PKI Architect

Job title: PKI Architect

Duration: 9 months

Clearance required: DV or DV Eligible

Rate: To be discussed

Location: Hybrid, onsite in Corsham twice a week

Specification: Below

Overview:

  • An experienced Public Key Infrastructure (PKI) Architect and Subject Matter Expert (SME) is required to lead the design, build, integration and assurance of PKI services within secure, offline (air gapped) environments. The post holder will provide technical leadership to deliver a robust, resilient and compliant cryptographic trust service in support of a UK secure account, working predominantly from customer sites within controlled environments.
  • The role demands proven experience designing and implementing PKI platforms for high-assurance use cases, including certificate life cycle management, cryptographic policy enforcement, secure key management, and integration with enterprise services and security controls.

Key Responsibilities:

  • Lead the architecture, design and delivery of PKI platforms operating in offline/disconnected networks, ensuring solutions are secure, supportable and auditable.

Define and implement PKI components, including (as applicable):

  • Root CA (offline), Issuing CAs, Registration Authorities (RA)
  • OCSP/CRL services and distribution models suitable for disconnected environments
  • Certificate templates, enrolment policies, and certificate life cycle processes
  • Develop secure and repeatable mechanisms for certificate and revocation data transfer into/out of air gapped environments in accordance with approved processes.
  • Establish and maintain cryptographic governance, including certificate policy and certificate practice statements (CP/CPS) where required, and alignment to programme security requirements.
  • Design secure key management processes, including key generation, storage, backup, escrow (if authorised), destruction, and compromise handling.
  • Define operational models, including role separation, dual control, and privileged administration, aligned to security policy and audit requirements.
  • Produce and maintain formal design and assurance documentation and provide technical input into risk assessments and accreditation evidence packs.

Support the integration of PKI services with enterprise capabilities (as applicable), including:

  • Microsoft Active Directory Certificate Services (AD CS) and Group Policy distribution
  • 802.1X/NAC, VPN, TLS for internal services, code signing, device identity
  • Provide technical leadership for troubleshooting, incident support, root cause analysis, and continuous improvement of PKI services.
  • Engage with internal and external stakeholders at all levels, including security, infrastructure, delivery teams and customer representatives, primarily on-site within secure facilities.

Required Skills & Experience:

  • Demonstrable experience operating as a PKI Architect or senior PKI SME within complex enterprise environments.
  • Proven experience designing and building PKI platforms in offline/air gapped environments, including handling of:
  • Controlled import/export processes
  • Revocation publishing strategies (CRL/OCSP) for disconnected networks
  • Secure media handling and procedural controls
  • Strong knowledge of PKI concepts and implementation including:
  • X.509 certificates, trust chains, certificate policies, key usage and extended key usage
  • Certificate life cycle management (issue, renew, revoke, recover, replace)
  • CRL/Delta CRL design, OCSP stapling considerations (where applicable)
  • Strong understanding of cryptography fundamentals and operational security, including:
  • Algorithm selection and key sizes appropriate to policy
  • HSM design/operations (preferred), secure key ceremonies, tamper controls
  • Role-based administration, segregation of duties, dual control
  • Experience with designing secure operational models (build, run, audit), including:
  • Break-glass and recovery arrangements
  • Compromise response procedures
  • Monitoring, logging and evidence generation
  • Demonstrable experience producing formal technical documentation, including:
  • High-Level Designs (HLDs)
  • Low-Level Designs (LLDs)
  • Security architecture documentation
  • Standard Operating Procedures (SOPs), runbooks, and key ceremony scripts
  • Strong stakeholder engagement and communication skills, including the ability to brief technical and non-technical audiences.

Government Security Standards:

The post holder must be able to design and assure solutions in alignment with relevant UK Government security policies and guidance, including (as applicable to the programme):

  • JSP 440 - Defence Manual of Security
  • JSP 604 - Network Rules and Design Principles
  • JSP 453 - Information Assurance Policy (where applicable)
  • NCSC Cyber Security Design Principles and applicable NCSC guidance for secure configuration and cryptographic services
  • MOD-aligned Secure by Design principles following NIST framework and MOD Security framework, and evidence-based assurance in support of accreditation

Desirable:

  • Experience working within the Defence and/or Aerospace sector, including delivery into regulated, high-assurance environments.
  • Experience with Microsoft AD CS architectures (offline root, issuing CA tiers, template governance) and/or other enterprise PKI stacks.
  • Experience implementing PKI for:
  • Device identity (workstations/Servers), user authentication, mutual TLS, code signing, S/MIME (as required)
  • Familiarity with HSM operations and assurance requirements and conducting or supporting key ceremonies.

If you are available and interested in this opportunity, please apply for further information. Please note that due to high volumes of applications we are unable to contact every applicant. If you do not hear back from us within 7 days of sending your application, please assume that you have not been successful on this occasion.

At Lucid, we celebrate difference and value diverse perspectives, underpinned by our values 'Honesty, Integrity and Pragmatism'. We are proud to provide equal opportunities in line with our Diversity and Inclusion policy and welcome applications from all suitably qualified or experienced people, regardless of personal characteristics. If you have a disability or health condition and seek support throughout the recruitment process, please do not hesitate to contact us via the details below.

Job Details

Company
Lucid Support Services Ltd
Location
Corsham, Wiltshire, United Kingdom SN130
Hybrid / Remote Options
Employment Type
Contract
Salary
GBP Annual
Posted