Overview
Job Summary We are seeking a Senior Systems Engineer to lead the evolution of our Secrets Management and Shared Services platform, with a primary focus on HashiCorp Vault, automation, and secure infrastructure in a fintech environment. This role will drive the design, implementation, and operational excellence of Vault and related services across our on-premises infrastructure, ensuring scalability, security, and reliability. You'll collaborate with security, DevOps, and application teams to build automation pipelines, enforce secrets governance, and integrate Vault with critical systems. Responsibilities
- Architect, deploy, and maintain HashiCorp Vault clusters for high availability and secure secrets management.
- Develop automation scripts and tooling using Python, Shell, and Ansible to streamline operations and enforce security controls.
- Integrate Vault with identity providers, PKI, and application platforms for dynamic secrets delivery.
- Collaborate with InfoSec and DevOps teams to define and implement secrets governance policies.
- Build and maintain CI/CD pipelines for secure deployment of Vault and shared services.
- Monitor and troubleshoot Vault performance, access controls, and audit logs.
- Lead efforts to modernize shared services infrastructure with a focus on automation and observability.
- Participate in on-call rotations and incident response for Vault and related shared services.
- Mentor junior engineers and contribute to internal documentation and knowledge sharing.
Knowledge and Experience
- 5+ years of experience in Linux systems engineering (RHEL preferred).
- Hands-on experience with HashiCorp Vault in production environments.
- Strong proficiency in Python and Shell scripting for automation.
- Experience with Ansible for configuration management and orchestration.
- Solid understanding of TCP/IP, TLS, and secure communication protocols.
- Familiarity with CI/CD tools (e.g., Jenkins, GitLab CI) and Infrastructure as Code (Terraform a plus).
- Experience with PKI, certificate management, and identity integration (LDAP, OIDC).
- Knowledge of SRE principles, including monitoring, alerting, and incident management.
- Ability to work in a regulated environment with a focus on security and compliance (e.g., SOC 2, ISO 27001).
Preferred
- Experience in fintech, crypto, or other security-sensitive domains.
- Exposure to container platforms (Docker, Kubernetes).
- Familiarity with GCP, AWS, or hybrid cloud environments.
- Understanding of threat modeling, secrets rotation, and zero trust architectures.
- Bachelor's degree in Computer Science, Engineering, or related field.
|