MENU
  • Remote Jobs
  • Companies
  • Go Premium
  • Job Alerts
  • Post a Job
  • Log in
  • Sign up
Working Nomads logo Working Nomads
  • Remote Jobs
  • Companies
  • Post Jobs
  • Go Premium
  • Get Free Job Alerts
  • Log in

Microsoft Active Directory Public Key Infrastructure (AD PKI) Expert

MetroSys

Freelance / Contract
USA
security
automation
compliance
Apply for this position

Position Summary:

We are seeking a Microsoft Active Directory Public Key Infrastructure (AD PKI) Expert for a short-term engagement to conduct a deep-dive discovery, analysis, and review of our existing PKI environment. The consultant will provide a detailed report on the current state, along with recommendations and options for migration, separation, and alternative on-premises or cloud-based architectures.

Key Responsibilities:

  • Deep-Dive PKI Discovery & Assessment:

    • Conduct a thorough review of the existing AD PKI infrastructure, including Certificate Authorities (CAs), Certificate Templates, CRL distribution, and Auto-Enrollment policies.

    • Analyze dependencies, security configurations, and compliance gaps.

    • Evaluate PKI integration with Active Directory, network services, and enterprise applications.

  • Analysis & Reporting:

    • Provide a detailed assessment report outlining the current PKI architecture, strengths, weaknesses, and risks.

    • Identify potential issues, security vulnerabilities, and areas for improvement.

    • Offer guidance on best practices for PKI security hardening and lifecycle management.

  • Migration & Separation Strategy:

    • Provide expert recommendations on PKI migration and separation strategies, considering:

      • Splitting PKI environments for multiple organizations or business units.

      • Migrating from on-premises to cloud-based PKI solutions (e.g., Microsoft Intune SCEP, AWS Private CA, or Azure Key Vault).

      • Transitioning from legacy PKI to a modern, scalable architecture.

    • Assess the impact of moving to cloud-native, hybrid, or third-party PKI solutions.

  • Future-State Architecture & Roadmap:

    • Design and present high-level architecture options tailored to business requirements.

    • Provide recommendations for governance, automation, and certificate lifecycle management.

    • Suggest enhancements for security, compliance, and resilience (e.g., HSM integration, CRL optimization, OCSP setup).

Qualifications & Skills:

  • Expert-level knowledge of Microsoft AD Certificate Services (AD CS), PKI design, implementation, and security best practices.

  • Experience with certificate lifecycle management, HSMs, and enterprise PKI solutions.

  • Strong understanding of certificate-based authentication, encryption, and digital signatures.

  • Hands-on experience in PKI migrations, separation strategies, and hybrid cloud PKI deployments.

  • Familiarity with cloud-based PKI alternatives, such as Microsoft Intune SCEP, AWS Private CA, or Azure Key Vault.

  • Experience with PowerShell scripting for automation of PKI-related tasks.

  • Knowledge of compliance frameworks (NIST, CIS, ISO 27001) and PKI security hardening techniques.

  • Relevant certifications (preferred): Microsoft Certified: Identity and Access Administrator, CISSP, CISM, or other security-related certifications.

Apply for this position
Bookmark Report

About the job

Freelance / Contract
USA
Posted 1 hour ago
security
automation
compliance

Apply for this position

Bookmark
Report
Enhancv advertisement

30,000+
REMOTE JOBS

Unlock access to our database and
kickstart your remote career
Join Premium

Microsoft Active Directory Public Key Infrastructure (AD PKI) Expert

MetroSys

Position Summary:

We are seeking a Microsoft Active Directory Public Key Infrastructure (AD PKI) Expert for a short-term engagement to conduct a deep-dive discovery, analysis, and review of our existing PKI environment. The consultant will provide a detailed report on the current state, along with recommendations and options for migration, separation, and alternative on-premises or cloud-based architectures.

Key Responsibilities:

  • Deep-Dive PKI Discovery & Assessment:

    • Conduct a thorough review of the existing AD PKI infrastructure, including Certificate Authorities (CAs), Certificate Templates, CRL distribution, and Auto-Enrollment policies.

