PKI Architect in Corsham

PKI Architect in Corsham

Corsham Temporary 63000 - 77000 £ / year (est.) Home office (partial)
Lucid Support Services Ltd

At a Glance

  • Tasks: Lead the design and implementation of secure PKI services in offline environments.
  • Company: Join a forward-thinking company focused on security and innovation.
  • Benefits: Competitive rate, hybrid work model, and opportunities for professional growth.
  • Other info: Diverse and inclusive workplace with a commitment to equal opportunities.
  • Why this job: Make a significant impact in cryptographic trust services within secure environments.
  • Qualifications: Experience in PKI architecture and strong knowledge of cryptography required.

The predicted salary is between 63000 - 77000 £ per year.

An experienced Public Key Infrastructure (PKI) Architect and Subject Matter Expert (SME) is required to lead the design, build, integration and assurance of PKI services within secure, offline (air gapped) environments. The post holder will provide technical leadership to deliver a robust, resilient and compliant cryptographic trust service in support of a UK secure account, working predominantly from customer sites within controlled environments. The role demands proven experience designing and implementing PKI platforms for high-assurance use cases, including certificate life cycle management, cryptographic policy enforcement, secure key management, and integration with enterprise services and security controls.

Key Responsibilities:

  • Lead the architecture, design and delivery of PKI platforms operating in offline/disconnected networks, ensuring solutions are secure, supportable and auditable.
  • Define and implement PKI components, including (as applicable):
    • Root CA (offline), Issuing CAs, Registration Authorities (RA)
    • OCSP/CRL services and distribution models suitable for disconnected environments
    • Certificate templates, enrolment policies, and certificate life cycle processes
  • Develop secure and repeatable mechanisms for certificate and revocation data transfer into/out of air gapped environments in accordance with approved processes.
  • Establish and maintain cryptographic governance, including certificate policy and certificate practice statements (CP/CPS) where required, and alignment to programme security requirements.
  • Design secure key management processes, including key generation, storage, backup, escrow (if authorised), destruction, and compromise handling.
  • Define operational models, including role separation, dual control, and privileged administration, aligned to security policy and audit requirements.
  • Produce and maintain formal design and assurance documentation and provide technical input into risk assessments and accreditation evidence packs.
  • Support the integration of PKI services with enterprise capabilities (as applicable), including:
    • Microsoft Active Directory Certificate Services (AD CS) and Group Policy distribution
    • 802.1X/NAC, VPN, TLS for internal services, code signing, device identity
  • Provide technical leadership for troubleshooting, incident support, root cause analysis, and continuous improvement of PKI services.
  • Engage with internal and external stakeholders at all levels, including security, infrastructure, delivery teams and customer representatives, primarily on-site within secure facilities.

Required Skills & Experience:

  • Demonstrable experience operating as a PKI Architect or senior PKI SME within complex enterprise environments.
  • Proven experience designing and building PKI platforms in offline/air gapped environments, including handling of:
    • Controlled import/export processes
    • Revocation publishing strategies (CRL/OCSP) for disconnected networks
    • Secure media handling and procedural controls
  • Strong knowledge of PKI concepts and implementation including:
    • X.509 certificates, trust chains, certificate policies, key usage and extended key usage
    • Certificate life cycle management (issue, renew, revoke, recover, replace)
    • CRL/Delta CRL design, OCSP stapling considerations (where applicable)
  • Strong understanding of cryptography fundamentals and operational security, including:
    • Algorithm selection and key sizes appropriate to policy
    • HSM design/operations (preferred), secure key ceremonies, tamper controls
    • Role-based administration, segregation of duties, dual control
  • Experience with designing secure operational models (build, run, audit), including:
    • Break-glass and recovery arrangements
    • Compromise response procedures
    • Monitoring, logging and evidence generation
  • Demonstrable experience producing formal technical documentation, including:
    • High-Level Designs (HLDs)
    • Low-Level Designs (LLDs)
    • Security architecture documentation
    • Standard Operating Procedures (SOPs), runbooks, and key ceremony scripts
  • Strong stakeholder engagement and communication skills, including the ability to brief technical and non-technical audiences.

Government Security Standards:

The post holder must be able to design and assure solutions in alignment with relevant UK Government security policies and guidance, including (as applicable to the programme):

  • JSP 440 - Defence Manual of Security
  • JSP 604 - Network Rules and Design Principles
  • JSP 453 - Information Assurance Policy (where applicable)
  • NCSC Cyber Security Design Principles and applicable NCSC guidance for secure configuration and cryptographic services
  • MOD-aligned Secure by Design principles following NIST framework and MOD Security framework, and evidence-based assurance in support of accreditation

Desirable:

  • Experience working within the Defence and/or Aerospace sector, including delivery into regulated, high-assurance environments.
  • Experience with Microsoft AD CS architectures (offline root, issuing CA tiers, template governance) and/or other enterprise PKI stacks.
  • Experience implementing PKI for:
    • Device identity (workstations/Servers), user authentication, mutual TLS, code signing, S/MIME (as required)
  • Familiarity with HSM operations and assurance requirements and conducting or supporting key ceremonies.

