), post-quantum readiness, and PKI policy enforcement
Technical Skills Required
Public Key Infrastructure (PKI) Cryptographic Algorithms & Standards (RSA, ECC, X.509, PKCS) Cloud Security & Infrastructure (Kubernetes, Google Cloud Platform)
Benefits & Perks
Visa and permanent residency sponsorship assistance
Long-term position with direct client engagement
Nice to Have
Experience with in-vehicle network architecture and protocols
Familiarity with ACME, CRL/OCSP, OAuth, and mTLS for access control
2+ years deploying cloud infrastructure with Kubernetes/OpenShift and managing SQL/NoSQL databases

Job Description


Title: Public Key Infrastructure (PKI) Engineer (Or) Cloud Security Engineer (only W2 Position – No C2C Accepted)


Description: STG is a SEI CMMi Level 5 company with several Fortune 500 and State Government clients. STG has an opening for Public Key Infrastructure (PKI) Engineer (Or) Cloud Security Engineer.


Please note that this project assignment is with our own direct clients. We do not go through any vendors. STG only does business with direct end clients. This is expected to be a long-term position. STG will provide immigration and permanent residency sponsorship assistance to those candidates who need it.


Experience Required:

  • The Product Cybersecurity PKI & Key Management Security Services team generates, distributes, stores, and manages lifecycle for the cryptographic keys and certificates in the vehicle product ecosystem. This includes developing and maintaining in-house APIs and web services to provide confidentiality, integrity and authenticity protection for various use cases and features in the product ecosystem. We are seeking an exceptional Software Engineer specializing in Public Key Infrastructure (PKI) and secure API services to own the end-to-end lifecycle of mission-critical cryptographic systems. You will design, build, deploy, and maintain high-assurance PKI and security service APIs that power certificate issuance, lifecycle management, revocation, and integration for the connected vehicle product ecosystem. Employees in this job function develop and maintain the back-end/ server-side parts of an application, typically consisting of APIs, databases and other services containing business logic. They work with various languages and tools to create and maintain services on-prem or in the cloud. Key Responsibilities: 1. Engage with customers to understand their use-cases and requirements 2. Solve complex problems by designing, developing, and delivering using various tools, languages, frameworks, and technologies 3. Align with architecture guidelines for unified and coherent approach to development 4. Design, develop, and deliver new code using various tools, languages, frameworks, and technologies 5. Develop and maintain back-end applications like APIs and microservices using server-side languages like Java, Python, C#, etc. 6. Collaborate with front-end developers to integrate user interface elements and with cross functional teams like product owners, designers, architects etc. 7. Manage application deployment to the cloud or on-prem, health and performance monitoring, security hardening and disaster recovery for deployed applications 8. Manage data storage and retrievals in applications by utilizing database technologies such as Oracle, MySQL, MongoDB, etc. 9. Promote improvements in programming practices, such as test-driven development, continuous integration, and continuous delivery 10. Optimize back-end infrastructure and deployment practices to improve application resiliency and reliability 11. Support security practices to safeguard user data including encryption and anonymization 12. Write and manage code that interfaces with HSMs to apply cryptography and issue certificates

Skills Required:

  • Computer engineering, Software Development Lifecycle, Software Testing, PostgreSQL, Software Documentation, Application Development, Bouncy Castle Cryptographic, Cloud Infrastructure, Google Cloud Platform, .NET Core, .NET Developer, Cyber Security, C#, Application Testing, Agile Software Development
  • Kubernetes, Technical Communication, Technical Requirements, Technical Documentation, Application Architect, Technical Analysis
  • Software engineering/development and secure coding practices using object oriented programming Strong knowledge and applicability of software architecture, development, methodologies and design principles including test-driven development Strong understanding and ability to apply cryptographic algorithms and standards in software, including RSA, ECC, AES, X.509 Proven track record of owning customer-facing products from ideation to general acceptance, and flexibility to manage multiple projects and deliverables throughout lifecycle. Bachelor's degree in Computer Science / Engineering

Experience Preferred:

  • 2+ years of experience deploying and maintaining cloud infrastructure with Kubernetes or OpenShift, and managing database instances (SQL Postgres, Redis, MongoDB) 2+ years building, maintaining, and integrating with production PKI systems and supporting cryptographic interfaces. Experience and understanding of industry security standards and applying them in our software solutions and processes, including NIST, OWASP, and relevant ISO and IEEE standards. Strong knowledge and applicability of software architecture, development, methodologies and design principles including test-driven development Familiarity with in-vehicle network architecture, modules, and protocols
  • Lead the full lifecycle of PKI and Key Management services supporting our vehicle products and ecosystem — lead customer requirements gathering, architecture design, implementation, testing, deployment, monitoring, and post-launch support. Design and develop robust, secure, and scalable RESTful APIs and web services for various features and use cases: CRL/OCSP, ACME, Certificate Issuance, message encryption/decryption, software signing, key rotation and certificate lifecycle management, HSM integration with PKCS11. Implement access control methods that enforce least privilege access principles using OAuth or mTLS.
  • Cryptographic Engineering: Implement and harden PKI and key services with deep knowledge of PKI industry standards, X.509, PKCS standards, elliptic curve cryptography (ECC) and RSA, post-quantum readiness, and hardware security module CSP integration.
  • Apply hybrid encryption techniques with AES. Define and enforce PKI certificate policies and certificate profiles. Infrastructure and CI/CD Integration: Release and Deploy your apps through build server, CI/CD pipeline, and infrastructure involving on-premises and cloud Kubernetes Security & Compliance: Monitor and address findings regularly in code base through SAST, DAST, software quality and security vulnerability scanning. Drive and support testing at each stage of the development process.


Public Key Infrastructure (PKI) Engineer (Or) Cloud Security Engineer is based in Dearborn, MI. A great opportunity to experience the corporate environment leading personal career growth.


Resume Submittal Instructions: Interested/qualified candidates should email their word formatted resumes to Vasavi Konda – vasavi.konda(.@)stgit.com and/or contact @(Two-Four-Eight) Seven- One-Two – Six-Seven-Two-Five (@248.712.6725). In the subject line of the email please include: First and Last Name: Public Key Infrastructure (PKI) Engineer (Or) Cloud Security Engineer.


For more information about STG, please visit us at www.stgit.com.

Sincerely,

Vasavi Konda| Recruiting Specialist

“Opportunities don't happen, you create them.”

Systems Technology Group (STG)

3001 W. Big Beaver Road, Suite 500

Troy, Michigan 48084

Phone: @(Two-Four-Eight) Seven- One-Two – Six-Seven-Two-Five: @248.712.6725(O)

Email: vasavi.konda(.@)stgit.com



Similar Jobs

Explore other opportunities that match your interests

AI Architect (AVP/VP)

Devops
4h ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Mid-Senior level

wissen technology

United State
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Not Applicable

typesafe ai

United State
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Not Applicable

blue river technology

United State

Subscribe our newsletter

New Things Will Always Update Regularly