PKI Engineer
Certificate authorities, HSMs, key rotation, signing infrastructure.
Tiny market, deep specialism, almost recession-proof if you're properly competent. Take it knowing you'll be one of very few who understand it.
- You enjoy long-lived systems that can't be casually rebuilt
- You're meticulous about lifecycle, expiry and rotation
- You like being the person three teams call when nothing else makes sense
- You're patient with cryptographic specs and vendor implementations that drift
- You want fast iteration, PKI cycles in years
- You can't tolerate work where one small mistake breaks everything
- You'd struggle being the only person in the room who knows the topic
- Your CA migrations go in cleanly with no surprise outage
- Auditors leave PKI alone in your environment
- You've automated certificate lifecycle in a way the next engineer can maintain
- You can explain trust hierarchies to leadership without losing them
Specialism is a double edge. There are very few PKI roles in the UK, but each one is hard to fill, so the people who hold the seat tend to stay until they retire. That stability is the upside. The downside is you can become unmoveable, and your skills are easy to pigeonhole. Pair PKI with broader IAM or cloud security work, not just deeper PKI, if you want the option to leave.
Tradeoffs at a glance
Hover any chip for the calibrated meaning. Ratings are directional, not absolute.
Promotion ceiling
Moderate but well-paid, small market, hard to displace.
- +Security Engineer
- +Cryptography enthusiast
- +Senior sysadmin
- −That it's a dying skill, modern zero-trust pushed demand up, not down.
Where this leads
- IAM
- Cloud Security
- Cryptography Engineer
Pathways that pass through here
Where this fits
Roles connect to pathways, certs and other roles. Use one to test the next.
- Enterprise IT. Windows / AD / M365
The Microsoft-shop spine. A durable, hireable lane and a direct on-ramp to security, cloud and IAM.
- Identity Security (IAM, PAM, SSO)
Engineer the identity layer. Entra ID, Okta, CyberArk, PAM, SSO, MFA, Zero Trust. Operational, technical, in demand.
- GRC (Audit, Risk, Compliance)
Governance, risk and compliance. Policy, audit, evidence, frameworks. Biased toward CISA / CRISC / CISM, NOT toward OSCP.
The serious next step
You've read about the role. The harder question is whether it's the right one for you.
A Career Verdict is the written, practitioner-authored call on your specific route into and out of this role. Six primitives, same format every time.
Built on POST's practitioner-authored assessment framework, calibrated by James from twenty years across helpdesk, infrastructure and security. Framework is human-authored; the verdict applies it to your inputs.