Sr. Security Engineer
IRIS Consulting Corporation · Atlanta, GA
$52.32–$62.32/hrfrom the description
Jul 23, 2026
Atlanta, GA
Jul 24, 2026
What this job asks for AI summary
A PKI and certificate lifecycle engineering role focused on maintaining and automating large-scale certificate infrastructure across enterprise applications, cloud services, and CI/CD pipelines. Day-to-day work spans certificate issuance, renewal, and revocation; policy and compliance enforcement; cross-team enablement; and incident support. Suits engineers with hands-on PKI platform experience who can also build automation and scripting solutions.
Mid level · 3+ years · Contract
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
Why we read it this way (8)
The SOC classification is a genuine judgment call: the role's primary work is PKI security engineering — certificate lifecycle management, cryptographic policy, and compliance — which aligns with 15-1212 (Information Security Analysts). However, a meaningful portion of the work involves operating and maintaining PKI infrastructure (patching, availability, resiliency), which could support 15-1244. 15-1212 was chosen because governance, policy enforcement, compliance, and risk reduction dominate the responsibilities.
The degree requirement states 'Bachelor's degree … or equivalent experience,' so no formal degree is hard-gated.
The 3–7+ year range is stated at the role level (PKI/cybersecurity engineering/infrastructure security); the minimum of 3 years is used for the overall years minimum.
Venafi, DigiCert, Microsoft CA, and AWS ACM are listed together as interchangeable examples of PKI platforms under the required qualifications section; Venafi is used as the primary with the others as alternatives.
HSMs, PKI automation (APIs/pipelines/scripting), cloud certificate services (AWS, Azure), NIST/PCI-DSS/CMMC compliance frameworks, and trust store management across distributed systems all appear under the Preferred Qualifications section.
'Trust Store Management' and 'Key Management' are retained as named capabilities despite being somewhat generic, because the posting explicitly calls them out as distinct technical competencies in the context of PKI operations.
Ignored 3 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): Certificate Lifecycle Management, Key Management, Trust Store Management.
Posting is for a contract engagement — the market benchmarks below price full-time roles, so read the comp comparison with that in mind.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.