3 дня назад
Secrets Management Platform Engineer (AWS/CyberArk)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Secrets Management Platform Engineer (AWS/CyberArk): Designing and operating a centralized enterprise secrets management platform for credentials, keys, certificates, and tokens across applications, cloud environments, and CI/CD workflows with an accent on automation, least-privilege access, PKI, and Zero Trust security. Focus on onboarding thousands of applications, implementing credential rotation and dynamic secrets, integrating AWS GovCloud and AWS KMS, and maintaining auditing and lifecycle governance.
Location: 100% Remote
Company
is a fast-growing technology company recognized by Best Places to Work and the Inc. 5000.
What you will do
- Design, implement, and operate a centralized enterprise secrets management platform using CyberArk or HashiCorp Vault.
- Onboard applications, services, users, and machine identities while automating credential provisioning, retrieval, rotation, revocation, and retirement.
- Integrate AWS Secrets Manager, AWS Systems Manager Parameter Store, AWS KMS, CI/CD pipelines, DevSecOps workflows, containers, and Kubernetes workloads.
- Implement least-privilege IAM policies, Zero Trust controls, dynamic credentials, and identity-based access for users, applications, and workloads.
- Maintain PKI and certificate lifecycle processes, including issuance, renewal, rotation, revocation, and expiration monitoring.
- Develop auditing, monitoring, governance, documentation, onboarding procedures, and operational runbooks while troubleshooting platform integrations.
Requirements
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related technical discipline.
- Experience implementing or administering CyberArk or HashiCorp Vault, plus AWS Secrets Manager, AWS Systems Manager Parameter Store, and AWS KMS.
- Strong knowledge of IAM, role-based and policy-based access, least privilege, Zero Trust, credential rotation, dynamic secrets, and machine identity.
- Hands-on automation experience with Python, Terraform, and/or Ansible, including integration with CI/CD and DevSecOps workflows.
- Experience with PKI, certificate management, encryption, key management, Kubernetes, container security, centralized logging, monitoring, auditing, and compliance reporting.
- Knowledge of FIPS 140-2/3 validated cryptography and controls for eliminating hard-coded credentials and unmanaged secrets.
Nice to have
- Experience supporting AWS GovCloud, government, defense, or other regulated cloud environments.
- AWS Certified Security – Specialty or AWS Certified Solutions Architect – Associate.
- HashiCorp Certified: Vault Associate, CyberArk Defender/Sentry, CISSP, or CISM certification.
Culture & Benefits
- Fully remote workplace.
- People-first approach focused on excellence and continuous improvement.
- Work on security, automation, scalability, compliance, and operational resilience for enterprise environments.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
21 час назад
Staff Cybersecurity Engineer (PKI/Secrets Management)
6 часов назад
Cybersecurity Engineer (AI)
135 000 - 155 000$
5 дней назад
Network Security Engineer (AI)
6 дней назад
Security Engineer (AWS)
104 148 - 140 000$
7 дней назад
SOC Manager (Cybersecurity)
205 000 - 215 000$
11 часов назад