Haystack
← Back to Jobs
Temporary/Casual
Engineering
TT

Microsoft PKI SME (Engineer)

TXP Technology x PeopleBath, Bath & N E Somerset🇬🇧United KingdomPosted 9 Oct 2026

Why This Role Stands Out

This contract offers a fantastic opportunity to lead the implementation of a critical Microsoft PKI solution in a greenfield environment, providing significant hands-on experience and technical ownership. You'll thrive here if you're a seasoned PKI SME with proven expertise in Microsoft AD CS, eager to drive a high-impact project from build to hypercare. Apply now to leverage your skills and contribute to a cutting-edge enterprise deployment.

Quick Overview

Seniority
Mid Senior
Employment type
Temporary/Casual
Work mode
On Site
Location
Bath, Bath & N E Somerset, United Kingdom
Posted
Yesterday

Job Description

PKI SME Engineer - Microsoft AD CS

Rate: £520 per day Inside IR35
Contract: 6-12 Months (Subject to Extension)
Location: Remote with some occasional travel onsite to Bath.

Overview

We are seeking an experienced PKI SME Engineer to lead the hands-on implementation of a Microsoft Public Key Infrastructure (PKI) solution within a greenfield enterprise environment.

This is a delivery-focused role requiring a technical specialist with proven experience deploying Microsoft Active Directory Certificate Services (AD CS) at enterprise scale. The successful candidate will be responsible for building, configuring, testing, and transitioning a production-ready PKI capability into service, followed by a period of focused post-go-live hypercare.

Working from established designs and architecture, you will take ownership of the implementation, integration, testing, and operational handover of the PKI platform, ensuring it is secure, scalable, and production-ready.

Role Purpose

The PKI SME Engineer is responsible for the end-to-end delivery of a Microsoft PKI solution within a new enterprise environment.

You will carry out the technical implementation of Microsoft Active Directory Certificate Services (AD CS), integrating the service into enterprise infrastructure and validating the platform through comprehensive testing before supporting production cutover and hypercare activities.

This role is focused on technical delivery, testing, transition, and post-go-live support rather than solution design.

Key Responsibilities

PKI Platform Implementation

  • Build and configure a greenfield Microsoft PKI environment based on approved architectural designs.
  • Prepare and validate all platform prerequisites, including Windows Server, Active Directory, DNS, networking, service accounts, and security groups.
  • Install and configure:
  • Offline Root Certificate Authority (CA)
  • Enterprise Issuing Certificate Authorities
  • Active Directory Certificate Services (AD CS) components
  • Supporting PKI infrastructure services

Certificate Services Configuration

  • Configure and manage certificate templates, policies, and permissions.
  • Implement auto-enrolment, certificate renewal, and certificate revocation processes.
  • Configure and validate Certificate Revocation Lists (CRLs), certificate chain publication, and supporting services.
  • Implement and support OCSP and NDES services where required.

Integration & Validation

  • Integrate PKI services with Active Directory and enterprise infrastructure.
  • Support integration with applications, devices, endpoints, and hybrid environments.
  • Execute build verification testing and functional validation activities.
  • Troubleshoot and resolve implementation defects and technical issues.

Go-Live & Hypercare

  • Support production deployment and service cutover activities.
  • Provide post-go-live hypercare support.
  • Investigate and resolve certificate, trust, authentication, and enrolment issues.
  • Work closely with operational support teams to ensure a smooth transition to business-as-usual support.

Documentation & Handover

  • Produce comprehensive as-built documentation.
  • Create operational runbooks and configuration records.
  • Document testing outcomes and implementation activities.
  • Deliver knowledge transfer sessions to support and operational teams.

Essential Technical Skills

Microsoft PKI Expertise

  • Strong hands-on experience implementing Microsoft Active Directory Certificate Services (AD CS).
  • Enterprise Certificate Authority (CA) deployment and administration.
  • Certificate lifecycle management.

PKI Technologies

  • Certificate Templates
  • Auto-Enrolment
  • Certificate Revocation Lists (CRL)
  • Online Certificate Status Protocol (OCSP)
  • Network Device Enrolment Service (NDES)
  • Certificate Chain Management
  • Trust Validation

Microsoft Infrastructure

  • Windows Server
  • Active Directory
  • Group Policy
  • DNS
  • PowerShell Scripting

Enterprise Integration

  • Integration of PKI with enterprise infrastructure and applications.
  • Experience supporting hybrid and on-premises environments.
  • Knowledge of identity, authentication, and security services.

Troubleshooting

  • Certificate chain troubleshooting.
  • TLS and SSL certificate troubleshooting.
  • Service authentication and trust-related issue resolution.
  • Certificate enrolment and renewal diagnostics.

Required Experience

  • Proven hands-on experience delivering enterprise PKI implementations.
  • Extensive experience deploying Microsoft AD CS environments.
  • Experience building and configuring enterprise-scale PKI solutions.
  • Strong background working across both on-premises and hybrid infrastructures.
  • Demonstrated experience supporting production deployments and post-go-live hypercare activities.

Desirable Skills

  • Microsoft security technologies.
  • Enterprise identity and access management solutions.
  • Infrastructure automation using PowerShell.
  • Experience within highly regulated or security-sensitive environments.
  • Knowledge of certificate-based authentication and enterprise security frameworks.

Similar jobs