Senior PKI Infrastructure Security Engineer

Fisher Investments
Arlington, TX, US
Full-time
We are sorry. The job offer you are looking for is no longer available.

It's an exciting time to be a member of the Fisher Investments Technology Department. We're investing in the future of our firm's technology and are building our team to achieve global growth.

We are looking for a Senior PKI Security Engineer to support our Corporate Systems team. If you are looking for an opportunity to make a difference as we develop scalable and strategic solutions to support our global growth, we want to hear from you!

The Opportunity :

As a PKI / KMS / HSM / Certificates Architect, Engineer, and Implementer you will be responsible for administration, operation, upgrade and support of Certification Authorities (CA), Registration Authorities (RA), online responders, and Hardware Security Modules (HSM) of a Microsoft Windows-based enterprise Public Key Infrastructure (PKI).

You will take an active leadership role in maintaining and communicating PKI / KMS industry changes, advising and directing leadership to ensure that PKI requirements are addressed.

You will ensure PKI systems align to the firms Information Security policies, standards, and the industry best practices.

You will report to the Vice President, Infrastructure Security.

The Day-to-Day :

Build a mature enterprise-wide certificate management services and Public Key Infrastructure capabilities. Support the definition, design, and deployment of enterprise PKI system

Provide detailed specifications for PKI / KMS infrastructure

Provide roadmap guidance and recommendations to existing environment and future landscape (including the assessment & discovery work)

Maintain detailed procedures, policies, baselines, and work instructions for PKI & KMS administration, advise on improvements

An understanding of SSH, especially the configuration and use of SSH keys for authentication

Experience with technologies that heavily use TLS / SSL encryption

Represent PKI Engineering on organizational project teams and ensure adherence to existing security policies and standards

Manage the successful technical delivery of Information Security projects and services for our customers by working directly with key business stakeholders, executives and project teams

Keep up on current technologies and maintain awareness of industry trends and threats, focusing on PKI / PKE technologies

Your Qualifications :

8+ years of advanced hands-on experience in deploying, configuring, and managing certificated lifecycle management (KMS), Public Key Infrastructure (PKI), Certification Authorities (CA), Hardware Security Modules (HSM), Registration Authorities (RA), Root CA, Azure Key Vault, Thales, Venafi, Keyfactor, and Entrust integration experience (PKI / HSM / KMS / CRL / CRT)

Experience in Entrust, HashiCorp, Thales, DigCert, Venafi, Keyfactor

Individuals in this role must be well versed and educated in common Information Security practices and the CISSP domains, and have general Information Technology experience

You can use these experiences and education to identify opportunities for improvement of present information security environment, focusing on PKI, encryption, and certificate-based authentication solutions

Expert level experience with PKI implementation and certificate lifecycle management solution

Expert level experience with hardware security module (HSM) technology

Expert level experience in MS Certificate Management Services and Active Directory Domain Services

Expert level experience in SSL certificate management concepts, processes, and solution management

Expert level experience in cloud solution development with Azure architectures as it related to PKI management

Excellent knowledge in PKI / HSM ecosystem (technology, standards, implementations, & migration)

Technical Skills :

Public key infrastructure

Strong authentication / multi-factor authentication technologies

CodeSigning

Cryptographic services

Encryption

Certificate Management

Data Protection

Bachelor's degree in Information Assurance, Computer Science, Cybersecurity, Information Systems or related field of study

Security industry certification is required including but not limited to CISSP, SSCP, CISM, SANS GSEC, ECSA, ECSP, and Security+

Why Fisher Investments :

We work for a bigger purpose : bettering the investment universe. We take great pride in our inclusive culture, our learning and development framework customized for every employee, and our Great Place to Work Certification.

It's the people that make the Fisher purpose possible, and we invest in them by offering exceptional benefits like :

100% paid medical, dental and vision premiums for you and your qualifying dependents

A 50% 401(k) match, up to the IRS maximum

20 days of PTO*, plus 10 paid holidays (*17 days of PTO and 3 days of sick time for California employees)

Family Support programs including 8 weeks Paid Primary Caregiver leave, adoption assistance and back-up child care

  • $10,000 fertility, hormonal health and family-forming benefit
  • Opportunity to participate in our hybrid work from home program. This program is subject to change. Based on tenure and performance eligibility, you will have the opportunity to work from home up to 75 days per year

FISHER INVESTMENTS IS AN EQUAL OPPORTUNITY EMPLOYER

By applying, you consent to your information being transmitted by Jobcase to the Employer, as data controller, through the Employers data processor SonicJobs.

See SonicJobs Privacy Policy at https : / / www.sonicjobs.com / us / privacy-policy and Terms of Use at https : / / www.sonicjobs.

com / us / terms-conditions

2 days ago
Related jobs
Promoted
Capital One
Fort Worth, Texas
Remote

Senior Lead Engineer - Generative AI Infrastructure (Remote-Eligible). We are committed to building world-class applied science and engineering teams and continue our industry leading capabilities with breakthrough product experiences and scalable, high-performance AI infrastructure. Lead Engineer, ...

Promoted
Buildertrend
Arlington, Texas
Remote

Security Engineer or Cloud Engineer, with a focus on public cloud security and network security required. The Senior Cloud Network Security Engineer is responsible for designing, implementing, and maintaining secure network infrastructure in cloud environments. Work closely with Cloud Engineers and ...

Promoted
Capital One
Haltom City, Texas
Remote

NYC 299 Park Avenue (22957), United States of America, New York, New YorkSenior Lead Engineer - Generative AI Infrastructure (Remote-Eligible)Our mission at Capital One is to create trustworthy, reliable and human-in-the-loop AI systems, changing banking for good. Capital One is open to hiring a Rem...

Promoted
U.S. Bank
Irving, Texas

This may include infrastructure as code, programming, scripting languages, multi-cloud environments, system engineering and software development. You will be responsible for the maintenance of installed infrastructure technologies as well as the installation and configuration of these technologies w...

Promoted
Capital One
Everman, Texas
Remote

NYC 299 Park Avenue (22957), United States of America, New York, New YorkSenior Lead Engineer - Generative AI Infrastructure (Remote-Eligible)Our mission at Capital One is to create trustworthy, reliable and human-in-the-loop AI systems, changing banking for good. Capital One is open to hiring a Rem...

Promoted
Sirius XM Radio, Inc.
Irving, Texas

SiriusXM's Security Operations Center is seeking an experienced Offensive Security Engineer to ensure the security of our organization's systems and applications. Experience in network security architecture, infrastructure security, and application security. The Offensive Security Engineer will also...

Daystar Television Network
Bedford, Texas

As a Senior Security Engineer, you will be responsible for designing, implementing, managing, and monitoring security measures to protect computer systems, networks, and data. Evaluates and recommends new security technologies, tools, and methodologies to enhance the organization's security posture....

Crunchbase
Texas, United States

Infrastructure Engineering at Crunchbase. As an infrastructure engineer at Crunchbase you will build tooling to enable feature teams to own their solution from commit through to deployment, providing automation, observability and reliability at each step on the path. Build and maintain our custom ga...

Highmark Health
TX, Working at Home, Texas

The Identity & Access Management Senior Security Engineer is responsible for acting as resource, leader, and peer coach with other engineers in the development, testing, implementation, and integration of Identity and Access Management systems and solutions. Experience working within an information ...

Tapcheck Inc.
Remote, TX, US
Remote

The Security Engineer, you will play a crucial role in ensuring the security and integrity of our systems and data. The Sr Security Engineer will be responsible for designing and implementing security measures, performing vulnerability assessments and penetration testing, and actively monitoring our...