PKI System Setup

Job ID: 40468844

Budget: $90 – $115 USD

I am looking for an experienced PKI engineer to design and implement a new on-premises PKI system for an active client engagement. This is a solo delivery role — one resource owns the full scope from discovery through handoff.
The engagement includes:

Designing and implementing the full PKI architecture including CA hierarchy, RA, and trust model selection
Configuring CA, RA, and CRL components
Integrating ACME protocol for automated certificate management
Implementing certificate lifecycle management — issuance, renewal, revocation, and expiration alerting
Automating certificate workflows using Python, PowerShell, or Bash
Producing client-grade documentation including architecture diagrams, runbooks, and a project closeout report
Delivering a knowledge transfer session so the client can operate what was built independently

What we need:

Deep hands-on knowledge of PKI concepts and components — not theoretical
Proven experience with on-premises PKI deployments in professional engagements
Platform fluency in at least one of: AD CS, EJBCA, HashiCorp Vault PKI, Venafi, or Keyfactor
Proficiency configuring CA, RA, CRL, and ACME automation
Strong security and compliance background
Client-facing experience — you have delivered runbooks and architecture documentation a team can actually use

Engagement Details:

Duration: Approximately 8 weeks
Delivery: Fully remote
Start: June 1, 2026
This is not a support role. There is no backstop.

Please provide examples of similar work and relevant certifications. Candidates meeting 85% of requirements are encouraged to apply. Rate is negotiable based on experience and fit.