About Us
Cloudflare is building a new public Certificate Authority for the Internet. We are looking for a senior technical architect to help define the systems, protocols, and security architecture behind it.
This role spans applied cryptography, Web PKI, distributed systems, security engineering, compliance, and Internet standards. It will help Cloudflare build a CA that operates safely at Internet scale while establishing a credible path from today's X.509 ecosystem toward post-quantum authentication using Merkle Tree Certificates (MTCs).
Mission
Define and guide the end-to-end architecture of Cloudflare's public Certificate Authority: a high-assurance, highly available system capable of issuing conventional publicly trusted certificates at Cloudflare scale while supporting Merkle Tree Certificates (MTCs) and the evolution toward a post-quantum Web PKI.
You will help determine not only how the CA is implemented, but also its trust boundaries, key hierarchy, issuance architecture, auditability, failure modes, incident response mechanisms, and long-term cryptographic evolution.
Key Responsibilities
- Define and maintain the end-to-end technical architecture of Cloudflare's public CA across certificate issuance, key management, transparency, revocation, renewal, and relying-party integration.
- Design root and intermediate CA trust hierarchies, signing systems, HSM integration, key ceremonies, key rotation, backup, recovery, migration, and key-compromise response.
- Architect secure, resilient, and highly available issuance services capable of operating at Internet scale and across multiple geographic and failure domains.
- Design certificate lifecycle systems around ACME, domain and IP validation, CAA, Certificate Transparency, pre-issuance linting, revocation, renewal, and large-scale certificate replacement.
- Integrate Cloudflare’s MTC infrastructure, including CA logs, landmarks,, cosigning or mirroring, and interactions with relying parties.
- Develop practical architectures for coexistence and migration between classical X.509 certificates and post-quantum authentication mechanisms.
- Define trust boundaries, security properties, and threat models covering key compromise, unauthorized issuance, software supply-chain compromise, operator error, malicious insiders, infrastructure failure, split views, and cryptographic migration.
- Design systems that make CA behavior observable and independently verifiable through transparency mechanisms, reproducible builds, cryptographic attestations, public operational telemetry, tamper-evident evidence, and audit controls.
- Design failure containment and recovery mechanisms that support safe certificate replacement, revocation, key rotation, and incident response without creating avoidable Internet availability failures.
- Translate CA/Browser Forum requirements, browser and operating-system root-program policies, audit criteria, and certification requirements into concrete technical and operational controls.
- Review protocols, architecture, and implementations with an adversarial mindset, identifying assumptions and failure modes that do not hold at Internet scale.
- Work closely with Cloudflare's cryptography, TLS, security, networking, infrastructure, compliance, product, and operations teams.
- Provide architectural direction, design review, and technical mentorship to engineers implementing and operating the CA platform.
- Represent Cloudflare in relevant standards and industry work, collaborating with browser vendors, root programs, researchers, auditors, CA operators, and the wider Web PKI community.
What You'll Bring
- Substantial experience designing or operating security-critical systems, with deep expertise in at least one of: public Certificate Authorities, Web PKI, applied cryptography, TLS and Internet security protocols, Certificate Transparency, hardware-backed key management, or large-scale distributed security systems.
- Strong knowledge of certificate trust chains, issuance and validation, revocation, key lifecycle management, and the security and availability implications of CA design decisions.
- Experience defining system trust boundaries, threat models, security invariants, and failure-handling strategies.
- Ability to reason about systems in which a subtle architectural or operational mistake can affect a significant fraction of the Internet.
- Experience leading architecture across multiple engineering teams without relying solely on organizational authority.
- Strong written and verbal communication, including the ability to explain cryptographic and architectural tradeoffs to engineers, auditors, standards participants, and senior stakeholders.
- Comfort operating with substantial autonomy in an evolving technical and policy environment.
What Makes Cloudflare Special?
Standard company text repeated across Cloudflare's postings is omitted here.