At a Glance
- Tasks: Assess, design, and optimise Public Key Infrastructure (PKI) for secure authentication and compliance.
- Company: Join a leading organisation focused on security in a fully remote role.
- Benefits: Competitive daily rate, flexible working, and potential for contract extension.
- Other info: Opportunity to work with cutting-edge technology and grow your expertise in a dynamic field.
- Why this job: Make a real impact by enhancing security in a highly regulated environment.
- Qualifications: Strong experience with Microsoft PKI technologies and excellent communication skills.
The predicted salary is between 60000 - 75000 £ per year.
Our client requires a Microsoft PKI Subject Matter Expert (SME) to assess, design, and optimise the organisation's Public Key Infrastructure (PKI) across on-premises and cloud environments. This role will focus on reviewing the existing certificate services landscape, identifying risks and gaps, and translating the current configuration into a secure, scalable, and repeatable design. The successful candidate will ensure PKI services support secure authentication, encryption, and compliance within a highly regulated and data-sensitive environment.
Key Responsibilities
- Conduct a detailed assessment of the current PKI environment, including Certificate Authorities (CAs), certificate templates, and trust chains.
- Document existing ('as-is') PKI architecture, configurations, and operational processes.
- Identify security risks, misconfigurations, and lifecycle management gaps (e.g. expiry, revocation, weak templates).
- Design a target-state ('to-be') PKI architecture, including:
- Root and subordinate CA hierarchy.
- Certificate enrolment and lifecycle processes.
- High availability and resilience considerations.
- Translate existing setup into a standardised, repeatable PKI design suitable for enterprise scale.
- Configure and optimise Active Directory Certificate Services (AD CS).
- Support certificate-based authentication scenarios, including:
- User and device authentication.
- Smartcards / passwordless authentication.
- Integration with Active Directory and Microsoft Entra ID.
- Enable secure certificate usage across services, including:
- TLS/SSL for applications and infrastructure.
- Email encryption (S/MIME).
- VPN and wireless authentication.
- Define and implement PKI governance, policies, and operational standards.
- Ensure alignment with security frameworks and regulatory requirements (e.g. ISO27001, NIST, legal sector obligations).
- Provide clear documentation and knowledge transfer to operational teams.
Required Skills & Experience
- Strong hands-on experience with Microsoft PKI technologies, particularly Active Directory Certificate Services (AD CS).
- Proven experience in PKI design, implementation, and remediation.
- Experience conducting PKI health checks and security assessments.
- Strong knowledge of:
- Certificate lifecycle management (enrolment, renewal, revocation).
- Certificate templates and policies.
- Cryptography fundamentals (keys, hashing, encryption).
- Experience with certificate-based authentication and identity integration.
- Ability to translate complex environments into structured, repeatable designs.
- Strong documentation and stakeholder communication skills.
Desirable Experience
- Experience in highly regulated industries (legal, financial services, public sector).
- Exposure to cloud-integrated PKI, including:
- Microsoft Entra ID.
- Intune (device certificate deployment).
- Knowledge of Zero Trust architecture principles.
- Experience with PKI migration or modernisation programmes.
- Familiarity with hardware security modules (HSMs).
Key Deliverables
- Current-state PKI assessment report.
- Risk and gap analysis with prioritised remediation plan.
- Target-state PKI architecture and design documentation.
- Standardised certificate management model.
- Operational processes and governance framework.
- Knowledge transfer and implementation guidance.
Profile
- Highly detail-oriented with strong analytical capability.
- Strong focus on security, trust, and risk reduction.
- Comfortable operating as a standalone SME.
- Able to work across infrastructure, security, and identity teams.
- Strong communication skills, particularly in explaining complex PKI concepts to non-specialists.
Microsoft PKI SME in London employer: TXP
As a Microsoft PKI Subject Matter Expert, you will join a forward-thinking organisation that prioritises innovation and security in a fully remote environment. The company fosters a collaborative work culture, offering competitive daily rates and opportunities for professional growth through challenging projects in a highly regulated sector. With a focus on employee development and a commitment to excellence, this role provides a unique chance to make a significant impact while enjoying the flexibility of remote work.
StudySmarter Expert Advice🤫
We think this is how you could land Microsoft PKI SME in London
✨Get Active on Cybersecurity Forums
Join platforms like Stack Exchange and Reddit’s r/cybersecurity to hang out with industry pros, learn the latest, and share your insights. This will not only boost your visibility but also help you connect with potential clients who might need your freelance services.
✨Show Off Your Skills with Public Projects
Create a few open-source projects or contribute to existing ones that showcase your cybersecurity skills. Use GitHub to display your work, as this is an excellent way to attract clients looking for freelancers with a proven track record.
✨Attend Local Conferences and Meetups
Make sure to hit up cybersecurity meetups, workshops, and conferences in your area. These events are goldmines for networking, and you’ll often find people looking for freelancers after a chat over a coffee – so come prepared with your business cards and a killer elevator pitch!
✨Market Yourself Smartly
Set up a professional website that showcases your portfolio, expertise, and client testimonials. Optimise it for SEO with relevant keywords so potential clients searching for cybersecurity freelancers can easily find you. Don’t forget to link to your site on all your social media and profiles!
We think you need these skills to ace Microsoft PKI SME in London
Some tips for your application 🫡
Show Your Skills Through a Strong Portfolio:Since you're applying for a freelance role in cybersecurity, it's crucial to showcase your technical skills through a detailed portfolio. Include case studies of projects you've worked on, any security tools you've developed or assessed, and specifics on the methodologies you’ve used. This will help TXP understand what you're capable of.
Certifications Matter!:Make sure to list any relevant certifications you hold, such as CISSP, CEH, or CompTIA Security+. Freelance clients often value these credentials as they reflect your expertise and commitment to the field. If you’re actively pursuing more certifications, don’t hesitate to mention that too!
Rates, Availability, and Your Work Style:In your application, it’s essential to be clear about your freelance rates and availability. Clients appreciate transparency. Mention how many hours a week you can dedicate and your preferred working hours, as this sets expectations from the start and shows you're organised and professional.
Tailor Your CV to Highlight Cybersecurity Experience:When crafting your CV, make sure to tailor it specifically to cybersecurity. Highlight projects, tasks, and achievements related to security assessments, vulnerabilities you've mitigated, or compliance work you've undertaken. Keywords relevant to the job can grab attention and increase your chances of landing a spot at TXP.
How to prepare for a job interview at TXP
✨Showcase Your Cybersecurity Skills
As a freelancer in cybersecurity, it’s crucial we demonstrate not just our knowledge but our practical skills too. Be ready to discuss specific tools you’ve used, like Wireshark or Metasploit, and share relevant experiences where you identified vulnerabilities or mitigated risks in past projects.
✨Prepare Your Portfolio
Unlike traditional roles, freelancing relies heavily on your portfolio. Let’s curate a selection of past work that showcases our best projects. If we’ve handled penetration tests, audits, or incident responses, be sure to highlight these in your portfolio, and share any client testimonials if we have them.
✨Stay Updated on Trends and Tools
Cybersecurity is an ever-evolving field, so we should be prepared to chat about recent developments and how they impact our work. Familiarise ourselves with the latest threats, tools, and frameworks, like MITRE ATT&CK, that are pertinent to the projects we’re pitching.
✨Pitching Your Value as a Freelancer
When freelancing, we often need to negotiate our rates and value propositions. Be ready to explain how our skills can help TXP protect their assets and manage risks. It can help to outline some potential strategies or improvements we could implement for them based on their current setup.