Godaddy Principal Compliance Engineer - PKI at GoDaddy responsible for defining requirements and guiding evolution of Certificate Authority platform. Focuses on technical standards, CA infrastructure, cryptographic systems, and automation.
Responsibilities
Actively participate in standards bodies such as the IETF, representing GoDaddy in working groups for TLS and related SSL standards
Conduct deep-dive technical assessments of CA infrastructure, identifying architectural gaps, security vulnerabilities, and performance bottlenecks
Define technical requirements for the evolution of certificate issuance pipelines, HSM integrations, and cryptographic key management systems
Specify requirements for automated testing frameworks for compliance validation, including CT log integration, OCSP responder infrastructure, and revocation mechanisms
Develop automation scripts for compliance testing and validation processes
Define SLIs/SLOs focused on certificate issuance latency, system availability, and compliance metrics
Document requirements for infrastructure-as-code solutions for CA deployment, disaster recovery, and high-availability architectures
Research and define requirements for post-quantum cryptographic algorithms (e.g., ML-KEM, ML-DSA, SLH-DSA) and hybrid certificate chains
Develop migration strategies and technical requirements for transitioning legacy cryptographic systems to next-generation algorithms
Create technical specifications for proof-of-concept implementations for emerging standards (ACME extensions, certificate transparency v2, delegated credentials)
Collaborate with cryptography researchers to evaluate algorithm performance, key sizes, and implementation trade-offs
Define the technical requirements roadmap for CA platform capabilities including certificate lifecycle automation, API development, and integration frameworks
Qualification
Mentor engineers on PKI conceptsAdvanced degree in Computer ScienceSecurity certifications such as CISSP
Required
Lead architecture reviews and technical design sessions with cross-functional engineering teams, providing requirements and guidance
Establish technical documentation standards and compliance engineering requirements for CA-related systems
Mentor engineers on PKI concepts, cryptographic implementations, and compliance engineering patterns
8+ years of hands-on engineering experience in PKI systems, applied cryptography, or security infrastructure with proven technical leadership and strong technical background in languages such as Go, Python, Java, or C++
Deep expertise in PKI architecture including X.509 certificate structures, ASN.1 encoding, certificate chain validation, HSM operations, and cryptographic primitives
Proven experience translating CA/Browser Forum Baseline Requirements into technical specifications, including controls for key generation, certificate issuance, and audit logging
Systems engineering background with experience in distributed systems, API design, database architecture, and cloud infrastructure (AWS/GCP/Azure)
Strong ability to define requirements for PKI protocols (ACME, Certificate Transparency, OCSP/CRL) and translate compliance requirements into technical specifications, detailed engineering requirements, and test automation scripts
Advanced degree in Computer Science, Cryptography, Mathematics, or Electrical Engineering