
Secrets Management Platform Engineer
Posted Aug 14

Posted Aug 14
This is a fully remote position, open to applicants in United States.
• Onboard applications, services, users, and machine identities into a centralized secrets management platform such as CyberArk or HashiCorp Vault.
• Design and implement secure processes for credential provisioning, storage, retrieval, rotation, revocation, and retirement.
• Integrate AWS Secrets Manager and AWS Systems Manager Parameter Store with enterprise applications and cloud-native workloads.
• Develop and enforce least-privilege IAM policies for secrets, credentials, encryption keys, and privileged services.
• Automate secrets-management workflows utilizing Python, Terraform, Ansible, and other approved infrastructure-as-code technologies.
• Incorporate secrets management into CI/CD pipelines and DevSecOps workflows.
• Design and support secrets integration for containers, Kubernetes workloads, cloud services, virtual machines, and application platforms.
• Implement and maintain PKI and certificate management processes.
• Eliminate hard-coded credentials, static passwords, embedded API keys, and unmanaged secrets.
• Enforce FIPS 140-2/3 cryptographic controls and integrate solutions with AWS KMS in AWS GovCloud as necessary.
• Configure authentication methods and access policies for users, applications, workloads, and machine identities.
• Implement dynamic or short-lived credentials.
• Maintain centralized auditing, logging, monitoring, and alerting for secrets access and policy violations.
• Develop and enforce governance standards for secret ownership, access, rotation, expiration, and lifecycle management.
• Collaborate with application, cloud, platform, cybersecurity, and DevSecOps teams.
• Troubleshoot authentication, authorization, credential rotation, certificate, API, and platform integration issues.
• Maintain technical documentation, onboarding procedures, platform standards, runbooks, and governance processes.
• Continuously enhance platform availability, scalability, automation, security controls, onboarding efficiency, and operational resilience.
• Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related technical discipline.
• Proven experience implementing or administering CyberArk or HashiCorp Vault.
• Familiarity with AWS Secrets Manager, AWS Systems Manager Parameter Store, and AWS KMS.
• Strong knowledge of Identity and Access Management, role-based access control, policy-based access, and least-privilege principles.
• Practical automation experience using Python, Terraform, and/or Ansible.
• Experience integrating secrets-management solutions with CI/CD pipelines, DevSecOps workflows, and automated deployment processes.
• Knowledge of PKI, certificate management, encryption, key management, and certificate lifecycle automation.
• Understanding of container and cloud security, including Kubernetes and cloud-native workloads.
• Experience in designing credential rotation, dynamic secrets, machine identity, and privileged-access workflows.
• Familiarity with FIPS 140-2/3 validated cryptography and cryptographic requirements for government or regulated environments.
• Experience in identifying and eliminating hard-coded credentials and unmanaged secrets.
• Strong understanding of Zero Trust principles.
• Experience with centralized logging, monitoring, auditing, compliance reporting, and security-event integration.
• Excellent troubleshooting, documentation, governance, automation, and cross-functional collaboration skills.
• Preference for candidates with experience supporting AWS GovCloud, government, defense, or other regulated cloud environments.
• Preferred certifications include AWS Certified Security – Specialty; AWS Certified Solutions Architect – Associate; HashiCorp Certified: Vault Associate or applicable CyberArk Defender/Sentry certification; CISSP or CISM.
• Competitive salary, paid bi-monthly.
• Best-in-class medical coverage.
• 100% of medical premiums covered by True Zero.
• Company-wide new business incentive programs.
• Contribution incentives (e.g., white papers, blog posts, internal webinars, etc.).
• Three weeks of PTO plus 11 paid holidays annually.
• 401k program with 100% company match on the first 4%.
• Monthly reimbursement for cell phone and home internet costs.
• Paternity/maternity leave.
• Investment in training and certifications to enhance and deepen your technical skills.
Resend
Resend
Improvix Technologies
Improvix Technologies
Get handpicked remote jobs straight to your inbox weekly.