Basingstoke
PKI Architect Location Basingstoke – 5 days a week – Office based. Are you skilled PKI Architect with excellent interpersonal skills who can learn and adapt to work across both legacy and new technologies as part of a live system transitioned programme? Do you want to make an impact and change the way the world works? Do you want to collaborate and achieve together with committed people to work as part of a multi skilled agile team, where teamwork is paramount. The role will be challenging and varied, where cross training is expected, and challenges shared. This is your world and your opportunity to transform it for the better. Your role We are looking for a PKI Architect to work as part of a multi-skilled agile team, including security, service and management where teamwork is paramount. Your role will be challenging and varied, where cross training is expected and challenges shared. Example of tasks: • Design and architect enterprise-grade PKI solutions (including internal/external CA, OCSP, CRL, HSM integration)., • Develop and enforce policies, standards, and procedures for digital certificate lifecycle management., • Implement and maintain Certificate Authorities (CAs), Registration Authorities (RAs), and associated infrastructure., • Ensure secure deployment and configuration of PKI across enterprise systems, endpoints, applications, and devices (including IoT and mobile)., • Collaborate with IDAM, DevOps, and cloud security teams to integrate PKI with broader identity and security architecture., • Provide technical leadership in incident response and troubleshooting related to certificates and encryption., • Stay current with industry standards, compliance requirements (e.g., NIST, FIPS, ISO 27001), and emerging cryptographic technologies (e.g., quantum-safe cryptography), • Document required all architecture, policies, procedures, and system configurations related to PKI., • Provide mentoring and knowledge transfer to junior members of the team and other stakeholders. Your skills and experiences • Experience in IT Security or Infrastructure with at least 3 years in PKI architecture and management., • Deep knowledge of PKI components: CAs, HSMs, OCSP, CRLs, SCEP, etc., • Hands-on experience with tools such as Microsoft ADCS, Thales HSM’s (Luna etc), DigiCert, OpenSSL., • Familiarity with certificate usage in TLS, S/MIME, code signing, document signing, VPN, smart cards, and secure email., • Understanding of encryption algorithms (RSA, ECC, AES), hash functions (SHA-2, SHA-3), and key management practices., • Experience in designing secure architecture in hybrid or cloud environments (e.g., AWS, Azure)., • Knowledge of compliance and regulatory standards such as PCI DSS, HIPAA, SOX, GDPR, NIST 800-53., • Hardware Security Modules (HSM) and creation of Certificate Policies, and Certificate Practice Statements. Preferred Qualifications: • Certifications: CISSP, CISM, CEH, GIAC, Microsoft Certified: Identity and Access, or other IDAM equivalent Technologies., • Experience with Zero Trust Architecture and Identity Federation., • Exposure to quantum-safe cryptography principles and roadmaps (Not Essential) Strong determination to tackle and solve problems, balancing artistic vision with practicality.