Secrets Management Platform Engineer

Posted Aug 14

This is a fully remote position, open to applicants in United States.

📋 Description

• Onboard applications, services, users, and machine identities into a centralized secrets management platform such as CyberArk or HashiCorp Vault.

• Design and implement secure processes for credential provisioning, storage, retrieval, rotation, revocation, and retirement.

• Integrate AWS Secrets Manager and AWS Systems Manager Parameter Store with enterprise applications and cloud-native workloads.

• Develop and enforce least-privilege IAM policies for secrets, credentials, encryption keys, and privileged services.

• Automate secrets-management workflows utilizing Python, Terraform, Ansible, and other approved infrastructure-as-code technologies.

• Incorporate secrets management into CI/CD pipelines and DevSecOps workflows.

• Design and support secrets integration for containers, Kubernetes workloads, cloud services, virtual machines, and application platforms.

• Implement and maintain PKI and certificate management processes.

• Eliminate hard-coded credentials, static passwords, embedded API keys, and unmanaged secrets.

• Enforce FIPS 140-2/3 cryptographic controls and integrate solutions with AWS KMS in AWS GovCloud as necessary.

• Configure authentication methods and access policies for users, applications, workloads, and machine identities.

• Implement dynamic or short-lived credentials.

• Maintain centralized auditing, logging, monitoring, and alerting for secrets access and policy violations.

• Develop and enforce governance standards for secret ownership, access, rotation, expiration, and lifecycle management.

• Collaborate with application, cloud, platform, cybersecurity, and DevSecOps teams.

• Troubleshoot authentication, authorization, credential rotation, certificate, API, and platform integration issues.

• Maintain technical documentation, onboarding procedures, platform standards, runbooks, and governance processes.

• Continuously enhance platform availability, scalability, automation, security controls, onboarding efficiency, and operational resilience.


⛳️ Requirements

• Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related technical discipline.

• Proven experience implementing or administering CyberArk or HashiCorp Vault.

• Familiarity with AWS Secrets Manager, AWS Systems Manager Parameter Store, and AWS KMS.

• Strong knowledge of Identity and Access Management, role-based access control, policy-based access, and least-privilege principles.

• Practical automation experience using Python, Terraform, and/or Ansible.

• Experience integrating secrets-management solutions with CI/CD pipelines, DevSecOps workflows, and automated deployment processes.

• Knowledge of PKI, certificate management, encryption, key management, and certificate lifecycle automation.

• Understanding of container and cloud security, including Kubernetes and cloud-native workloads.

• Experience in designing credential rotation, dynamic secrets, machine identity, and privileged-access workflows.

• Familiarity with FIPS 140-2/3 validated cryptography and cryptographic requirements for government or regulated environments.

• Experience in identifying and eliminating hard-coded credentials and unmanaged secrets.

• Strong understanding of Zero Trust principles.

• Experience with centralized logging, monitoring, auditing, compliance reporting, and security-event integration.

• Excellent troubleshooting, documentation, governance, automation, and cross-functional collaboration skills.

• Preference for candidates with experience supporting AWS GovCloud, government, defense, or other regulated cloud environments.

• Preferred certifications include AWS Certified Security – Specialty; AWS Certified Solutions Architect – Associate; HashiCorp Certified: Vault Associate or applicable CyberArk Defender/Sentry certification; CISSP or CISM.


🏝️ Benefits

• Competitive salary, paid bi-monthly.

• Best-in-class medical coverage.

• 100% of medical premiums covered by True Zero.

• Company-wide new business incentive programs.

• Contribution incentives (e.g., white papers, blog posts, internal webinars, etc.).

• Three weeks of PTO plus 11 paid holidays annually.

• 401k program with 100% company match on the first 4%.

• Monthly reimbursement for cell phone and home internet costs.

• Paternity/maternity leave.

• Investment in training and certifications to enhance and deepen your technical skills.

People also viewed

Resend1 day ago

Platform Engineer

North AmericaFull-timePlatform Engineer$150k – $180k/year
ApplyView job
Resend1 day ago

Platform Engineer

North AmericaFull-timePlatform Engineer$150k – $180k/year
ApplyView job
Improvix Technologies1 day ago

Senior Platform Engineer, AI Applications

US flagWashington OnlyFull-timePlatform Engineer$180k – $220k/year
ApplyView job
Improvix Technologies1 day ago

Senior Platform Engineer, AI Applications

US flagUnited States OnlyFull-timePlatform Engineer$180k – $220k/year
ApplyView job
Board Intelligence1 day ago

Product Engineer – Platform Experience

GB flagUnited Kingdom OnlyFull-timePlatform Engineer
ApplyView job
T-Rex Solutions, LLC1 day ago

Power Platform Developer

US flagUnited States OnlyFull-timePlatform Engineer$100k – $135k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers