Find your dream job faster with JobLogr
AI-powered job search, resume help, and more.
Try for Free
IT Labs

IT Labs

via Ashby

All our jobs are verified from trusted employers and sources. We connect to legitimate platforms only.

Senior PKI Engineer

Anywhere
Full-time
Posted 10/7/2026
Direct Apply
Key Skills:
Public Key Infrastructure
Microsoft AD CS
Certificate lifecycle management
Windows endpoint management
Microsoft Intune
Palo Alto GlobalProtect
Active Directory
PowerShell

Compensation

Salary Range

$120K - 160K a year

Responsibilities

Implement and manage machine certificate authentication across Windows endpoints, Intune, and Palo Alto environments, troubleshooting certificate lifecycles and supporting secure network connectivity.

Requirements

Requires hands-on enterprise PKI and Microsoft AD CS experience, Windows endpoint management and certificate lifecycle skills, plus U.S. citizenship.

Full Description

IT Labs is looking for a Senior PKI Engineer to support a U.S.-based client with the implementation and operationalization of certificate-based device authentication across a secure Windows endpoint environment. The client already has an existing PKI environment. The focus of this role is therefore not to build an enterprise PKI from scratch, but to integrate and manage machine certificate authentication across Windows endpoints, Microsoft Intune, and Palo Alto GlobalProtect / Prisma Access. The engineer will help ensure that corporate laptops can securely authenticate before user login, maintain reliable certificate lifecycle processes, and support a secure transition from device identity to authenticated user identity. What You'll Do Implement and support machine certificate-based authentication for Windows endpoints. Integrate an existing enterprise PKI environment with Palo Alto GlobalProtect Pre-Logon. Support secure device authentication before Windows user login. Configure and troubleshoot certificate enrollment, renewal, expiration, and revocation. Work with Microsoft Intune, Active Directory, and Windows endpoint management. Ensure certificates and private keys are securely stored and protected, including TPM-backed key scenarios where applicable. Support CRL and OCSP validation and certificate revocation processes. Configure and troubleshoot GlobalProtect certificate authentication and pre-logon connectivity. Support the transition from machine/device identity to authenticated user identity. Work with network and security teams on Prisma Access, firewall policies, and secure endpoint connectivity. Troubleshoot certificate, authentication, and connectivity issues across endpoints. Support resilience and failover scenarios across GlobalProtect / Prisma Access gateways. Document technical configurations, operational processes, and troubleshooting procedures. Collaborate with endpoint, networking, identity, and security teams. What We're Looking For Strong hands-on experience with Public Key Infrastructure (PKI) in enterprise environments. Strong knowledge of Microsoft AD CS / Certificate Services or comparable enterprise PKI solutions. Experience with: Machine/device certificates Certificate enrollment and auto-enrollment Certificate lifecycle management Certificate renewal and revocation CRL / OCSP X.509 certificates Private key management Strong experience with Windows enterprise environments. Experience with Active Directory. Experience with Microsoft Intune or another enterprise endpoint management platform. Strong troubleshooting skills across certificates, authentication, endpoint configuration, and network connectivity. Experience working in security-conscious enterprise environments. Nice to Have Experience with Palo Alto GlobalProtect. Experience with Prisma Access. Experience implementing GlobalProtect Pre-Logon. Experience with certificate-based VPN authentication. Understanding of Always-On VPN / Always-On GlobalProtect architectures. Experience with TPM-backed certificates and hardware-protected private keys. Experience with Microsoft Entra ID. Experience with endpoint security tooling such as: CrowdStrike Microsoft Defender Tanium Qualys PowerShell scripting experience. Experience working in regulated or high-security environments. Working Conditions Remote position, open only to candidates based in the United States. U.S. citizenship is required for this engagement. Engagement is offered on an Individual Contractor or B2B contract basis. Paid Time Off (PTO) is included as part of the engagement. Full-time commitment, working in alignment with the client's business hours and project needs. Our values We are a company that seeks the best for both our employees and clients, reaching beyond expectations in turning dreams into reality. Our way of working is rooted in our core values (Integrity, Excellence, Proactivity, Innovation, and People), with an expectation that our future colleagues will make these their second nature in their everyday work and life. We don’t ask for perfection, but we do appreciate people motivated to better themselves in every conceivable aspect. About IT Labs Founded in 2005, IT Labs is an international software tech company, specializing in purpose and process-driven teams for high-performance, innovation, transformation, and efficiency. Our HQ is in Palm Beach Gardens, Florida, and we have teams around the world - the UK, the Netherlands, Brazil, Argentina, Serbia, Croatia, BIH, Montenegro, North Macedonia, and the Middle East. We are constantly growing, and we would love for you to become part of our team!

This job posting was last updated on 10/7/2026

Ready to have AI work for you in your job search?

Sign-up for free and start using JobLogr today!

Get Started »
JobLogr badgeTinyLaunch BadgeJobLogr - AI Job Search Tools to Land Your Next Job Faster than Ever | Product Hunt