Skip to main content
close Search Jobs

Senior PKI Engineer

Southlake, TX ; Phoenix, AZ
Requisition ID 2026-122977 Category Engineering & Software Development Position type Regular Pay range USD $145,000.00 - $190,000.00 / Year Application deadline 2026-08-22
Apply

Your opportunity


At Schwab, you’re empowered to make an impact on your career. Here, innovative thought meets creative problem solving, helping us “challenge the status quo” and transform the finance industry together.

We believe in the importance of in-office collaboration and fully intend for the selected candidate for this role to work on site in the specified location(s).

At Schwab, you’re empowered to make an impact on your career. Here, innovative thought meets creative problem solving, helping us challenge the status quo and transform the finance industry together. Schwab’s Cybersecurity organization is the first line of defense for the Firm, and the Senior Security Engineer on the Public Key Infrastructure PKI team will play a key role in designing, implementing, and maintaining enterprise PKI controls that reduce risk and support Schwab’s security policies and standards.

We are looking for a senior, hands-on security engineer with strong experience in Public Key Infrastructure, certificate lifecycle management, trust models, automation, and enterprise security engineering. This role will support PKI capabilities across on-prem, SaaS, and IaaS cloud-based environments, with responsibility for managing and improving Certificate Authorities CAs, Registration Authorities RAs, Hardware Security Modules HSMs, and X.509 certificate lifecycle processes across a large enterprise environment.

This is a senior engineering role focused on building reliable, scalable, and automated PKI services that other teams depend on. The right candidate will bring strong technical judgment around certificate lifecycle risks, trust chains, validation, renewal failure modes, and system integrations, while also being able to partner across cybersecurity, infrastructure, application, and engineering teams to deliver secure and reliable PKI solutions.

What You’ll Do

  • Architect, deploy, maintain, and enhance enterprise PKI infrastructure, including Certificate Authorities CAs, Registration Authorities RAs, Hardware Security Modules HSMs, and related certificate services.
  • Implement and maintain issuance, renewal, revocation, and lifecycle management processes for digital certificates used by users, servers, applications, services, and devices across the organization.
  • Design and build automation that improves PKI reliability, reduces manual effort, and scales certificate lifecycle management across enterprise environments.
  • Apply PKI, certificate, and trust concepts when designing or reviewing system architectures, platform integrations, authentication flows, access control mechanisms, and security automation.
  • Integrate PKI solutions with security systems, applications, infrastructure platforms, developer workflows, and enterprise technology services.
  • Identify and address trust failures, certificate lifecycle risks, validation gaps, automation issues, and potential sources of outages or security exposure.
  • Conduct security assessments and audits of PKI systems to identify vulnerabilities, operational risks, and opportunities for improvement.
  • Drive complex technical initiatives from design through delivery using cybersecurity practices, software engineering principles, agile delivery methods, and strong stakeholder engagement.
  • Partner closely with Data Protection, Cybersecurity, infrastructure, application, developer, and engineering teams to ensure PKI services meet business, security, and operational needs.
  • Translate technical PKI and trust requirements into practical, repeatable engineering patterns that can be adopted across teams.

What you have


Required Qualifications

  • 5+ years of hands-on experience in network security, data security, PKI, certificate management, or other cybersecurity-related controls and technologies.
  • Strong understanding of Public Key Infrastructure PKI principles, including certificate lifecycle management, trust chains, validation, renewal, revocation, and common failure modes.
  • Experience managing or supporting enterprise PKI technologies such as Microsoft Active Directory Certificate Services AD CS, Entrust, Venafi, or other commercial PKI solutions.
  • Experience with Certificate Lifecycle Management automation using tools and scripting/coding such as Venafi, PowerShell, and Python; GitHub and .NET experience are highly desired.
  • Experience managing or working with Hardware Security Modules HSMs.
  • Strong software engineering or automation background with the ability to design, build, and maintain services or automation that operate reliably at scale.
  • Experience integrating PKI with authentication, access control, applications, infrastructure platforms, or enterprise security systems.
  • Ability to assess system designs and identify trust, identity, certificate, or cryptographic risks without requiring deep cryptographic research or protocol design specialization.
  • Proven ability to deliver high-visibility, high-impact cybersecurity projects with cross-functional teams while maintaining strong results across planning, requirements, design, testing, and deployment.
  • Strong communication skills with the ability to translate technical information for different audiences and influence stakeholders across multiple levels of the organization.
  • Bachelor’s degree in computer science or a related field highly preferred.

Preferred Qualifications

  • Cybersecurity or data protection certifications such as CISSP, GIAC, CISM, CCSP, CISA, Security+, or related certifications.
  • Experience with secure SDLC, threat modeling, vulnerability remediation workflows, application security, or platform security engineering.
  • Exposure to identity, authentication, access management, or broader trust and platform security engineering concepts.
  • Familiarity with AI-assisted development or AI security controls is a plus, but the primary focus of this role remains PKI, certificate lifecycle management, and trust engineering.


What’s in it for you

At Schwab, you’re empowered to shape your future. We champion your growth through meaningful work, continuous learning, and a culture of trust and collaboration—so you can build the skills to make a lasting impact. Our Hybrid Work and Flexibility approach balances our ongoing commitment to workplace flexibility, serving our clients, and our strong belief in the value of being together in person on a regular basis.

We offer a competitive benefits package that takes care of the whole you – both today and in the future:

  • 401(k) with company match and Employee stock purchase plan
  • Paid time for vacation, volunteering, and 28-day sabbatical after every 5 years of service for eligible positions
  • Paid parental leave and family building benefits
  • Tuition reimbursement
  • Health, dental, and vision insurance
Apply

Eligible Schwabbies receive

  • Medical, dental and vision benefits

  • 401(k) and employee stock purchase plans

  • Tuition reimbursement to keep developing your career

  • Paid parental leave and adoption/family building benefits

  • Sabbatical leave available after five years of employment