
Secrets Management Platform Engineer
Posted 19 hours ago

Posted 19 hours ago
This is a fully remote position, open to applicants in United States.
• Onboard applications, services, users, and machine identities into a centralized secrets management platform such as CyberArk or HashiCorp Vault.
• Design and implement secure processes for credential provisioning, storage, retrieval, rotation, revocation, and retirement.
• Integrate AWS Secrets Manager and AWS Systems Manager Parameter Store with enterprise applications and cloud-native workloads.
• Develop and enforce least-privilege IAM policies for secrets, credentials, encryption keys, and privileged services.
• Automate secrets-management workflows utilizing Python, Terraform, Ansible, and other approved infrastructure-as-code technologies.
• Incorporate secrets management into CI/CD pipelines and DevSecOps workflows.
• Design and support secrets integration for containers, Kubernetes workloads, cloud services, virtual machines, and application platforms.
• Implement and maintain PKI and certificate management processes.
• Eliminate hard-coded credentials, static passwords, embedded API keys, and unmanaged secrets.
• Enforce FIPS 140-2/3 cryptographic controls and integrate solutions with AWS KMS in AWS GovCloud as necessary.
• Configure authentication methods and access policies for users, applications, workloads, and machine identities.
• Implement dynamic or short-lived credentials.
• Maintain centralized auditing, logging, monitoring, and alerting for secrets access and policy violations.
• Develop and enforce governance standards for secret ownership, access, rotation, expiration, and lifecycle management.
• Collaborate with application, cloud, platform, cybersecurity, and DevSecOps teams.
• Troubleshoot authentication, authorization, credential rotation, certificate, API, and platform integration issues.
• Maintain technical documentation, onboarding procedures, platform standards, runbooks, and governance processes.
• Continuously enhance platform availability, scalability, automation, security controls, onboarding efficiency, and operational resilience.
• Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related technical discipline.
• Proven experience implementing or administering CyberArk or HashiCorp Vault.
• Familiarity with AWS Secrets Manager, AWS Systems Manager Parameter Store, and AWS KMS.
• Strong knowledge of Identity and Access Management, role-based access control, policy-based access, and least-privilege principles.
• Practical automation experience using Python, Terraform, and/or Ansible.
• Experience integrating secrets-management solutions with CI/CD pipelines, DevSecOps workflows, and automated deployment processes.
• Knowledge of PKI, certificate management, encryption, key management, and certificate lifecycle automation.
• Understanding of container and cloud security, including Kubernetes and cloud-native workloads.
• Experience in designing credential rotation, dynamic secrets, machine identity, and privileged-access workflows.
• Familiarity with FIPS 140-2/3 validated cryptography and cryptographic requirements for government or regulated environments.
• Experience in identifying and eliminating hard-coded credentials and unmanaged secrets.
• Strong understanding of Zero Trust principles.
• Experience with centralized logging, monitoring, auditing, compliance reporting, and security-event integration.
• Excellent troubleshooting, documentation, governance, automation, and cross-functional collaboration skills.
• Preference for candidates with experience supporting AWS GovCloud, government, defense, or other regulated cloud environments.
• Preferred certifications include AWS Certified Security – Specialty; AWS Certified Solutions Architect – Associate; HashiCorp Certified: Vault Associate or applicable CyberArk Defender/Sentry certification; CISSP or CISM.
• Competitive salary, paid bi-monthly.
• Best-in-class medical coverage.
• 100% of medical premiums covered by True Zero.
• Company-wide new business incentive programs.
• Contribution incentives (e.g., white papers, blog posts, internal webinars, etc.).
• Three weeks of PTO plus 11 paid holidays annually.
• 401k program with 100% company match on the first 4%.
• Monthly reimbursement for cell phone and home internet costs.
• Paternity/maternity leave.
• Investment in training and certifications to enhance and deepen your technical skills.
Agility Technologies Inc
American College of Education
First Due
Faire
Get handpicked remote jobs straight to your inbox weekly.