DigiCert is a global leader in intelligent trust, ensuring the security and authenticity of digital interactions. The PKI Compliance and Automation Engineer will join the Certificate Authority Industry Standards team, focusing on compliance automation, code validation, and collaborating with product and engineering teams to implement policy-as-code guardrails.
Responsibilities:
- Validate code against CA/B Forum BRs, EV Guidelines, S/MIME BRs, Root Program policies, RFC 5280, and CP/CPS
- Support development of policy-as-code rules under guidance from senior engineers
- Help integrate compliance checks into CI/CD pipelines
- Participate in building automated evidence collection for audits
- Implement validators and monitors for certificate lifecycle operations to ensure continuous compliance
- Collaborate with team to improve developer experience and reduce false positives
Requirements:
- Bachelor's degree in Computer Science, Software Engineering, Information Security, or equivalent practical experience
- 2+ years of experience in software development, security, or compliance engineering
- Ability to read and understand code (Python, Go, Java, or similar languages)
- Familiarity with PKI concepts (certificate lifecycle, Domain Control Verification methods) and eagerness to learn CA/Browser Forum standards
- Exposure to CI/CD pipelines and willingness to learn compliance automation tools
- Curiosity and willingness to learn PKI compliance engineering
- Standards Translation: Turn industry policies into precise policy-as-code
- Technical Analysis: Parse complex issuance code paths, DCV implementations, and profile renderers
- Basic understanding of security principles and automation mindset to build reliable shift-left guardrails that block non-compliance pre-merge and pre-issuance
- Attention to detail when reviewing code and configurations
- Strong communication skills and ability to work in a team environment
- Some experience with PKI tools such as zlint/cablint, OpenSSL/CFSSL, ASN.1 tooling, RFC 5280 path validation test suites
- Kubernetes/cloud experience (OPA Gatekeeper/Kyverno, AWS/Azure/GCP)
- HSM operations (PKCS#11), FIPS 140-2/140-3 familiarity