At a Glance
- Tasks: Design and implement secure Microsoft PKI solutions for enterprise environments.
- Company: Join a leading tech consultancy transforming businesses with innovative solutions.
- Benefits: Flexible contract work, competitive pay, and opportunities to enhance your skills.
- Other info: Collaborative team environment with opportunities for professional growth.
- Why this job: Make a real impact by securing critical systems and enhancing operational efficiency.
- Qualifications: Strong experience in Microsoft AD CS, PKI concepts, and security governance.
The predicted salary is between 50000 - 70000 £ per year.
Windsor and Maidenhead, United Kingdom | Posted on 18/05/2026
VE3 is a technology and business consultancy focused on delivering end-to-end technology solutions and products. We have successfully serviced enterprises across multiple markets, including the public and private sectors. Our services span all aspects of business, providing a holistic approach to managing an organization. We are committed to providing technical innovations and tools that empower organizations with critical information to facilitate decision-making that results in business transformation through cost savings and increased operational efficiency. Our commitment to quality is adopted throughout the organization and sets the foundation for delivering our full suite of capabilities.
Role Purpose
We are looking for an experienced Microsoft PKI / AD CS Specialist to assess, design and support implementation of an on-premise certificate lifecycle management solution for a Microsoft-based enterprise environment.
Key Responsibilities
- Current-State PKI Assessment
- Review the existing on-premise Microsoft CA/AD CS configuration.
- Assess CA hierarchy, root/intermediate CA design, issuing CA configuration and certificate policies.
- Review certificate templates, issuance permissions, auto-enrolment settings and approval workflows.
- Assess CRL, OCSP, revocation checking and certificate chain availability.
- Review current server certificate usage across domain-joined, internal, SQL/SSRS and DMZ/workgroup servers.
- Identify current risks, gaps and improvement areas in certificate lifecycle management.
- Target PKI Architecture
- Design a secure and supportable Microsoft PKI / AD CS target architecture.
- Define certificate templates for internal server authentication, SQL Server, SSRS, application portals and internal HTTPS endpoints.
- Define certificate validity periods, renewal periods, key lengths, algorithms, SAN naming standards and subject naming conventions.
- Define auto-enrolment patterns for domain-joined Windows servers.
- Define secure issuance and renewal options for non-domain-joined DMZ/workgroup servers.
- Recommend whether the existing CA can be reused, remediated or whether additional configuration is required.
- Produce practical design documentation suitable for infrastructure, security and operations teams.
- Certificate Lifecycle and Automation
- Define certificate request, approval, issuance, deployment, renewal and revocation processes.
- Design GPO-based certificate auto-enrolment where appropriate.
- Advise on scripted or manual certificate issuance patterns where auto-enrolment is not suitable.
- Define monitoring and alerting requirements for expiring certificates.
- Support integration with operational processes, including change management, CAB, maintenance windows and service validation.
- Advise on whether third-party certificate lifecycle tools are required or whether native Microsoft capabilities are sufficient.
- Security and Compliance
- Ensure the PKI design aligns with security best practice and audit expectations.
- Define auditable controls for certificate issuance, renewal, revocation and administrative access.
- Support ISO 27001-style evidence requirements, including proof that certificates are monitored, renewed and controlled.
- Identify and document risks associated with self-signed certificates, public wildcard certificate reuse, weak cryptography, unmanaged certificates and orphaned certificate owners.
- Produce an exception handling model for systems that cannot follow the standard certificate lifecycle process.
- Proof of Concept and Implementation Support
- Lead or support a PoC using selected non-production servers.
- Validate certificate enrolment and renewal for domain-joined servers.
- Support testing of certificate bindings for internal web services, SQL Server and SSRS.
- Validate trust chains, certificate stores, CRL accessibility and service connectivity.
- Produce implementation runbooks and operational handover materials.
- Support production rollout planning, including change records, test plans, rollback/fix-forward approach and post-change validation.
Required Skills and Experience
The candidate should have strong hands-on and architectural experience in:
- Microsoft AD CS: Strong experience designing, configuring or assessing Microsoft Active Directory Certificate Services.
- Windows PKI: Strong understanding of PKI concepts, certificate chains, root/intermediate CAs, revocation, CRLs, OCSP and certificate templates.
