Skip to main content
Keeper Security

Staff Software Engineer, Certificate Lifecycle Management

RemoteUnited States only
Published
Role
Backend
Experience
Staff
Employment
Full-time
Salary not disclosed
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Staff Software Engineer with 8+ years of experience in backend, infrastructure, or security systems. Requires deep hands-on experience in PKI, certificate management, or machine identity security. Must have strong knowledge of X.509 certificates, PKI protocols, and secure key handling. Experience with AI-assisted tools is required.

Core skills

Certificate Lifecycle ManagementPKImachine identity security

Required skills

X.509 certificatescertificate authoritiescertificate chainstrust storesprivate keyspublic key cryptographyACMESCEPESTOCSPCRLsTLSJavaGoPythonC++C#APIsdistributed systemsautomation workflowssecure key handlingauthenticationauthorizationcryptographic trustcloud-native infrastructureenterprise infrastructureAI-assisted tools

Optional skills

commercial certificate lifecycle management platformPKI platformmachine identity platformKeyfactorDigiCertVenafiAppViewXSectigo

What you'll do

  • Architect and develop certificate lifecycle management capabilities spanning discovery, inventory, enrollment, issuance, deployment, renewal, rotation and revocation
  • Design scalable backend services and APIs for managing certificates, machine identities and related cryptographic metadata across enterprise environments
  • Build certificate discovery and automation workflows across cloud platforms, Kubernetes, web servers, load balancers, databases, network devices and other infrastructure
  • Design integrations with public and private certificate authorities and enterprise PKI environments
  • Develop secure workflows for certificate enrollment, key handling, trust validation and certificate deployment
  • Solve complex engineering challenges involving certificate chains, trust stores, expiration, ownership, policy enforcement and cryptographic compliance
  • Design systems that support automated certificate renewal and remediation while minimizing operational disruption
  • Provide technical leadership on PKI architecture, machine identity, cryptographic standards and certificate automation
  • Partner with Product and Engineering leadership on technical strategy, architecture, requirements and long-term platform direction
  • Lead technical design reviews, mentor engineers and help establish engineering standards for security-sensitive certificate management capabilities
  • Evaluate emerging PKI, machine identity and cryptographic technologies and recommend architectural approaches
  • Use AI-assisted development tools such as Claude, ChatGPT, GitHub Copilot or similar platforms to improve technical research, software development, debugging, documentation and engineering efficiency

What they require

  • 8+ years of professional software engineering experience, including significant experience building backend, infrastructure or security-focused systems
  • Deep hands-on experience with certificate lifecycle management, PKI, machine identity security or a closely related domain
  • Strong understanding of X.509 certificates, certificate authorities, certificate chains, trust stores, private keys and public key cryptography
  • Experience with certificate lifecycle operations including discovery, enrollment, issuance, deployment, renewal, rotation, revocation and expiration management
  • Strong knowledge of certificate and PKI protocols and technologies such as ACME, SCEP, EST, OCSP, CRLs and TLS
  • Strong backend software engineering experience using languages such as Java, Go, Python, C++, C# or similar
  • Experience designing scalable APIs, distributed systems and automation workflows
  • Experience integrating with enterprise PKI systems, certificate authorities, cloud platforms or infrastructure technologies
  • Strong understanding of secure key handling, authentication, authorization and cryptographic trust
  • Experience working with cloud-native and enterprise infrastructure environments
  • Ability to lead architecture discussions and make sound technical tradeoffs across security, scalability, reliability and usability
  • Proven ability to mentor engineers and influence technical direction across teams
  • Ability and willingness to use AI-assisted tools effectively to support engineering, research, debugging, prototyping and technical documentation
  • Bachelor’s degree in Computer Science, Engineering or a related field, or equivalent practical experience

Benefits

  • Medical, Dental & Vision (inclusive of domestic partnerships)
  • Employer Paid Life Insurance & Employee/Spouse/Child Supplemental Life
  • Voluntary Short/Long Term Disability Insurance
  • 401K (Roth/Traditional)
  • A generous PTO plan that celebrates your commitment and seniority (including paid Bereavement/Jury Duty, etc.)
  • Above-market annual bonuses

Keeper Security is one of the fastest-growing cybersecurity software companies that protects thousands of organizations and millions of people in over 150 countries. Keeper is a pioneer of zero-knowledge and zero-trust security built for any IT environment. Its core offering, KeeperPAM®, is an AI-enabled, cloud-native platform that protects all users, devices and infrastructure from cyber attacks.

🇺🇸 United StatesCybersecurityEnterprise
Salary not disclosed