Principal Compliance Engineer
Location
United States
Posted
10 days ago
Salary
Not specified
No structured requirement data.
Job Description
Location Details: United States, Remote
At GoDaddy the future of work looks different for each team. Some teams work in the office full-time; others have a hybrid arrangement (they work remotely some days and in the office some days) and some work entirely remotely.
This is a remote position, so you’ll be working remotely from your home. You may occasionally visit a GoDaddy office to meet with your team for events or meetings.
This position is not eligible to be performed in Alaska, Mississippi, North Dakota, or the Virgin Islands.
Join our team
At GoDaddy, we are seeking an exceptional Principal Compliance Engineer - PKI with deep technical expertise to define requirements and guide the evolution of our Certificate Authority (CA) platform. Reporting to GoDaddy's Vice President Engineering Partners, you will translate industry standards into technical requirements, define specifications for compliance automation, and provide technical guidance for next-generation cryptographic systems. This role combines technical leadership with strategic requirements development, focusing on post-quantum cryptography readiness, certificate lifecycle automation, and CA infrastructure resilience.
What you'll get to do...
Technical Standards & Requirements Leadership
- Lead technical representation in the CA/Browser Forum and other industry standards bodies, contributing to protocol specifications and requirements development
- Translate CAB Forum requirements into detailed technical specifications and engineering requirements for development teams
- Define requirements for automated compliance validation systems and monitoring infrastructure
CA Infrastructure & Systems Requirements
- Conduct deep-dive technical assessments of CA infrastructure, identifying architectural gaps, security vulnerabilities, and performance bottlenecks
- Define technical requirements for the evolution of certificate issuance pipelines, HSM integrations, and cryptographic key management systems
- Specify requirements for automated testing frameworks for compliance validation, including CT log integration, OCSP responder infrastructure, and revocation mechanisms
- Develop automation scripts for compliance testing and validation processes
- Define SLIs/SLOs focused on certificate issuance latency, system availability, and compliance metrics
- Document requirements for infrastructure-as-code solutions for CA deployment, disaster recovery, and high-availability architectures
Cryptographic Systems & Innovation
- Research and define requirements for post-quantum cryptographic algorithms (e.g., ML-KEM, ML-DSA, SLH-DSA) and hybrid certificate chains
- Develop migration strategies and technical requirements for transitioning legacy cryptographic systems to next-generation algorithms
- Create technical specifications for proof-of-concept implementations for emerging standards (ACME extensions, certificate transparency v2, delegated credentials)
- Collaborate with cryptography researchers to evaluate algorithm performance, key sizes, and implementation trade-offs
Platform Requirements & Automation
- Define the technical requirements roadmap for CA platform capabilities including certificate lifecycle automation, API development, and integration frameworks
- Specify requirements for scalable APIs and automation tools for certificate issuance, renewal, and revocation workflows
- Document specifications for self-service platforms and tools to reduce manual intervention in certificate operations
- Develop automated testing scripts and define requirements for continuous compliance monitoring systems with automated remediation capabilities
Technical Collaboration & Documentation
- Partner with security engineering teams on threat modeling, secure coding practices, and vulnerability management
- Lead architecture reviews and technical design sessions with cross-functional engineering teams, providing requirements and guidance
- Establish technical documentation standards and compliance engineering requirements for CA-related systems
- Mentor engineers on PKI concepts, cryptographic implementations, and compliance engineering patterns
Your experience should include...
- 8+ years of hands-on engineering experience in PKI systems, applied cryptography, or security infrastructure with proven technical leadership and strong technical background in languages such as Go, Python, Java, or C++
- Deep expertise in PKI architecture including X.509 certificate structures, ASN.1 encoding, certificate chain validation, HSM operations, and cryptographic primitives
- Proven experience translating CA/Browser Forum Baseline Requirements into technical specifications, including controls for key generation, certificate issuance, and audit logging
- Systems engineering background with experience in distributed systems, API design, database architecture, and cloud infrastructure (AWS/GCP/Azure)
- Strong ability to define requirements for PKI protocols (ACME, Certificate Transparency, OCSP/CRL) and translate compliance requirements into technical specifications, detailed engineering requirements, and test automation scripts
You might also have...
-
- Advanced degree in Computer Science, Cryptography, Mathematics, or Electrical Engineering
- Experience researching and evaluating post-quantum cryptographic algorithms (NIST PQC finalists, hybrid modes)
- Security certifications such as CISSP, CEH, or specialized cryptography credentials
- Experience with security audit processes (WebTrust for CAs, ETSI EN 319 411) from a technical implementation perspective
- Contributions to PKI-related projects (Boulder, cert-manager, OpenSSL, BoringSSL, etc.)
