Sign up to save this job, get alerts, and apply with an optimized CV.
Senior Cyber Security Engineer for PKI and Key Management with MS ADCS (Ref.Nr.: 46115)
Job description
We are looking for a Senior Security / Cyber Engineer for the further development of a PKI-Service within the framework of the corporate cybersecurity. The focus of the role lies on technical analysis, architecture consulting, and conception of migration strategies and operating models in a hybrid project environment combining agile and classical methods.
Key Facts
Start: 23.02.2026
Duration: Not known
Utilization: 0 %
Type of employment:
Location of employment: Remote
Country of employment: Germany
Your tasks
• Technical support in the analysis and evaluation of new requirements from the CS@Auftraggeber or IAM@OT program
• Technical support in the form of analysis and evaluation in the context of the Big-Picture-Re-Design, including aspects of OT authorization management, OT directory services, and PKI
• Evaluation of requirements with regard to standards and industry best practices
• Consulting with expertise on PKI, Microsoft Active Directory, or Microsoft ADCS
• Consulting for answering bidder questions and setting up the test environment
• Expert review of feedback
• Analysis of technical configurations and documentation, as well as evaluation with regard to standards and industry best practices
• Analysis of customer-specific requirements and technical framework conditions
• Technical support in the creation of a rough concept for migration
• Creation of a migration plan and strategy
• Consulting with expertise on PKI- or AD-Forest-migration best practices
• Evaluation of potential risks and creation of a test strategy to ensure a smooth transition
• Technical support in the creation of an architecture fine concept
• Definition and design of individual system components
• Planning of interfaces and interactions between the components
• Development of security and data protection measures
• Rough conceptualization of the PKI- and AD-specific operating model in line with customer requirements, the existing PKI consortium strategy, the PKI reference architecture, and the valid Certificate Policy (CP) of the customer
• Expert review and revision of existing PKI, AD operation documentation
• Consulting with expertise for the operation of PKI and related AD infrastructure
• Conducting decision-making workshops
• Creation of decision-making templates
• Creation of specialized documentation (e.g. test concepts, role and rights concepts)
• Specialized communication with relevant IT/OT stakeholders within the corporation (up to C-level) to ensure an addressable service
• Creation of presentations and decision-making templates
• Conducting workshops
• Technical support for event management around the PKI community of the customer
Must-Requirements
• Analysis, evaluation, and testing of MS ADCS and its components for integration with PKI solutions in the last 6 years, proven by at least 2 references
• At least 7 years of practical experience with products in the field of PKI and key management in the last 6 years
• Creation of PKI architectures based on MS ADCS for rough and detailed concepts in the last 6 years, proven by at least 2 references
• Definition of processes and workflows as well as creation of role and rights concepts for PKI in the last 6 years, proven by at least 2 references
• Process-compliant documentation of requirements and future services to a central PKI, such as integration with IT/OT identity providers, MS AD-forests, certificate issuance processes, certificate management, and key management, proven by at least 2 references
Can-Requirements
• At least 5 years of experience in setting up and managing Certificate Authorities (CA)
• At least 3 years of practical experience in the field of code signing
• At least 3 years of experience with device authentication (802.1x)
• At least 3 years of experience in dealing with identity providers, particularly with One Identity Manager
• Experience with Microsoft Active Directory Certificate Services (ADCS) in the last 6 years, proven by at least one reference
• At least 3 years of experience in key escrow
• At least 3 years of experience in key management
• Process-compliant documentation of requirements and future services to a central PKI in the last 6 years, proven by at least 2 references
• At least 3 years of experience in certificate deployment on client devices (PC, mobile), servers (Windows, Linux) as well as in IoT and OT areas
• Experience in certifying a trust center according to ISO27001 in the last 6 years, proven by at least one reference
Additional Information
The location of employment is Frankfurt am Main. The performance delivery can take place independently of the location (Onsite PT: 0). The planned deployment period is from February 23, 2026 to December 31, 2027.
Let’s power the future together
From business case to implementation: As a leading consulting firm for strategic transformations, we are a trustworthy partner for our customers - and for our employees. Responsible, high-performance, and always with people in focus. #WeAreWavestone
With our 360° portfolio of consulting services, we combine excellent industry expertise with a broad range of cross-industry competencies, work interdisciplinary, and think beyond the horizon. Our partner companies and freelancers: Freelancers can offer us comprehensive perspectives within our own projects and support as long-term framework partners for filling project vacancies - quickly and directly.
We look forward to your contact!
Your direct point of contact at Wavestone
Alexander Schwalm
Phone: +49 174 163 89 54
Email:
Required skills
Sign up to apply
Create a free account to apply for this job and get access to:
- AI-powered CV optimization for this specific job
- Save jobs and create custom alerts
- See your CV match score for each job
Company information
- Company
- Wavestone Germany AG
- Location
-
Munich
Germany - Posted
- 6 months ago
Interested in this position?
Create your free account and tailor your CV to match this job.