← Back to results

Senior Certificate Authority Architect

Join Cloudflare as a Senior Certificate Authority Architect to define the architecture for a new public Certificate Authority at Internet scale.

Location
San Francisco, CA, United States
Compensation
Not disclosed
Level
senior
Type
full time · Hybrid

Posted by employer 12 hours ago

First seen on Joblaze 4 hours ago

Last verified on the company career page 4 hours ago

What you'll build

  • Define and maintain the end-to-end technical architecture of Cloudflare's public CA
  • Design root and intermediate CA trust hierarchies
  • Architect secure, resilient, and highly available issuance services
  • Design certificate lifecycle systems
  • Translate CA/Browser Forum requirements into technical controls

Must have

  • Substantial experience designing or operating security-critical systems
  • Deep expertise in at least one of: public Certificate Authorities, Web PKI, applied cryptography
  • Strong knowledge of certificate trust chains and key lifecycle management
  • Experience defining system trust boundaries and threat models
  • Strong written and verbal communication skills

Requirements

Visa
No sponsorship (stated in posting)

Not disclosed in this posting: compensation, years of experience.

Joblaze summary

The Senior Certificate Authority Architect at Cloudflare is responsible for defining the architecture of a new public Certificate Authority, focusing on systems for certificate issuance, key management, and security protocols. This role requires expertise in applied cryptography, Web PKI, and distributed systems, along with a strong understanding of certificate trust chains and lifecycle management. It is suited for experienced professionals who can lead cross-team architecture discussions and operate autonomously in a complex technical environment.

Joblaze insights

  • Listed today — first seen on Joblaze October 10, 2026. Last confirmed on Cloudflare's careers page October 10, 2026.
  • Applied Cryptography appears in 1.2% of 331 comparable senior security roles in United States; TLS appears in 0.9% of 331 comparable senior security roles in United States.

Quick facts

Is the Senior Certificate Authority Architect role remote?
It's hybrid — Cloudflare expects some on-site time in San Francisco, CA, United States.
Where is the role based?
Cloudflare is hiring for this position in San Francisco, CA, United States.
What's the tech stack?
Joblaze extracted these technologies from the posting: Applied Cryptography, Certificate Transparency, Internet security protocols, TLS, Web PKI, hardware-backed key management.
What seniority level is this role?
Cloudflare targets senior candidates for this position.
Is this full-time or contract?
Full-time for this Senior Certificate Authority Architect role at Cloudflare.

From the original posting

About Us

Cloudflare is building a new public Certificate Authority for the Internet. We are looking for a senior technical architect to help define the systems, protocols, and security architecture behind it.

This role spans applied cryptography, Web PKI, distributed systems, security engineering, compliance, and Internet standards. It will help Cloudflare build a CA that operates safely at Internet scale while establishing a credible path from today's X.509 ecosystem toward post-quantum authentication using Merkle Tree Certificates (MTCs).

Mission

Define and guide the end-to-end architecture of Cloudflare's public Certificate Authority: a high-assurance, highly available system capable of issuing conventional publicly trusted certificates at Cloudflare scale while supporting Merkle Tree Certificates (MTCs) and the evolution toward a post-quantum Web PKI.

You will help determine not only how the CA is implemented, but also its trust boundaries, key hierarchy, issuance architecture, auditability, failure modes, incident response mechanisms, and long-term cryptographic evolution.

Key Responsibilities

  • Define and maintain the end-to-end technical architecture of Cloudflare's public CA across certificate issuance, key management, transparency, revocation, renewal, and relying-party integration.
  • Design root and intermediate CA trust hierarchies, signing systems, HSM integration, key ceremonies, key rotation, backup, recovery, migration, and key-compromise response.
  • Architect secure, resilient, and highly available issuance services capable of operating at Internet scale and across multiple geographic and failure domains.
  • Design certificate lifecycle systems around ACME, domain and IP validation, CAA, Certificate Transparency, pre-issuance linting, revocation, renewal, and large-scale certificate replacement.
  • Integrate Cloudflare’s MTC infrastructure, including CA logs, landmarks,, cosigning or mirroring, and interactions with relying parties.
  • Develop practical architectures for coexistence and migration between classical X.509 certificates and post-quantum authentication mechanisms.
  • Define trust boundaries, security properties, and threat models covering key compromise, unauthorized issuance, software supply-chain compromise, operator error, malicious insiders, infrastructure failure, split views, and cryptographic migration.
  • Design systems that make CA behavior observable and independently verifiable through transparency mechanisms, reproducible builds, cryptographic attestations, public operational telemetry, tamper-evident evidence, and audit controls.
  • Design failure containment and recovery mechanisms that support safe certificate replacement, revocation, key rotation, and incident response without creating avoidable Internet availability failures.
  • Translate CA/Browser Forum requirements, browser and operating-system root-program policies, audit criteria, and certification requirements into concrete technical and operational controls.
  • Review protocols, architecture, and implementations with an adversarial mindset, identifying assumptions and failure modes that do not hold at Internet scale.
  • Work closely with Cloudflare's cryptography, TLS, security, networking, infrastructure, compliance, product, and operations teams.
  • Provide architectural direction, design review, and technical mentorship to engineers implementing and operating the CA platform.
  • Represent Cloudflare in relevant standards and industry work, collaborating with browser vendors, root programs, researchers, auditors, CA operators, and the wider Web PKI community.

What You'll Bring

  • Substantial experience designing or operating security-critical systems, with deep expertise in at least one of: public Certificate Authorities, Web PKI, applied cryptography, TLS and Internet security protocols, Certificate Transparency, hardware-backed key management, or large-scale distributed security systems.
  • Strong knowledge of certificate trust chains, issuance and validation, revocation, key lifecycle management, and the security and availability implications of CA design decisions.
  • Experience defining system trust boundaries, threat models, security invariants, and failure-handling strategies.
  • Ability to reason about systems in which a subtle architectural or operational mistake can affect a significant fraction of the Internet.
  • Experience leading architecture across multiple engineering teams without relying solely on organizational authority.
  • Strong written and verbal communication, including the ability to explain cryptographic and architectural tradeoffs to engineers, auditors, standards participants, and senior stakeholders.
  • Comfort operating with substantial autonomy in an evolving technical and policy environment.

What Makes Cloudflare Special?

Standard company text repeated across Cloudflare's postings is omitted here.

Similar positions

Cloudflare
Cloudflare
Cloudflare
Senior Manager, Engineering
Cloudflare · Hybrid
Cloudflare