    • Analyze dependencies, security configurations, and compliance gaps.

    • Evaluate PKI integration with Active Directory, network services, and enterprise applications.

  • Analysis & Reporting:

    • Provide a detailed assessment report outlining the current PKI architecture, strengths, weaknesses, and risks.

    • Identify potential issues, security vulnerabilities, and areas for improvement.

    • Offer guidance on best practices for PKI security hardening and lifecycle management.

  • Migration & Separation Strategy:

    • Provide expert recommendations on PKI migration and separation strategies, considering:

      • Splitting PKI environments for multiple organizations or business units.

      • Migrating from on-premises to cloud-based PKI solutions (e.g., Microsoft Intune SCEP, AWS Private CA, or Azure Key Vault).

      • Transitioning from legacy PKI to a modern, scalable architecture.

    • Assess the impact of moving to cloud-native, hybrid, or third-party PKI solutions.

  • Future-State Architecture & Roadmap:

    • Design and present high-level architecture options tailored to business requirements.

    • Provide recommendations for governance, automation, and certificate lifecycle management.

    • Suggest enhancements for security, compliance, and resilience (e.g., HSM integration, CRL optimization, OCSP setup).

Qualifications & Skills:

  • Expert-level knowledge of Microsoft AD Certificate Services (AD CS), PKI design, implementation, and security best practices.

  • Experience with certificate lifecycle management, HSMs, and enterprise PKI solutions.

  • Strong understanding of certificate-based authentication, encryption, and digital signatures.

  • Hands-on experience in PKI migrations, separation strategies, and hybrid cloud PKI deployments.

  • Familiarity with cloud-based PKI alternatives, such as Microsoft Intune SCEP, AWS Private CA, or Azure Key Vault.

  • Experience with PowerShell scripting for automation of PKI-related tasks.

  • Knowledge of compliance frameworks (NIST, CIS, ISO 27001) and PKI security hardening techniques.

  • Relevant certifications (preferred): Microsoft Certified: Identity and Access Administrator, CISSP, CISM, or other security-related certifications.

Working Nomads

Post Jobs
Premium Subscription
Sponsorship
Free Job Alerts

Job Skills
API
FAQ
Privacy policy
Terms and conditions
Contact us
About us

Jobs by Category

Remote Administration jobs
Remote Consulting jobs
Remote Customer Success jobs
Remote Development jobs
Remote Design jobs
Remote Education jobs
Remote Finance jobs
Remote Legal jobs
Remote Healthcare jobs
Remote Human Resources jobs
Remote Management jobs
Remote Marketing jobs
Remote Sales jobs
Remote System Administration jobs
Remote Writing jobs

Jobs by Position Type

Remote Full-time jobs
Remote Part-time jobs
Remote Contract jobs

Jobs by Region

Remote jobs Anywhere
Remote jobs North America
Remote jobs Latin America
Remote jobs Europe
Remote jobs Middle East
Remote jobs Africa
Remote jobs APAC

Jobs by Skill

Remote Accounting jobs
Remote Assistant jobs
Remote Copywriting jobs
Remote Cyber Security jobs
Remote Data Analyst jobs
Remote Data Entry jobs
Remote English jobs
Remote Spanish jobs
Remote Project Management jobs
Remote QA jobs
Remote SEO jobs

Jobs by Country

Remote jobs Australia
Remote jobs Argentina
Remote jobs Brazil
Remote jobs Canada
Remote jobs Colombia
Remote jobs France
Remote jobs Germany
Remote jobs Ireland
Remote jobs India
Remote jobs Japan
Remote jobs Mexico
Remote jobs Netherlands
Remote jobs New Zealand
Remote jobs Philippines
Remote jobs Poland
Remote jobs Portugal
Remote jobs Singapore
Remote jobs Spain
Remote jobs UK
Remote jobs USA


Working Nomads curates remote digital jobs from around the web.

© 2025 Working Nomads.