- Experience defining requirements for high-availability systems design, hardware security modules (HSMs), and secure key ceremony procedures
- Knowledge of DevSecOps practices, CI/CD pipelines for security-critical systems, and infrastructure automation (Terraform, Kubernetes, Ansible)
- Familiarity with cryptographic libraries (OpenSSL, BoringSSL, PKCS#11) and performance considerations for cryptographic operations
- Experience developing test automation scripts for compliance validation
We've got your back... We offer a range of total rewards that may include paid time off, retirement savings (e.g., 401k, pension schemes), bonus/incentive eligibility, equity grants, participation in our employee stock purchase plan, competitive health benefits, and other family-friendly benefits including parental leave. GoDaddy’s benefits vary based on individual role and location and can be reviewed in more detail during the interview process.
We also embrace our diverse culture and offer a range of Employee Resource Groups (Culture). Have a side hustle? No problem. We love entrepreneurs! Most importantly, come as you are and make your own way.
About us... GoDaddy is empowering everyday entrepreneurs around the world by providing the help and tools to succeed online, making opportunity more inclusive for all. GoDaddy is the place people come to name their idea, build a professional website, attract customers, sell their products and services, and manage their work. Our mission is to give our customers the tools, insights, and people to transform their ideas and personal initiative into success. To learn more about the company, visit About Us.
At GoDaddy, we know diverse teams build better products—period. Our people and culture reflect and celebrate that sense of diversity and inclusion in ideas, experiences and perspectives. But we also know that’s not enough to build true equity and belonging in our communities. That’s why we prioritize integrating diversity, equity, inclusion and belonging principles into the core of how we work every day—focusing not only on our employee experience, but also our customer experience and operations. It’s the best way to serve our mission of empowering entrepreneurs everywhere, and making opportunity more inclusive for all. To read more about these commitments, as well as our representation and pay equity data, check out our Diversity and Pay Parity annual report which can be found on our Diversity Careers page.
GoDaddy is proud to be an equal opportunity employer. GoDaddy will consider for employment qualified applicants with criminal histories in a manner consistent with local and federal requirements. Refer to our full EEO policy.
Our recruiting team is available to assist you in completing your application. If they could be helpful, please reach out to myrecruiter@godaddy.com.
Colorado Residents: In any materials you submit, you may redact or remove age-identifying information such as age, date of birth, or dates of school attendance or graduation. You will not be penalized for redacting or removing this information.
GoDaddy doesn’t accept unsolicited resumes from recruiters or employment agencies.
Related Guides
Related Categories
Related Job Pages
More Compliance Jobs
Lead GRC Analyst
TherapyNotes.comTherapyNotes is the go-to superhero for behavioral health Practice Management and EHR software! Our top-notch SaaS solution handles scheduling, billing, documenting, telehealth, and more so clinicians can focus on awesome patient care. We're a dynamic team of pros who love to innovate and push the envelope, keeping our software cutting-edge. Join us, and let's revolutionize behavioral health software together while making a real difference!
About UsTherapyNotes is the go-to superhero for behavioral health Practice Management and EHR software! Our top-notch SaaS solution handles scheduling, billing, documenting, telehealth, and more so clinicians can focus on awesome patient care.We're...
Compliance Manager
TEKsystemsWe're partners in transformation. We help clients activate ideas and solutions to take advantage of a new world of opportunity. We are a team of 80,000 strong, working with over 6,000 clients, including 80% of the Fortune 500, across North America, Europe and Asia.
The Compliance Manager will handle licensing duties, including filing documents, solving NMLS action items, coordinating renewals, and managing state entity filings and Director/Officer changes. They will also manage regulatory examinations related to mortgage loan brokering licenses, including preparation and response delivery.
eToro is the trading and investing platform that empowers users to invest, share, and learn. We were founded in 2007 with the vision of a world where everyone can trade and invest simply and transparently. We have created an investment platform that is built around collaboration ...
Compliance Consultant
UnitedHealth GroupAt UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone–of every race, gender, sexuality, age, location and income–deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes — an enterprise priority reflected in our mission. OptumCare is an Equal Employment Opportunity employer under applicable law and qualified applicants will receive consideration for employment without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations. OptumCare is a drug-free workplace. Candidates are required to pass a drug test before beginning employment.
This Compliance Consultant role will help Optum Financial prevent, detect, and correct compliance risk by strengthening governance, monitoring, and issue management across the business. Compliance Governance & Program Support Assist with the development, maintenance, and implemen...