PKI Engineer
Certificate authorities, HSMs, key rotation, signing infrastructure.
Tiny market, deep specialism, almost recession-proof if you're properly competent. Take it knowing you'll be one of very few who understand it.
- Domain
- Cybersecurity
- Entry
- £32–52k
- Senior
- £95–135k
- You enjoy long-lived systems that can't be casually rebuilt
- You're meticulous about lifecycle, expiry and rotation
- You like being the person three teams call when nothing else makes sense
- You're patient with cryptographic specs and vendor implementations that drift
- You want fast iteration, PKI cycles in years
- You can't tolerate work where one small mistake breaks everything
- You'd struggle being the only person in the room who knows the topic
What "doing well" looks like in the seat
- Your CA migrations go in cleanly with no surprise outage
- Auditors leave PKI alone in your environment
- You've automated certificate lifecycle in a way the next engineer can maintain
- You can explain trust hierarchies to leadership without losing them
Specialism is a double edge. There are very few PKI roles in the UK, but each one is hard to fill, so the people who hold the seat tend to stay until they retire. That stability is the upside. The downside is you can become unmoveable, and your skills are easy to pigeonhole. Pair PKI with broader IAM or cloud security work, not just deeper PKI, if you want the option to leave.
Tradeoffs at a glance
Hover any chip for the calibrated meaning. Ratings are directional, not absolute.
Promotion ceiling
Moderate but well-paid, small market, hard to displace.
Who actually gets in
- +Security Engineer
- +Cryptography enthusiast
- +Senior sysadmin
Common misconceptions
- −That it's a dying skill, modern zero-trust pushed demand up, not down.
Where this leads
- IAM
- Cloud Security
- Cryptography Engineer
Pathways that pass through here
What this is based on
Practitioner judgement. External evidence review pending.
Last reviewed: not yet reviewed · UK market
Where this fits
Roles connect to pathways, certs and other roles. Use one to test the next.
- Enterprise IT. Windows / AD / M365
The Microsoft-shop spine. A durable, hireable lane and a direct on-ramp to security, cloud and IAM.
- Identity Security (IAM, PAM, SSO)
Engineer the identity layer. Entra ID, Okta, CyberArk, PAM, SSO, MFA, Zero Trust. Operational, technical, in demand.
- GRC (Audit, Risk, Compliance)
Governance, risk and compliance. Policy, audit, evidence, frameworks. Biased toward CISA / CRISC / CISM, NOT toward OSCP.
The next step
You've read about the role. The harder question is whether it's the right one for you.
A Career Verdict is the written, practitioner-authored call on your specific route into and out of this role. Six primitives, same format every time.
A route shows what is possible. A Career Verdict makes the call.
Career Verdict
Helpdesk → Security Architect
- 01The callA clear judgement on whether your route is realistic, and under what conditions.
- 02Where the route breaksThe most likely point to stall, and why it happens in practice.
- 03What to do nextSpecific priorities for the next 6–24 months, and what to drop.
Career Verdict
- The callA single written judgement on whether the route is realistic for you.
- Plateaus and failure modesThe flat years and the specific ways this route tends to stall.
- Where you standThe strongest and weakest parts of your current position, named.
- Salary realityWhat this route actually pays, set against what you've been told it pays.
Usually within minutes of payment. Kept 24 months, then deleted. Deletion on request at any time.
Built on POST's practitioner-authored assessment framework, informed by two decades across helpdesk, infrastructure and security. The verdict applies that framework to your inputs.