If you are available and interested in this opportunity, please apply for further information. Please note that due to high volumes of applications we are unable to contact every applicant. If you do not hear back from us within 7 days of sending your application, please assume that you have not been successful on this occasion.

At Lucid, we celebrate difference and value diverse perspectives, underpinned by our values 'Honesty, Integrity and Pragmatism'. We are proud to provide equal opportunities in line with our Diversity and Inclusion policy and welcome applications from all suitably qualified or experienced people, regardless of personal characteristics. If you have a disability or health condition and seek support throughout the recruitment process, please do not hesitate to contact us via the details below.

PKI Architect in Corsham employer: Lucid Support Services Ltd

At Lucid, we pride ourselves on being an excellent employer, offering a dynamic work culture that fosters innovation and collaboration. Our remote-first approach allows for flexibility while still providing opportunities for professional growth through diverse project engagements, particularly in the infrastructure and engineering sectors. With a commitment to diversity and inclusion, we ensure that every team member feels valued and empowered to contribute their unique perspectives.

Lucid Support Services Ltd

Contact Details:

Lucid Support Services Ltd Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land PKI Architect in Corsham

Get Engaged in Cybersecurity Communities

Dive into online forums or local meetups, like OWASP events or Cybersecurity conferences. These spaces are packed with pros who can share insights and might even know about temporary roles at places like Lucid Support Services Ltd.

Showcase Your Skills Publicly

Link your GitHub or create a series of blogs sharing your knowledge on cybersecurity topics. It’s a great way to demonstrate your expertise and attract attention from hiring managers, especially when they see your passion in action.

Stay On Top of Temp Opportunities

Keep an eye on platforms that list temporary positions specifically in tech. Websites focusing on contract roles in cybersecurity can lead straight to employers like Lucid Support Services Ltd.

Make Contact with Recruiters Specialising in Cybersecurity

Reach out to recruitment agencies that focus on cybersecurity roles. They often have insights into temporary roles before they’re advertised and can put your name forward to companies like Lucid Support Services Ltd.

We think you need these skills to ace PKI Architect in Corsham

Public Key Infrastructure (PKI) Architecture
Certificate Life Cycle Management
Cryptographic Policy Enforcement
Secure Key Management
Integration with Enterprise Services
X.509 Certificates
Revocation Publishing Strategies (CRL/OCSP)

Some tips for your application 🫡

Show Off Your Technical Skills:In cybersecurity, it's vital to highlight your skills with relevant tools and technologies. Make sure your CV showcases your experience with firewalls, intrusion detection systems, and any cybersecurity frameworks you've worked with. This gives Lucid Support Services Ltd a clear view of your capabilities right off the bat.

Certifications Matter:If you’ve got any cybersecurity certifications, like CompTIA Security+ or CISSP, flaunt them! These not only validate your skills but also show that you’re committed to the field. Add a section to your CV specifically for this, because in a temporary role like this, those credentials can really set you apart.

Tailor Your Cover Letter to the Role:For a temporary position, we want to see your willingness to learn and adapt quickly. Make your cover letter specific to the role at Lucid Support Services Ltd; mention why you’re excited about the opportunity and how it fits your career goals. A personal touch can make a big difference!

Don’t Forget the Soft Skills:In cybersecurity, technical skills are crucial, but so are soft skills like teamwork and communication. Make sure to weave examples of how you've collaborated with teams or communicated complex ideas into your application. This shows that you're not just a tech whizz but also a great team player, perfect for a temporary role at Lucid Support Services Ltd.

How to prepare for a job interview at Lucid Support Services Ltd

Brush Up on Technical Skills

Make sure you’re familiar with the latest cybersecurity tools and techniques, like firewalls, intrusion detection systems, and malware analysis. During the interview with Lucid Support Services Ltd for the PKI Architect, be prepared to discuss specific scenarios where you tackled security threats or vulnerabilities.

Show Your Problem-Solving Prowess

Cybersecurity is all about thinking on your feet. Expect technical questions that require you to demonstrate your problem-solving abilities. You might be presented with a mock security breach scenario, so practising your responses to potential threats can be a game changer!

Demonstrate Your Adaptability

As this is a temporary role, showing that you're adaptable and quick to learn is crucial. Talk about times you've picked up new skills or reacted to changing situations quickly. Employers want to know you can hit the ground running and keep things secure during your short stay at Lucid Support Services Ltd.

Bring Relevant Certifications

If you have any relevant cybersecurity certifications, like CompTIA Security+ or CEH, be sure to mention them. This can really help you stand out during a temporary hiring process, as it showcases your commitment to the field and your readiness to take on the PKI Architect role at Lucid Support Services Ltd.