PKI Architect

PKI Architect

Full-Time 63000 - 77000 Β£ / year (est.) Home office (partial)
Lucid Support Services Ltd

At a Glance

  • Tasks: Lead the design and implementation of secure PKI services in offline environments.
  • Company: Join a leading organisation focused on high-assurance cryptographic solutions.
  • Benefits: Competitive rate, hybrid work model, and opportunities for professional growth.
  • Other info: Engage with diverse teams and enhance your expertise in a dynamic environment.
  • Why this job: Make a significant impact in securing sensitive information with cutting-edge technology.
  • Qualifications: Proven experience in PKI architecture and strong technical leadership skills.

The predicted salary is between 63000 - 77000 Β£ per year.

An experienced Public Key Infrastructure (PKI) Architect and Subject Matter Expert (SME) is required to lead the design, build, integration and assurance of PKI services within secure, offline (air gapped) environments. The post holder will provide technical leadership to deliver a robust, resilient and compliant cryptographic trust service in support of a UK secure account, working predominantly from customer sites within controlled environments. The role demands proven experience designing and implementing PKI platforms for high-assurance use cases, including certificate life cycle management, cryptographic policy enforcement, secure key management, and integration with enterprise services and security controls.

Key Responsibilities:

  • Lead the architecture, design and delivery of PKI platforms operating in offline/disconnected networks, ensuring solutions are secure, supportable and auditable.
  • Define and implement PKI components, including (as applicable): Root CA (offline), Issuing CAs, Registration Authorities (RA), OCSP/CRL services and distribution models suitable for disconnected environments.
  • Develop secure and repeatable mechanisms for certificate and revocation data transfer into/out of air gapped environments in accordance with approved processes.
  • Establish and maintain cryptographic governance, including certificate policy and certificate practice statements (CP/CPS) where required, and alignment to programme security requirements.
  • Design secure key management processes, including key generation, storage, backup, escrow (if authorised), destruction, and compromise handling.
  • Define operational models, including role separation, dual control, and privileged administration, aligned to security policy and audit requirements.
  • Produce and maintain formal design and assurance documentation and provide technical input into risk assessments and accreditation evidence packs.
  • Support the integration of PKI services with enterprise capabilities (as applicable), including: Microsoft Active Directory Certificate Services (AD CS) and Group Policy distribution, 802.1X/NAC, VPN, TLS for internal services, code signing, device identity.
  • Provide technical leadership for troubleshooting, incident support, root cause analysis, and continuous improvement of PKI services.
  • Engage with internal and external stakeholders at all levels, including security, infrastructure, delivery teams and customer representatives, primarily on-site within secure facilities.

PKI Architect employer: Lucid Support Services Ltd

At Lucid, we pride ourselves on being an excellent employer, offering a dynamic work culture that fosters innovation and collaboration. Our remote-first approach allows for flexibility while still providing opportunities for professional growth through diverse project engagements, particularly in the infrastructure and engineering sectors. With a commitment to diversity and inclusion, we ensure that every team member feels valued and empowered to contribute their unique perspectives.

Lucid Support Services Ltd

Contact Details:

Lucid Support Services Ltd Recruitment Team

We think you need these skills to ace PKI Architect

Public Key Infrastructure (PKI)
Cryptographic Trust Services
Certificate Life Cycle Management
Cryptographic Policy Enforcement
Secure Key Management
Integration with Enterprise Services
Root CA Design