At Delta Air Lines, connection is at the heart of everything we do and guides our every action. We strive to welcome and care for all of our customers during their travels with us and aim to deliver an elevated experience.
Delta is focused on sustaining a strong IT operation, growing our capabilities, and maximizing optimization across each of our tech hubs to elevate the travel experience for our customers and empower our 90,000 Delta people.
We’re committed to fostering innovation, and we’re excited to invite you to be part of our journey as we shape the future of technology at the world’s best airline!
The PKI Engineer is responsible for designing, operating, and enhancing the enterprise Public Key Infrastructure (PKI) and certificate management services. This role ensures secure authentication, encryption, and certificate lifecycle management across enterprise systems, supporting regulatory compliance and operational stability.
This position plays a critical role in scaling PKI services, driving automation, and reducing operational risk associated with certificate expiration, trust store management, and cryptographic operations.
YOUR RESPONSIBILITIES IN THIS ROLE:1. PKI Infrastructure & Operations
- Maintain and operate PKI platforms, including Certificate Authorities (CAs), HSMs, and certificate management systems
- Ensure availability, resiliency, and patching of PKI infrastructure
- Support certificate issuance, renewal, revocation, and lifecycle management
2. Certificate Lifecycle Management- Manage large-scale certificate environments across applications and infrastructure
- Ensure timely renewal and replacement of certificates
- Support trust store management and certificate chain integrity
3. Automation & Integration- Build and implement automation for certificate lifecycle management
- Integrate PKI services with enterprise platforms (CI/CD pipelines, cloud services, applications)
- Deploy and operationalize tools such as connectors and automation pipelines
4. Governance, Standards & Policy Enforcement- Enforce security policies related to certificate usage and cryptography
- Define and maintain standards for certificate issuance, validity, and usage
- Support compliance with regulatory frameworks (e.g., NIST, CMMC, PCI, TSA directives)
5. Cross-Team Collaboration- Partner with application and infrastructure teams to enable certificate automation
- Provide guidance and supporting tooling while ensuring clear ownership boundaries
- Assist teams with onboarding to PKI services and automation
6. Risk Reduction & Incident Support- Identify and remediate risks related to certificate expiration, misconfiguration, or trust failures
- Support incident response involving certificate or encryption issues
- Improve visibility and reporting for certificate health and compliance
7. Emerging Crypto & Future Readiness- Support adoption of new cryptographic standards (e.g., post-quantum cryptography)
- Assist in modernization of PKI architecture and tooling
- Evaluate new solutions for scalability and resilience