PKI, Cryptography and Zero Trust Architect
What engineering roles in crypto pay
205 salaries · our own dataMost engineering roles in crypto pay between $144k and $255k, with a median of $202k.
As a PKI, Cryptography, and Zero Trust Architect at Iron Bow Technologies, you will lead the architecture and modernization of the Government's enterprise PKI, key-management, HSM-backed trust, Zero Trust, and post-quantum cryptographic environment. You will define architectures that allow classical and post-quantum cryptography to coexist during the customer's phased transition. This role requires demonstrated experience designing and operating enterprise PKI and key-management architectures, along with working knowledge of FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA). The position is primarily remote with limited travel to customer facilities.
What you'll do
- Develop enterprise PKI, KMS, cryptographic, and HSM architecture supporting VA operational and cybersecurity requirements.
- Architect HSM-backed roots of trust and integration with enterprise Certificate Authorities and KMS platforms.
- Design Zero Trust cryptographic controls aligned with NIST SP 800-207 and VA Critical Security Controls.
- Integrate HSM architecture with enterprise ICAM services, machine identity, authentication, authorization, and least-privilege controls.
- Design hybrid classical and post-quantum cryptographic architectures supporting phased PQC adoption.
- Architect parallel PQC and hybrid CA hierarchies to enable transition without disruption to production PKI.
- Develop approaches for cross-certification, new trust-anchor distribution, certificate issuance and validation, revocation, OCSP, and enrollment.
- Support development of the Zero Trust Implementation Plan and define measurable Zero Trust maturity targets.
- Design management-plane segmentation, mutually authenticated communications, machine identity, privileged-access controls, quorum control, and tamper-evident audit capabilities.
- Support development and maintenance of the Crypto Agility Plan and Cryptographic Bill of Materials.
- Evaluate architectural impacts of evolving NIST, IETF, CNSA 2.0, and Federal cryptographic standards.
What you bring
- Demonstrated enterprise PKI architecture and operations experience.
- Demonstrated enterprise KMS and HSM architecture experience.
- Strong understanding of Zero Trust architecture and NIST SP 800-207.
- Experience with HSM-backed roots of trust and enterprise ICAM integration.
- Working knowledge of FIPS 203, FIPS 204, and FIPS 205 and their HSM implementation implications.
- Demonstrated experience designing hybrid classical and post-quantum cryptographic architectures or cryptographic modernization strategies.
Nice to have
- CISSP-ISSAP, SABSA, TOGAF, or comparable security and architecture credentials.
- Experience with Federal ICAM/FICAM and PIV/CAC environments.
- Experience with Microsoft ADCS and enterprise certificate services.
- Experience designing PQC migration strategies for large enterprise environments.
About Iron Bow Technologies
Iron Bow Technologies is a next-generation solutions provider delivering mission success across government, healthcare, and commercial industries. The company works with clients, colleagues, and partners to solve critical challenges through passionate people, long-standing partnerships, and strategic thinking.
