More jobs:
Job Description & How to Apply Below
In this specialized engineering role, you will be responsible for providing secure, highly available secrets management platforms at a global scale. Your mission is to enable seamless, programmatic access to credentials, API tokens, and cryptographic keys across all automated developer workflows while embedding compliance, structural resilience, and zero-trust principles. The Enterprise Secrets Management team plays a pivotal role in securing the software delivery lifecycle end-to-end, deeply integrating with multi-region cloud infrastructures, continuous delivery pipelines, and Infrastructure-as-Code frameworks.
Desired
Start Date:
July 6, 2026
Contract Length: 6-Month Contract (Possibility of extension is highly likely)
Location:
Hybrid Vancouver (4 days per week on-site at the Vancouver, BC corporate headquarters)
Advantages
Global Technical
Infrastructure: Lead the design, replication architecture, and upgrade lifecycles for massive, multi-region cryptographic clusters.
Cutting-Edge Security Paradigms:
Implement advanced Zero-Trust patterns including dynamic, lease-based credentials, just-in-time (JIT) access, and break-glass automation.
Extensible Engineering Scope:
Drive platform customization by developing bespoke plugins and policy-as-code structures for automated access governance.
High-Impact Domain:
Own a critical, baseline security layer that protects company-wide engineering pipelines, corporate applications, and enterprise third-party integrations.
Responsibilities
Enterprise Platform Operations:
Administer, scale, and secure enterprise secrets management architectures globally, guaranteeing high availability, cross-region replication, and robust disaster recovery protocols.
Dynamic Workflow Engineering:
Design and implement dynamic secrets, lease-based access models, and automated just-in-time (JIT) token provisioning workflows.
Pipeline Integration:
Build and embed secure secret injection, rotation, and lifecycle patterns seamlessly into enterprise CI/CD pipelines (Git Lab) and Infrastructure as Code (Terraform) environments.
Policy-as-Code Governance:
Develop and enforce strict access control lists (ACLs), authentication mappings, and policy-as-code modules to ensure compliance with enterprise guardrails.
Identity & Access Alignment:
Support Identity and Privileged Access Management (PAM) integrations, utilizing advanced auth methods to establish automated trust relationships.
Security Monitoring & Auditing:
Analyze platform audit logs, programmatic usage patterns, and anomaly risk signals to detect potential policy breaches and fortify the overall security posture.
Runbook & Self-Service Automation:
Drive corporate adoption of secure patterns by authoring developer self-service automation scripts (via Python/Go), architecture blueprints, and deep operational runbooks.
Qualifications
Experience:
8+ years of progressive professional experience operating within Platform Engineering, Cyber Security Engineering, or Cloud Infrastructure roles.
Hashi Corp Vault Mastery:
Deep, expert-level hands-on experience with Hashi Corp Vault Enterprise—specifically managing ACL Policies, Auth Methods, and Dynamic Secrets Engine mounts.
Custom Development:
Direct, referenceable experience developing custom Vault Plugins and scripting via Vault CLI/APIs using Python or Go.
Cluster Infrastructure Management:
Proven track record managing global cluster topologies, data replication layers, token tokenization, and major platform upgrade lifecycles.
Identity Systems Depth:
Comprehensive knowledge of modern enterprise identity patterns, including OIDC, OAuth, Cloud IAM, and LDAP/Active Directory.
Cryptographic Domain Literacy:
Solid understanding of core cryptography, key management operations, and automated certificate lifecycle management (PKI engines).
Compliance & Auditing:
Practical familiarity with corporate compliance controls, auditing frameworks (e.g., SOX), and enterprise security standards.
Summary
If you are a seasoned Platform Engineer who pairs absolute system…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×