Key details
Job Description
Salary: £? - ? per year
Requirements
- Strong hands-on experience with Microsoft PKI technologies, particularly Active Directory Certificate Services (AD CS)
- Proven experience in PKI design, implementation, and remediation
- Experience conducting PKI health checks and security assessments
- Strong knowledge of certificate lifecycle management, including enrolment, renewal, and revocation
- Strong knowledge of certificate templates and policies
- Strong knowledge of cryptography fundamentals, including keys, hashing, and encryption
- Experience with certificate-based authentication and identity integration
- Ability to translate complex environments into structured, repeatable designs
- Strong documentation and stakeholder communication skills
- Experience in highly regulated industries such as legal, financial services, or the public sector
- Exposure to cloud-integrated PKI, including Microsoft Entra ID and Intune device certificate deployment
- Knowledge of Zero Trust architecture principles
- Experience with PKI migration or modernisation programmes
- Familiarity with hardware security modules (HSMs)
- Highly detail-oriented with strong analytical capability
- Strong focus on security, trust, and risk reduction
- Comfortable operating as a standalone SME
- Able to work across infrastructure, security, and identity teams
- Strong communication skills, particularly in explaining complex PKI concepts to non-specialists
Responsibilities
- Conduct a detailed assessment of the current PKI environment, including Certificate Authorities, certificate templates, and trust chains
- Document existing as-is PKI architecture, configurations, and operational processes
- Identify security risks, misconfigurations, and lifecycle management gaps such as expiry, revocation, and weak templates
- Design a target-state to-be PKI architecture, including root and subordinate CA hierarchy, certificate enrolment and lifecycle processes, and high availability and resilience considerations
- Translate the existing setup into a standardised, repeatable PKI design suitable for enterprise scale
- Configure and optimise Active Directory Certificate Services (AD CS)
- Support certificate-based authentication scenarios, including user and device authentication, smartcards, passwordless authentication, and integration with Active Directory and Microsoft Entra ID
- Enable secure certificate usage across services, including TLS/SSL for applications and infrastructure, email encryption (S/MIME), VPN, and wireless authentication
- Define and implement PKI governance, policies, and operational standards
- Ensure alignment with security frameworks and regulatory requirements, including ISO27001, NIST, and legal sector obligations
- Provide clear documentation and knowledge transfer to operational teams
Technologies
- Active Directory
- Cloud
- Cryptography
- Hardware
- Support
- Security
- VPN
- DevOps
More
We are offering a Microsoft PKI SME contract role focused on assessing, designing, and optimising Public Key Infrastructure across on-premises and cloud environments. This is a fully remote position paying £700 to £750 per day inside IR35 for 3 months, with scope to extend. Active SC clearance would be advantageous. You will work within a highly regulated and data-sensitive environment, helping us strengthen secure authentication, encryption, compliance, and operational standards across our certificate services landscape.
last updated 27 week of 2026
Company & context
Evidence is labeled so you can tell internal community data from public sources.
Range from 160 indexed roles at this employer: $10,800 - $149,500(mid ~48797)
Context may refresh in the background.
Trust-check this listing
Verify scam risk and ghost-job signals before you apply.
Related roles
SC Cleared Data & Reconciliation Analyst
Ruby Developer
Business Analyst
Source: DevITJobs • Last updated 2w ago