Microsoft PKI SME (Engineer)

PKI SME Engineer - Microsoft AD CS

Rate: £520 per day Inside IR35
Contract: 6-12 Months (Subject to Extension)
Location: Remote with some occasional travel onsite to Bath.

Overview

We are seeking an experienced PKI SME Engineer to lead the hands-on implementation of a Microsoft Public Key Infrastructure (PKI) solution within a greenfield enterprise environment.

This is a delivery-focused role requiring a technical specialist with proven experience deploying Microsoft Active Directory Certificate Services (AD CS) at enterprise scale. The successful candidate will be responsible for building, configuring, testing, and transitioning a production-ready PKI capability into service, followed by a period of focused post-go-live hypercare.

Working from established designs and architecture, you will take ownership of the implementation, integration, testing, and operational handover of the PKI platform, ensuring it is secure, scalable, and production-ready.

Role Purpose

The PKI SME Engineer is responsible for the end-to-end delivery of a Microsoft PKI solution within a new enterprise environment.

You will carry out the technical implementation of Microsoft Active Directory Certificate Services (AD CS), integrating the service into enterprise infrastructure and validating the platform through comprehensive testing before supporting production cutover and hypercare activities.

This role is focused on technical delivery, testing, transition, and post-go-live support rather than solution design.

Key Responsibilities

PKI Platform Implementation

  • Build and configure a greenfield Microsoft PKI environment based on approved architectural designs.
  • Prepare and validate all platform prerequisites, including Windows Server, Active Directory, DNS, networking, service accounts, and security groups.
  • Install and configure:
    • Offline Root Certificate Authority (CA)
    • Enterprise Issuing Certificate Authorities
    • Active Directory Certificate Services (AD CS) components
    • Supporting PKI infrastructure services

Certificate Services Configuration

  • Configure and manage certificate templates, policies, and permissions.
  • Implement auto-enrolment, certificate renewal, and certificate revocation processes.
  • Configure and validate Certificate Revocation Lists (CRLs), certificate chain publication, and supporting services.
  • Implement and support OCSP and NDES services where required.

Integration & Validation

  • Integrate PKI services with Active Directory and enterprise infrastructure.
  • Support integration with applications, devices, endpoints, and hybrid environments.
  • Execute build verification testing and functional validation activities.
  • Troubleshoot and resolve implementation defects and technical issues.

Go-Live & Hypercare

  • Support production deployment and service cutover activities.
  • Provide post-go-live hypercare support.
  • Investigate and resolve certificate, trust, authentication, and enrolment issues.
  • Work closely with operational support teams to ensure a smooth transition to business-as-usual support.

Documentation & Handover

  • Produce comprehensive as-built documentation.
  • Create operational runbooks and configuration records.
  • Document testing outcomes and implementation activities.
  • Deliver knowledge transfer sessions to support and operational teams.

Essential Technical Skills

Microsoft PKI Expertise

  • Strong hands-on experience implementing Microsoft Active Directory Certificate Services (AD CS).
  • Enterprise Certificate Authority (CA) deployment and administration.
  • Certificate lifecycle management.

PKI Technologies

  • Certificate Templates
  • Auto-Enrolment
  • Certificate Revocation Lists (CRL)
  • Online Certificate Status Protocol (OCSP)
  • Network Device Enrolment Service (NDES)
  • Certificate Chain Management
  • Trust Validation

Microsoft Infrastructure

  • Windows Server
  • Active Directory
  • Group Policy
  • DNS
  • PowerShell Scripting

Enterprise Integration

  • Integration of PKI with enterprise infrastructure and applications.
  • Experience supporting hybrid and on-premises environments.
  • Knowledge of identity, authentication, and security services.

Troubleshooting

  • Certificate chain troubleshooting.
  • TLS and SSL certificate troubleshooting.
  • Service authentication and trust-related issue resolution.
  • Certificate enrolment and renewal diagnostics.

Required Experience

  • Proven hands-on experience delivering enterprise PKI implementations.
  • Extensive experience deploying Microsoft AD CS environments.
  • Experience building and configuring enterprise-scale PKI solutions.
  • Strong background working across both on-premises and hybrid infrastructures.
  • Demonstrated experience supporting production deployments and post-go-live hypercare activities.

Desirable Skills

  • Microsoft security technologies.
  • Enterprise identity and access management solutions.
  • Infrastructure automation using PowerShell.
  • Experience within highly regulated or security-sensitive environments.
  • Knowledge of certificate-based authentication and enterprise security frameworks.

Job Details

Company
TXP
Location
Bath, Somerset, United Kingdom
Employment Type
Contract
Salary
£0.00 - £520/day
Posted