hirly

GoDaddy

Principal Engineer Cryptography

United States

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at GoDaddy first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

hirly's read of this role

Role family
Engineering
Seniority
Lead / management
Stated salary
$165,500 – $323,000 per year
Country
US
Work mode
Remote-friendly
First seen by hirly
11 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

Location Details: United States, Remote

At GoDaddy the future of work looks different for each team. Some teams work in the office full-time; others have a hybrid arrangement (they work remotely some days and in the office some days) and some work entirely remotely.

This is a remote position, so you’ll be working remotely from your home. You may occasionally visit a GoDaddy office to meet with your team for events or meetings.

This position is not eligible to be performed in Alaska, Mississippi, North Dakota, or the Virgin Islands.

Join our team

At GoDaddy, we are seeking an exceptional Principal Compliance Engineer - PKI with deep technical expertise to define requirements and guide the evolution of our Certificate Authority (CA) platform. Reporting to GoDaddy's Vice President Engineering Partners, you will translate industry standards into technical requirements, define specifications for compliance automation, and provide technical guidance for next-generation cryptographic systems. This role combines technical leadership with strategic requirements development, focusing on post-quantum cryptography readiness, certificate lifecycle automation, and CA infrastructure resilience.

What you'll get to do...

Technical Standards & Requirements Leadership

Actively participate in standards bodies such as the IETF, representing GoDaddy in working groups for TLS and related SSL standards

CA Infrastructure & Systems Requirements

Conduct deep-dive technical assessments of CA infrastructure, identifying architectural gaps, security vulnerabilities, and performance bottlenecks

Define technical requirements for the evolution of certificate issuance pipelines, HSM integrations, and cryptographic key management systems

Specify requirements for automated testing frameworks for compliance validation, including CT log integration, OCSP responder infrastructure, and revocation mechanisms

Develop automation scripts for compliance testing and validation processes

Define SLIs/SLOs focused on certificate issuance latency, system availability, and compliance metrics

Document requirements for infrastructure-as-code solutions for CA deployment, disaster recovery, and high-availability architectures

Cryptographic Systems & Innovation

Research and define requirements for post-quantum cryptographic algorithms (e.g., ML-KEM, ML-DSA, SLH-DSA) and hybrid certificate chains

Develop migration strategies and technical requirements for transitioning legacy cryptographic systems to next-generation algorithms

Create technical specifications for proof-of-concept implementations for emerging standards (ACME extensions, certificate transparency v2, delegated credentials)

Collaborate with cryptography researchers to evaluate algorithm performance, key sizes, and implementation trade-offs

Platform Requirements & Automation

Define the technical requirements roadmap for CA platform capabilities including certificate lifecycle automation, API development, and integration frameworks

Specify requirements for scalable APIs and automation tools for certificate issuance, renewal, and revocation workflows

Document specifications for self-service platforms and tools to reduce manual intervention in certificate operations

Develop automated testing scripts and define requirements for continuous compliance monitoring systems with automated remediation capabilities

Technical Collaboration & Documentation

Partner with security engineering teams on threat modeling, secure coding practices, and vulnerability management

Lead architecture reviews and technical design sessions with cross-functional engineering teams, providing requirements and guidance

Establish technical documentation standards and compliance engineering requirements for CA-related systems

Mentor engineers on PKI concepts, cryptographic implementations, and compliance engineering patterns

Your experience should include...

8+ years of hands-on engineering experience in PKI systems, applied cryptography, or security infrastructure with proven technical leadership and strong technical background in languages such as Go, Python, Java, or C++

Deep expertise in PKI architecture including X.509 certificate structures, ASN.1 encoding, certificate chain validation, HSM operations, and cryptographic primitives

Proven experience translating CA/Browser Forum Baseline Requirements into technical specifications, including controls for key generation, certificate issuance, and audit logging

Systems engineering background with experience in distributed systems, API design, database architecture, and cloud infrastructure (AWS/GCP/Azure)

Strong ability to define requirements for PKI protocols (ACME, Certificate Transparency, OCSP/CRL) and translate compliance requirements into technical specifications, detailed engineering requirements, and test automation scripts

You might also have...

Advanced degree in Computer Science, Cryptography, Mathematics, or Electrical Engineering

Experience researching and evaluating post-quantum cryptographic algorithms (NIST PQC finalists, hybrid modes)

Security certifications such as CISSP, CEH, or specialized cryptography credentials

Experience with security audit processes (WebTrust for CAs, ETSI EN 319 411) from a technical implementation perspective

Contributions to PKI-related projects (Boulder, cert-manager, OpenSSL, BoringSSL, etc.)

Experience defining requirements for high-availability systems design, hardware security modules (HSMs), and secure key ceremony procedures

Knowledge of DevSecOps practices, CI/CD pipelines for security-critical systems, and infrastructure automation (Terraform, Kubernetes, Ansible)

Familiarity with cryptographic libraries (OpenSSL, BoringSSL, PKCS#11) and performance considerations for cryptographic operations

Experience developing test automation scripts for compliance validation

We encourage you to apply even if your experience or skillset doesn’t align perfectly with every requirement. We value a wide range of backgrounds and transferable skills, and we are excited to support learning and growth.

About us... GoDaddy is empowering everyday entrepreneurs around the world by providing the help and tools to succeed online, making opportunity more inclusive for all. GoDaddy is the place people come to name their idea, build a professional website, attract customers, sell their products and services, and manage their work. Our mission is to give our customers the tools, insights, and people to transform their ideas and personal initiative into success. To learn more about the company, visit About Us .

At GoDaddy, we know diverse teams build better products—period. Our people and culture reflect and celebrate that sense of diversity and inclusion in ideas, experiences and perspectives. But we also know that’s not enough to build true equity and belonging in our communities. That’s why we prioritize integrating diversity, equity, inclusion and belonging principles into the core of how we work every day—focusing not only on our employee experience, but also our customer experience and operations. It’s the best way to serve our mission of empowering entrepreneurs everywhere, and making opportunity more inclusive for all. To read more about these commitments, as well as our representation and pay equity data, check out our Diversity and Pay Parity annual report which can be found on our Diversity Careers page .

We also embrace our diverse culture and offer a range of Employee Resource Groups ( Culture ). Have a side hustle? No problem. We love entrepreneurs! Most importantly, come as you are and make your own way.

GoDaddy is proud to be an equal opportunity employer . GoDaddy will consider for employment qualified applicants with criminal histories in a manner consistent with local and federal requirements. Refer to our full EEO policy.

Our recruiting team is availa

Original posting on GoDaddy's site ↗

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job