Career Opportunities: SENIOR SYSTEMS ENGINEER- PKI (REMOTE) (1420184)

Remote: 
Full Remote
Contract: 
Work from: 

Offer summary

Qualifications:

5+ years of experience in infrastructure or security engineering roles with hands-on PKI and Active Directory responsibilities., Proficiency with Microsoft Active Directory Certificate Services (ADCS) and enterprise CA administration., Advanced scripting skills in PowerShell; Bash or Python is a plus., Deep understanding of TLS/SSL, OCSP, CRL, and certificate trust models..

Key responsibilities:

  • Administer and support enterprise certificate authorities in a hybrid environment.
  • Deploy and automate TLS/SSL certificates across internal and public-facing systems.
  • Serve as a senior engineer and subject matter expert for Microsoft Active Directory in a multidomain enterprise.
  • Collaborate on projects involving authentication, PKI-based access, federation, and identity management.

Morrison Healthcare logo
Morrison Healthcare Food & Beverages XLarge https://www.morrisonhealthcare.com/
10001 Employees
See all jobs

Job description

 

Salary:  $110,000-$118,000

 

 

Who We Are

Compass Technology is a dedicated internal team for Compass Group delivering enterprise-wide initiatives that support our diverse customer base and enhance our business operations. 

 

Our domain encompasses a vast spectrum of opportunities, from hands-on desk support to Cybersecurity, Cloud Engineering, AI, and Modern Application development. We are committed to building robust IT infrastructures, driving digital transformation, and much more. 

 

Compass Group is the leading foodservice management and support services company, with $26 billion in revenue in 2023.

 

In 2023, Compass Group was named one of Forbes’ America’s Best Large Employers along Springbuk’s Healthiest 100 Workplaces in America (since 2019).

Position Overview

The PKI Engineer is responsible for the ongoing management, support, and operational
maturity of Compass Group's enterprise Public Key Infrastructure (PKI) and enterprise-level
Active Directory environment. This senior-level role supports secure certificate lifecycle
management and core directory services across multiple domains in both on-premises and
AWS environments. The engineer collaborates with Cloud Operations, Security Architecture,
and Infrastructure teams to ensure secure, highly available, and scalable identity and certificate
services.

Key Responsibilities

Public Key Infrastructure (PKI)

  • Administer and support enterprise certificate authorities (Root and Subordinate CAs) in a hybrid environment.
  • Operate and maintain certificate lifecycle tools, including Venafi (required), AppViewX, Certmonger, Centrify, and AWS Certificate Manager (ACM).
  • Deploy and automate TLS/SSL certificates across internal and public-facing systems.
  • Monitor PKI services for performance, availability, and compliance with Compass security standards.
  • Automate certificate issuance, renewal, and revocation using scripting tools such as PowerShell and Bash.
  • Troubleshoot certificate issues across diverse systems and applications in Windows and Linux environments.
  • Maintain clear documentation of PKI processes, policies, and procedures for internal use and audits.
  • Partner with security and architecture teams to enforce and enhance certificate issuance policies.

 

Active Directory (AD)

  • Serve as a senior engineer and subject matter expert for Microsoft Active Directory in a multidomain enterprise.
  • Design, manage, and troubleshoot Group Policy Objects (GPOs) to enforce security baselines and configuration standards.
  • Support key AD components, including DNS, DHCP, replication, Sites and Services, FSMO role health, and AD-integrated applications.
  • Lead AD modernization efforts, including version upgrades, domain controller lifecycle, and hybrid identity integration.
  • Create and maintain automation scripts for Active Directory operations using PowerShell.
  • Manage privileged identities and support Group Managed Service Account (gMSA) implementations.
  • Monitor AD health, perform root cause analysis for directory-related issues, and participate in disaster recovery planning and testing.
  • Collaborate on projects involving authentication, PKI-based access, federation, and identity management.


 

Required Qualifications
  • 5+ years of experience in infrastructure or security engineering roles with hands-on PKI and Active Directory responsibilities.
  • Proficiency with Microsoft Active Directory Certificate Services (ADCS) and enterprise CA administration.
  • Proven experience with enterprise Active Directory, including GPO, DNS, replication, and secure configuration practices.
  • Experience with certificate lifecycle management platforms such as Venafi (required), AppViewX, or Certmonger.
  • Advanced scripting skills in PowerShell (required); Bash or Python is a plus.
  • Deep understanding of TLS/SSL, OCSP, CRL, and certificate trust models.
  • Strong troubleshooting skills in both Windows and Linux environments.

 

Preferred Qualifications

  • Experience with cloud-based certificate and directory services, especially AWS (e.g., ACM, AWS Directory Services).
  • Familiarity with certificate-based authentication solutions (e.g., mutual TLS, client certificates, smart cards).
  • Working knowledge of identity and access management frameworks and technologies.
  • Experience supporting Linux environments and tools related to certificate enrollment and validation.
  • Exposure to infrastructure automation, Infrastructure-as-Code (IaC), or CI/CD pipeline integration for identity and certificate services.
     

 Apply to Compass Group today!

Click here to Learn More about the Compass Story

 

Compass Group is an equal opportunity employer.  At Compass, we are committed to treating all Applicants and Associates fairly based on their abilities, achievements, and experience without regard to race, national origin, sex, age, disability, veteran status, sexual orientation, gender identity, or any other classification protected by law.

Qualified candidates must be able to perform the essential functions of this position satisfactorily with or without a reasonable accommodation. Disclaimer: this job post is not necessarily an exhaustive list of all essential responsibilities, skills, tasks, or requirements associated with this position. While this is intended to be an accurate reflection of the position posted, the Company reserves the right to modify or change the essential functions of the job based on business necessity. We will consider for employment all qualified applicants, including those with a criminal history (including relevant driving history), in a manner consistent with all applicable federal, state, and local laws, including the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance, the San Francisco Fair Chance Ordinance, and the New York Fair Chance Act. 

 

Compass Technology maintains a drug-free workplace.

 

Applications are accepted on an ongoing basis.

 

Associates at Corporate are offered many fantastic benefits.

  • Medical
  • Dental
  • Vision
  • Life Insurance/ AD
  • Disability Insurance
  • Retirement Plan
  • Paid Time Off
  • Holiday Time Off (varies by site/state)
  • Associate Shopping Program
  • Health and Wellness Programs
  • Discount Marketplace
  • Identity Theft Protection
  • Pet Insurance
  • Commuter Benefits
  • Employee Assistance Program
  • Flexible Spending Accounts (FSAs)
  • Paid Parental Leave
  • Personal Leave

Associates may also be eligible for paid and/or unpaid time off benefits in accordance with applicable federal, state, and local laws. For positions in Washington State, Maryland, or to be p formed Remotely, click here for paid time off benefits information. 

Req ID:  1420184

Compass Technology

MARY DICKSON

 

Required profile

Experience

Industry :
Food & Beverages
Spoken language(s):
English
Check out the description to know which languages are mandatory.

Other Skills

  • Troubleshooting (Problem Solving)
  • Collaboration
  • Problem Solving

System Engineer Related jobs