Jobs and Careers
GO

Principal Compliance Engineer-PKI

GoDaddy
United States, United StatesRemotefull_timeVerifiedPosted 5 Mar 2026

About the role

Location Details: United States, Remote

At GoDaddy the future of work looks different for each team. Some teams work in the office full-time; others have a hybrid arrangement (they work remotely some days and in the office some days) and some work entirely remotely.

This is a remote position, so you’ll be working remotely from your home. You may occasionally visit a GoDaddy office to meet with your team for events or meetings.  

This position is not eligible to be performed in Alaska, Mississippi, North Dakota, or the Virgin Islands.

Join our team

At GoDaddy, we are seeking an exceptional Principal Compliance Engineer - PKI with deep technical expertise to define requirements and guide the evolution of our Certificate Authority (CA) platform. Reporting to GoDaddy's Vice President Engineering Partners, you will translate industry standards into technical requirements, define specifications for compliance automation, and provide technical guidance for next-generation cryptographic systems. This role combines technical leadership with strategic requirements development, focusing on post-quantum cryptography readiness, certificate lifecycle automation, and CA infrastructure resilience.

What you'll get to do...

Technical Standards & Requirements Leadership

  • Lead technical representation in the CA/Browser Forum and other industry standards bodies, contributing to protocol specifications and requirements development
  • Translate CAB Forum requirements into detailed technical specifications and engineering requirements for development teams
  • Define requirements for automated compliance validation systems and monitoring infrastructure

CA Infrastructure & Systems Requirements

  • Conduct deep-dive technical assessments of CA infrastructure, identifying architectural gaps, security vulnerabilities, and performance bottlenecks
  • Define technical requirements for the evolution of certificate issuance pipelines, HSM integrations, and cryptographic key management systems
  • Specify requirements for automated testing frameworks for compliance validation, including CT log integration, OCSP responder infrastructure, and revocation mechanisms
  • Develop automation scripts for compliance testing and validation processes
  • Define SLIs/SLOs focused on certificate issuance latency, system availability, and compliance metrics
  • Document requirements for infrastructure-as-code solutions for CA deployment, disaster recovery, and high-availability architectures

Cryptographic Systems & Innovation

  • Research and define requirements for post-quantum cryptographic algorithms (e.g., ML-KEM, ML-DSA, SLH-DSA) and hybrid certificate chains
  • Develop migration strategies and technical requirements for transitioning legacy cryptographic systems to next-generation algorithms
  • Create technical specifications for proof-of-concept implementations for emerging standards (ACME extensions, certificate transparency v2, delegated credentials)
  • Collaborate with cryptography researchers to evaluate algorithm performance, key sizes, and implementation trade-offs

Platform Requirements & Automation

  • Define the technical requirements roadmap for CA platform capabilities including certificate lifecycle automation, API development, and integration frameworks
  • Specify requirements for scalable APIs and automation tools for certificate issuance, renewal, and revocation workflows
  • Document specifications for self-service platforms and tools to reduce manual intervention in certificate operations
  • Develop automated testing scripts and define requirements for continuous compliance monitoring systems with automated remediation capabilities

Technical Collaboration & Documentation

  • Partner with security engineering teams on threat modeling, secure coding practices, and vulnerability management
  • Lead architecture reviews and technical design sessions with cross-functional engineering teams, providing requirements and guidance
  • Establish technical documentation standards and compliance engineering requirements for CA-related systems
  • Mentor engineers on PKI concepts, cryptographic implementations, and compliance engineering patterns

Your experience should include...

 

  • 8+ years of hands-on engineering experience in PKI systems, applied cryptography, or security infrastructure with proven technical leadership and strong technical background in languages such as Go, Python, Java, or C++
  • Deep expertise in PKI architecture including X.509 certificate structures, ASN.1 encoding, certificate chain validation, HSM operations, and cryp

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

GoDaddy

View company profile →