Your new challenge
As a Trust Requirements Engineer, you play a critical role in ensuring compliance with global trust and certificate standards. You analyze evolving regulatory frameworks and translate them into actionable requirements that guide product development, certificate issuance practices, and compliance operations.
SwissSign is a recognised Swiss Trust Service Provider (TSP). We build the foundation for secure digital business based on robust certificate services and advanced digital trust services across multiple regulatory frameworks.
Our certificate services provide a fully Swiss made public key infrastructure for digital certificates, ensuring secure communication, data protection and compliance throughout the entire certificate lifecycle. Complementing this, our digital trust services enable legally compliant digital signatures, seals and timestamps, supporting end to end digital business processes based on verifiable, reusable credentials.
An overview of your tasks
-
Conduct in-depth compliance analysis of certificate issuance practices against industry standards, including:
-
CA/Browser Forum Baseline Requirements
-
Extended Validation (EV) Guidelines
-
S/MIME Baseline Requirements
-
Relevant RFCs, IETF, and ISO frameworks
-
-
Develop and maintain clear, structured compliance requirements specifications for internal stakeholders.
-
Collaborate cross-functionally with Product, Engineering, and Information Security & Compliance (ISC) teams to embed regulatory requirements into the software development lifecycle
-
Act as a Subject Matter Expert (SME) on:
-
Public Key Infrastructure (PKI)
-
Certificate profiles and lifecycles
-
Cryptographic algorithms
-
Trust store requirements
-
-
Represent the organization in industry forums (e.g., CA/Browser Forum, IETF) by:
-
Drafting ballots and proposals
-
Participating in technical discussions
-
Driving alignment with industry peers
-
-
Assess proposed changes to standards and regulations, translating them into practical guidance for engineering and operations teams
-
Monitor emerging trends and regulatory developments, including:
-
Certificate lifecycle changes
-
Automation protocols such as ACME
-
Root Store Policies
-
Post-Quantum Cryptography (PQC)
-
Merkle Tree Certificates (MTC)
-
-
Support audit readiness by preparing materials and walkthroughs in collaboration with ISC and engineering teams
-
Contribute to root cause analysis and remediation efforts related to compliance incidents
What you bring along
-
2+ years of experience in PKI, digital certificates, or a related domain
-
Strong understanding of:
-
X.509 certificate standards
-
RFC 5280
-
CA/Browser Forum requirements
-
-
Ability to analyze complex technical and policy documents and convert them into clear compliance requirements
-
Hands-on experience with:
-
Certificate tools like ASN.1
-
PKI troubleshooting and analysis methods
-
-
Excellent written and verbal communication skills in English
-
Any additional languages are an advantage
Nice to Have
-
Experience participating in standards bodies or working groups
-
Familiarity with audit frameworks (e.g., WebTrust, ETSI)
-
Exposure to secure software development practices
-
Knowledge of modern cryptographic trends (e.g., PQC)
