Job Description
Job Description
Overview
WORK ENVIRONMENT
The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of the job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.
Location: On-site, DISA Headquarters, 6914 Cooper Ave, Fort Meade, MD 20755
Type of environment: Office - on-site at a Government facility (classified environment)
Noise level: Low to Medium
Work schedule: Day shift Monday - Friday. May be requested to work evenings and weekends to meet program and contract needs.
Amount of Travel: Less than 10%. Occasional travel within the National Capital Region and to up to four (4) conferences per year.
WORK AUTHORIZATION/SECURITY CLEARANCE
U.S. Citizen
Secret clearance
PHYSICAL DEMANDS
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. While performing the duties of this job, the employee is regularly required to use hands to handle, feel, touch; reach with hands and arms; talk and hear. The employee is regularly required to stand; walk; sit; climb or balance; and stoop, kneel, crouch, or crawl. The employee is regularly required to lift up to 10 pounds. The employee is frequently required to lift up to 25 pounds; and up to 50 pounds. The vision requirements include close vision, distance vision, peripheral vision, depth perception, and ability to adjust focus.
OTHER INFORMATION
Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice
Responsibilities
We are seeking a PKI Subject Matter Expert - Cryptographic Modernization (PQC, Algorithm Evolution & NPE) - Key Personnel to join our team supporting the DISA PKI Public Key Enablement (PKE) Engineering Support Task Order (SETI Small Business) in Fort Meade, Maryland.
REQUIRED QUALIFICATIONS
Experience
- Ten (10) or more years of hands-on PKI, cryptographic engineering, or cryptographic infrastructure experience, including at least five (5) years in DoD or federal high-security environments.
- Hands-on, low-level technical proficiency in cryptographic infrastructure and system integration within high-security environments, with demonstrated capability to engineer solutions for complex hardware and legacy software integrations.
- Demonstrated understanding of the mathematics, protocols, and hardware that drive public key cryptography.
- Practical, demonstrable knowledge of NIST post-quantum standards (FIPS 203 ML-KEM, FIPS 204 ML-DSA, FIPS 205 SLH-DSA) and the engineering steps to migrate production systems to quantum-safe states.
- Expertise automating certificate lifecycles for Non-Person Entities (routers, firewalls, microservices, Kubernetes) using automated certificate management protocols (ACME, EST).
- Hands-on experience with Hardware Security Modules (Entrust, Thales, SafeNet), key ceremonies, and HSM lifecycle or refresh activities.
- Experience with Certificate Authority platforms, preferably Red Hat Certificate System, including CA stand-up, configuration, and certificate profile management across classified and unclassified domains.
- Working knowledge of DoD PKI policy, DoDI 8520.02, STIG application, and the DoD PKI Authority to Operate (ATO) accreditation process.
- Familiarity with the DoD PKE custom tool suite (e.g., InstallRoot, FileSigner, CRL Auto Cache, PITT) and software development in C++, C#, Java, Python, or Rust is strongly preferred.
Certifications
- Certification: DoD 8140 Cyber Workforce Qualification Program, IAT Level III or equivalent, required at time of assignment
Education
- Education: Bachelor's degree in Computer Science, Cybersecurity, Mathematics, Engineering, or a related field. Master's degree preferred; equivalent demonstrated technical experience may be considered.
Clearance
- Clearance: Active Secret clearance required. Must be onboard at the start of the Period of Performance.
RESPONSIBILITIES
- Serve as the senior technical and cryptographic authority, the technical trust anchor for implementation, for algorithm evolution and Post-Quantum Cryptography across the DoD PKI Portfolio.
- Recommend approaches that steer the PKI program away from legacy, vulnerable cryptographic implementations.
- Develop and execute the plan to migrate DoD PKI to stronger cryptographic algorithms in accordance with NIST SP 800-131A Rev3 and the CNSA 2.0 PQC timeline, addressing encryption, digital signing, key agreement, key derivation, key wrapping, key transport, hash functions, and message authentication codes.
- Apply practical knowledge of NIST-standardized quantum-resistant algorithms, including ML-KEM and ML-DSA, and define the engineering steps required to transition existing systems to quantum-safe states.
- Maintain cryptographic agility across the portfolio in response to evolving NIST standards and Executive Order 14412, so algorithm changes are absorbed by configuration and re-test rather than re-architecture.
- Coordinate with COTS vendors (approximately 15 in the current ecosystem) to test feasibility and assess the timeliness of product transition plans; maintain the vendor tracking report and raise capability gaps to the coordination cell and Component CIOs.
- Develop and deploy PKE lab environments supporting Algorithm Evolution and PQC integration testing; document and report results to DoD working groups including the Certificate Validation Tiger Team.
- Evaluate HSM platforms for PQC readiness; HSM hardware refresh is within contract scope and the current environment uses Entrust HSMs.
- Provide Non-Person Entity (NPE) certificate management expertise, automating certificate lifecycles for routers, firewalls, microservices, and Kubernetes clusters using automated certificate management protocols such as EST and ACME.
- Support Certificate Authority Development, including CA architecture analysis, deficiency identification, Analysis of Alternatives development, and CA deployment across 42 NIPRNet and 31 SIPRNet Red Hat Certificate Authorities supporting approximately 10,000 certificate issuances per day.
- Provide input to CA deployment plans and develop and document Change Requests to modify software and hardware configurations, submitted through the PKI Configuration Management process and Remedy.
- Provide Tier III technical support for the most complex cryptographic and infrastructure issues, and review and update PKE enablement documentation as cryptographic changes are released.
Qualifications
TekSynap is a fast growing high-tech company that understands both the pace of technology today and the need to have a comprehensive well planned information management environment. “Technology moving at the speed of thought” embodies these principles – the need to nimbly utilize the best that information technology offers to meet the business needs of our Federal Government customers. Apply now to explore jobs with us at www.TekSynap.com.
We offer our full-time employees a competitive benefits package to include health, dental, vision, 401K, life insurance, short-term and long-term disability plans, vacation time and holidays.
TekSynap is a drug-free workplace. We reserve the right to conduct drug testing in accordance with federal, state, and local laws. All employees and candidates may be subject to drug screening if deemed necessary to ensure a safe and compliant working environment.
By applying to a role at TekSynap you are providing consent to receive text messages regarding your interview and employment status. If at any time you would like to opt out of text messaging, respond "STOP". As part of the application process, you agree that TekSynap Corporation may retain and use your name, e-mail, and contact information for purposes related to employment consideration.
EQUAL EMPLOYMENT OPPORTUNITY
In order to provide equal employment and advancement opportunities to all individuals, employment decisions will be based on merit, qualifications, and abilities. TekSynap does not discriminate against any person because of race, color, creed, religion, sex, sexual orientation, gender identity, protected veteran status, national origin, disability, age, genetic information or any other characteristic protected by law (referred to as “protected status”). This nondiscrimination policy extends to all terms, conditions, and privileges of employment as well as the use of all company facilities, participation in all company-sponsored activities, and all employment actions such as promotions, compensation, benefits, and termination of employment. TekSynap is committed to ensuring that our online application process provides an equal employment opportunity to all job seekers, including individuals with disabilities. If you believe you need a reasonable accommodation in order to search for a job opening or to submit an application, please contact hr@teksynap.com for assistance.