- Active Directory: Strong understanding of AD, GPOs, domain-joined servers, permissions and security groups. Practical experience with certificate auto-enrolment using Group Policy.
- Certificate templates: Ability to design and secure templates for server authentication and internal TLS use cases.
- Windows Server: Strong knowledge of certificate stores, service bindings and Windows Server security.
- Internal TLS: Experience securing internal server-to-server communication using CA-issued certificates.
- DMZ/workgroup servers: Experience designing certificate processes for non-domain-joined or isolated servers.
- Security governance: Familiarity with audit, evidence, vulnerability scanning and ISO 27001-style control expectations.
- Documentation: Ability to produce clear architecture, assessment, runbook and operational documentation.
- Experience with SQL Server and SSRS certificate requirements.
- Experience with IIS certificate bindings.
- Experience with load balancers, reverse proxies or DMZ certificate patterns.
- Experience with certificate lifecycle management tools.
- PowerShell scripting experience for certificate inventory, reporting or automation.
- Experience working in regulated, public sector or security-conscious environments.
- Knowledge of Entra ID application certificates and secrets would be useful, but is not the primary focus of this role.
- Experience supporting CAB/change-controlled production environments.
Microsoft PKI / AD CS Specialist (Contract/Freelance) in Maidenhead employer: Data Controller, VE Ltd
VE3 is an exceptional employer that fosters a collaborative and innovative work culture, providing employees with the opportunity to engage in meaningful projects that drive business transformation. Located in Windsor and Maidenhead, we offer competitive benefits, a commitment to professional development, and a supportive environment that encourages growth and creativity, making it an ideal place for skilled professionals looking to make a significant impact in technology and business consultancy.
StudySmarter Expert Advice🤫
We think this is how you could land Microsoft PKI / AD CS Specialist (Contract/Freelance) in Maidenhead
✨Tip Number 1
Network like a pro! Attend industry meetups, webinars, or local tech events. It's all about making connections and getting your name out there. You never know who might have the inside scoop on a job opportunity!
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your projects related to Microsoft PKI and AD CS. This gives potential employers a taste of what you can do and sets you apart from the crowd.
✨Tip Number 3
Prepare for interviews by practising common questions specific to PKI and AD CS. We recommend doing mock interviews with friends or using online platforms to get comfortable discussing your expertise and experiences.
✨Tip Number 4
Apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who take the initiative to connect directly with us.
We think you need these skills to ace Microsoft PKI / AD CS Specialist (Contract/Freelance) in Maidenhead
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Microsoft PKI / AD CS Specialist role. Highlight your relevant experience with Microsoft AD CS, PKI concepts, and any hands-on projects you've worked on. We want to see how your skills match what we're looking for!
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about this role and how your background makes you the perfect fit. Don’t forget to mention specific projects or achievements that relate to the job description.
Showcase Your Technical Skills:Since this role is quite technical, make sure to clearly list your skills related to certificate lifecycle management, Windows Server security, and any scripting experience. We love seeing practical examples of how you've applied these skills in past roles.
Apply Through Our Website:We encourage you to apply through our website for the best chance of getting noticed. It helps us keep track of applications and ensures you’re considered for the role. Plus, it’s super easy to do!
How to prepare for a job interview at Data Controller, VE Ltd
✨Know Your PKI Inside Out
Make sure you brush up on your knowledge of Microsoft PKI and AD CS. Be ready to discuss the current-state assessment, CA hierarchy, and certificate policies. Familiarise yourself with common challenges and solutions in certificate lifecycle management, as this will show your expertise and readiness for the role.
✨Prepare Real-World Examples
Think of specific instances where you've successfully designed or implemented PKI solutions. Be prepared to share these examples during the interview, focusing on the challenges you faced, how you overcame them, and the impact of your work. This will demonstrate your practical experience and problem-solving skills.
✨Understand Security Best Practices
Since security is a key aspect of this role, ensure you can discuss how your PKI design aligns with security best practices and compliance requirements. Brush up on ISO 27001 standards and be ready to talk about how you've implemented auditable controls in past projects.
✨Ask Insightful Questions
Prepare thoughtful questions about the company's current PKI setup and future plans. This shows your genuine interest in the role and helps you gauge if the company’s environment aligns with your career goals. Questions about their approach to certificate lifecycle management or security governance can spark engaging discussions.