Company Description Egypt Trust - إيجيبت تراست is a trusted legal certificate service provider in Egypt, specializing in digital signatures and information security solutions. As a VeriSign Affiliate, the company operates under recognized international standards for secure digital transactions and identity verification. Egypt Trust supports organizations and institutions in protecting their data integrity and ensuring the legal validity of electronic documents. The company offers a professional environment for technology and security specialists who want to contribute to the growth of secure digital services in Egypt.
Role Description
The Junior PKI Engineer supports the operation, administration, monitoring, and maintenance of Public Key Infrastructure (PKI) systems and Digital Trust Services.
The role is responsible for supporting Certificate Authorities (CAs), Registration Authorities (RAs), OCSP services, Certificate Revocation Lists (CRLs), Timestamping Services (TSA), Hardware Security Modules (HSMs), and related PKI applications.
The Junior PKI Engineer works under the guidance of senior PKI engineers and follows approved security procedures, operational processes, and applicable regulatory and compliance requirements.
Key Responsibilities
1. PKI Operations
- Support the daily operation and monitoring of PKI infrastructure.
- Monitor CA, RA, OCSP, TSA, and related PKI services.
- Assist with certificate issuance, renewal, revocation, and suspension activities.
- Monitor certificate and CA service status and report abnormalities.
- Support CRL generation, publication, and monitoring.
- Support OCSP service monitoring and troubleshooting.
- Perform routine PKI operational checks according to approved procedures.
- Escalate critical incidents and service failures to the PKI Manager/Senior Engineer.
2. Certificate Authority Administration
- Assist with administration and maintenance of Issuing CA environments.
- Support CA configuration activities under supervision.
- Assist in certificate profile and certificate template configuration.
- Verify certificate extensions and attributes according to approved certificate policies.
- Support CA database and service health monitoring.
- Assist with CA certificate renewal and certificate lifecycle activities.
- Support CA migration, upgrade, and maintenance activities.
3. HSM Operations
- Assist with day-to-day HSM operational activities under approved procedures.
- Monitor HSM status, availability, and connectivity.
- Assist with HSM backup and synchronization activities.
- Support HSM partition/slot administration under supervision.
- Maintain HSM inventory and operational documentation.
- Participate in key ceremonies as an operational/support member when authorized.
- Strictly follow M-of-N, dual-control, segregation-of-duties, and key-management procedures.
Required Technical Knowledge
PKI & Cryptography
- Basic understanding of Public Key Infrastructure.
- Understanding of X.509 certificates.
- Knowledge of certificate lifecycle management.
- Understanding of Certificate Authorities (Root CA and Issuing CA).
- Basic understanding of CRL and OCSP.
- Basic understanding of TSA and RFC 3161.
- Understanding of certificate chains and trust models.
- Basic knowledge of digital signatures and public-key cryptography.
- Familiarity with RSA and ECC.
- Basic understanding of symmetric and asymmetric cryptography.
HSM
- Basic understanding of Hardware Security Modules.
- Understanding of secure key storage.
- Basic knowledge of cryptographic key lifecycle.
- Familiarity with HSM concepts such as partitions/slots, authentication, backup, and key management is preferred.
Education
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Computer Engineering, Electronics/Communication Engineering, or a related field.
Experience
- 0–2 years of experience in PKI, cybersecurity, infrastructure, system administration, or a related technical field.
- Fresh graduates with relevant PKI, cybersecurity, cryptography, or infrastructure training may be considered.