Job Title: Identity Management - Public Key Infrastructure Administrator
Job Category: Information Technology
Time Type: Full time
Minimum Clearance Required to Start: Secret
Employee Type: Regular-Long Term Assignment
Percentage of Travel Required: Up to 10%
Type of Travel: Local
* * *
The Opportunity:
CACI is looking for a Senior Platforms Infrastructure Systems Administrator.
Responsibilities;
A contractor on the Platforms team, you will be responsible for core enterprise Windows infrastructure, with a defined specialization in certificate lifecycle automation and machine identity management. This role will lead the buildout and expansion of certificate automation capability across additional environments, working closely with the existing PKI/AD CS infrastructure rather than replacing it. You will help define the standards, integration patterns, and operational processes the team uses for certificate lifecycle management going forward, including discovery, automated renewal, and policy-based governance across servers, applications, and network devices. Outside of the certificate automation work, your core responsibilities mirror those of a senior Windows administrator: Active Directory, Group Policy, DNS/DHCP, Windows Server administration, and STIG compliance. You will also maintain baseline familiarity with CyberArk Privileged Access Management to assist the team's PAM lead when needed, though CyberArk is not your primary ownership area. As a senior team member, you are expected to document your work thoroughly, particularly the certificate automation buildout, since this documentation will help establish a repeatable reference for how certificate automation is run across the enterprise. This also includes:
- Certificate Automation Platform Administration: Lead the buildout and expansion of the enterprise certificate lifecycle automation platform, including certificate discovery, monitoring, automated renewal, and revocation across servers, applications, and network devices.
- Certificate Lifecycle Management: Manage the full certificate lifecycle including issuance, renewal, revocation, and expiration tracking, applying policy-based governance to reduce certificate-related outages and unmanaged machine identities.
- CA Integration: Integrate the certificate automation platform with internal and external Certificate Authorities, primarily Microsoft AD CS, ensuring proper alignment with the existing Root CA/Intermediate CA hierarchy, CRL distribution, and OCSP responder configuration.
- Automation and Scripting: Develop PowerShell and, where applicable, Python or REST API-based automation to streamline certificate provisioning, renewal workflows, and reporting.
- Active Directory Management: Administer and support Active Directory services including user accounts, security groups, Group Policy, and security configurations across a multi-site enterprise environment.
- DNS/DHCP Administration: Administer and troubleshoot AD-integrated DNS and DHCP services as part of broader enterprise infrastructure support.
- Windows Server Administration: Install, configure, and maintain Windows Server environments, ensuring optimal performance, reliability, and STIG compliance.
- System Security and Compliance: Ensure security of Windows and certificate infrastructure through STIG remediation, patch management, ACAS vulnerability remediation, and alignment with DISA security baselines.
- Documentation and Standards Development: Produce comprehensive documentation for the certificate automation buildout, including architecture decisions, integration points, and operational runbooks, submitted through GitLab for peer review. This documentation will help establish a standard reference for the platform going forward.
- CyberArk Awareness: Maintain baseline familiarity with CyberArk PAM operations, including vault structure and credential management concepts, sufficient to provide backup assistance when the team's CyberArk lead requires coverage.
- Monitoring and Troubleshooting: Proactively monitor certificate infrastructure and Windows platform health, identify issues, and perform troubleshooting to ensure system stability and prevent certificate-related outages.
- Collaboration: Work closely with the PKI lead, CyberArk lead, cybersecurity, and architecture teams to ensure the certificate automation work aligns with broader identity and security architecture.
More About the Role
The successful candidate must be able to communicate clearly and succinctly both written and orally, and present products and ideas in a professional manner. This role is unusual in that it combines steady-state senior Windows administration with a significant buildout effort on the certificate automation side. The candidate will need to be comfortable operating with a degree of ambiguity during the buildout phase, while also carrying standard senior-level Windows and AD responsibilities in parallel. Once the platform work matures, the role will shift toward sustainment, expansion to additional certificate use cases, and ongoing integration work as the enterprise's certificate footprint grows.
Qualifications:
Required:
- Active Secret clearance with ability to obtain and maintain a TS/SCI.
- Currently a US Citizen
- Minimum 5 years of experience in Windows systems administration with demonstrated depth in Active Directory, Group Policy, DNS/DHCP, and Windows Server in large-scale, multi-site environments.
- Experience with an enterprise certificate lifecycle automation platform (e.g., Venafi TPP or Venafi as a Service), or strong hands-on experience with enterprise PKI and certificate lifecycle management with demonstrated ability to learn a new platform quickly.
- Strong working knowledge of PKI fundamentals, X.509 certificates, TLS/SSL, CSR generation, key management, and cryptographic standards.
- Experience integrating certificate automation platforms with enterprise or public Certificate Authorities (Microsoft CA, DigiCert, Entrust, or similar).
- Advanced capabilities in designing, troubleshooting, and enforcing complex enterprise Active Directory Group Policy Objects (GPOs).
- Proven experience operating and managing lifecycle infrastructure for Certificate Authorities specifically within the DoD Space or highly regulated federal environments.
- Direct, hands-on configuration and administration experience with nCipher and Thales/Gemalto Luna HSMs for key generation, storage, and backup.
- Comprehensive understanding of configuring and maintaining OCSP, CRL, and AIA pathways for real-time validation chains.
- Strong proficiency in building, deploying, and managing custom enterprise certificate templates in an Department of War (DoW) environment.
- Holistic mastery of asymmetric cryptography, key escrows, and trust chain architecture.
- Relevant industry certifications & including CASP+ or CompTIA SecurityX or Security+ (DOD 8570/8140 required)
Desired:
- Familiarity with Federal/DoD compliance standards, including STIGs, NIST SP 800-53, and FIPS 140-2/3.
- Strong scripting skills (such as PowerShell) for automating certificate monitoring, CRL updates, or Active Directory management tasks.
- Experience with Git/GitLab for version-controlled documentation and change workflows.
- Moderate to strong scripting/automation skills in PowerShell; familiarity with Python, Bash, or REST APIs a plus.
- Proven experience in technical documentation, particularly the ability to produce reference-quality architecture and operational documentation.
- Familiarity with MECM/SCCM for endpoint management.
- Familiarity with Linux systems administration.
- Knowledge of cloud platforms (Azure, AWS) and their certificate management services.
- Experience supporting Combatant Command (CCMD) or Joint Service environments.
-
What You Can Expect:
A culture of integrity.
At CACI, we place character and innovation at the center of everything we do. As a valued team member, you’ll be part of a high-performing group dedicated to our customer’s missions and driven by a higher purpose – to ensure the safety of our nation.
An environment of trust.
CACI values the unique contributions that every employee brings to our company and our customers - every day. You’ll have the autonomy to take the time you need through a unique flexible time off benefit and have access to robust learning resources to make your ambitions a reality.
A focus on continuous growth.
Together, we will advance our nation's most critical missions, build on our lengthy track record of business success, and find opportunities to break new ground — in your career and in our legacy.
Pay Range :
There are a host of factors that can influence final salary including, but not limited to, geographic location, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, education, and certifications. Our employees value the flexibility at CACI that allows them to balance quality work and their personal lives. We offer competitive compensation, benefits and learning and development opportunities. Our broad and competitive mix of benefits options is designed to support and protect employees and their families. At CACI, you will receive comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits.
The proposed salary range for this position is:
$82,700 - 173,900 USD
CACI is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, age, national origin, disability, status as a protected veteran, or any other protected characteristic.