×
Register Here to Apply for Jobs or Post Jobs. X

Machine Identity Engineer

Job in New York, New York County, New York, 10261, USA
Listing for: Mizuho
Full Time position
Listed on 2026-02-15
Job specializations:
  • IT/Tech
    Cybersecurity, Systems Engineer
Salary/Wage Range or Industry Benchmark: 80000 - 100000 USD Yearly USD 80000.00 100000.00 YEAR
Job Description & How to Apply Below
Location: New York

Join Mizuho as a Machine Identity Engineer!

Mizuho’s Identity and Access Management (IAM) team is in the midst of an exciting transformation. We're building a dedicated high performing IAM function that is central to the firm's cybersecurity and regulatory strategy. Our environment is dynamic, growing, and rich with opportunity. You’ll work alongside a talented group of professionals who are passionate about solving complex access challenges, automating at scale, and strengthening security posture across both on‑premises and cloud environments.

This is a unique chance to join our team that's shaping the future of IAM at a major financial institution.

Summary

We are seeking an experienced IAM Engineer with specialization in PKI, certificate lifecycle management, and secrets management to design, implement, and support identity and credential services for non‑human identities across on‑prem and cloud environments, with a strong emphasis on Azure‑native identity services.

This hands‑on engineering role focuses on delivering secure and scalable solutions for managing digital certificates, encryption keys, and non‑human credentials used by servers, applications, services, APIs, and cloud workloads. The ideal candidate has deep expertise in PKI infrastructure, certificate lifecycle automation, and secrets management platforms such as Cyber Ark CCP, Azure Key Vault, or Hashi Corp Vault, along with strong working knowledge of Microsoft Entra  identities, Azure Managed Identities, service principals, and cloud IAM control patterns applicable to non‑human identities.

This role is critical to strengthening the firm's identity security posture, enabling secure cloud adoption, and supporting compliance with regulatory and internal control requirements

Key Responsibilities PKI & Certificate Lifecycle Management
  • Manage and enhance the enterprise PKI and Venafi certificate lifecycle management platform ensuring scalable, secure, and policy‑compliant certificate operations.

  • Integrate certificate‑based authentication into platforms, applications, network components, and Azure‑native services, minimizing manual handling and outage risk.

  • Establish and enforce certificate lifecycle standards, monitoring, and alerting to ensure certificate health, trust integrity, and regulatory compliance.

Secrets Management
  • Deploy and support secrets management platforms (e.g., Cyber Ark CCP, Azure Key Vault, Hashi Corp Vault) to protect non‑human credentials, API keys, and sensitive configuration data.

  • Integrate secrets management with infrastructure automation and CI/CD pipelines; define and enforce rotation, expiration, and least‑privilege access policies.

Cloud Workload Identity
  • Implement and support cloud workload identity patterns (e.g., Azure Managed Identities and service principals) to enable secure, identity‑based access for non‑human workloads and reduce reliance on static credentials.

  • Partner with cloud and platform teams to integrate workload identities with enterprise PKI and secrets management solutions, enforce least‑privilege access models, and support security, audit, and compliance requirements.

Control Execution & Compliance
  • Maintain accurate and complete inventories of certificates, keys, secrets, and machine identities aligned with CMDBs or authorized asset repositories.

  • Ensure identity, credential, and key management controls are documented, monitored, and evidenced to support audit, risk, and regulatory requirements.

  • Support regulatory exams, internal audits, and control testing activities, including evidence preparation, issue remediation, and control validation.

Cross‑Functional Engagement
  • Partner with infrastructure, cloud, cybersecurity, and Dev Ops teams to align machine identity, certificate, and secrets controls with enterprise architecture standards.

  • Participate in design and architecture discussions to identify gaps and drive scalable, automation‑friendly improvements.

Required Qualifications
  • 7+ years of experience in Identity & Access Management, cybersecurity engineering, or related infrastructure security roles, with a strong focus on non‑human identities.

  • Hands‑on experience operating and supporting enterprise…

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary