Secrets Management Platform Engineer @True Zero Technologies
All Others
Salary unspecified
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 1mth ago

[Hiring] Secrets Management Platform Engineer @True Zero Technologies

1mth ago - True Zero Technologies is hiring a remote Secrets Management Platform Engineer. πŸ’Έ Salary: unspecified πŸ“Location: USA

Role Description

The Secrets Management Platform Engineer designs, implements, and operates a centralized enterprise secrets management platform that securely manages credentials, keys, certificates, tokens, and other sensitive authentication material across applications, services, cloud environments, and CI/CD workflows.

This role is responsible for:

  • Onboarding thousands of applications and services into the secrets management platform.
  • Automating credential provisioning, retrieval, and rotation.
  • Integrating secrets management into DevSecOps and cloud-native workloads.
  • Enforcing least-privilege access.
  • Maintaining compliance through auditing, monitoring, policy enforcement, and lifecycle governance.

The engineer will support AWS GovCloud and Zero Trust requirements by:

  • Eliminating hard-coded credentials.
  • Implementing strong identity-based access controls.
  • Using FIPS 140-2/3 validated cryptography.
  • Integrating with AWS KMS and approved secrets-management services.

Qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related technical discipline.
  • Demonstrated experience implementing or administering an enterprise secrets management platform such as CyberArk or HashiCorp Vault.
  • Experience with AWS Secrets Manager, AWS Systems Manager Parameter Store, and AWS KMS.
  • Strong understanding of Identity and Access Management, role-based access control, policy-based access, and least-privilege principles.
  • Hands-on automation experience using Python, Terraform, and/or Ansible.
  • Experience integrating secrets-management solutions with CI/CD pipelines, DevSecOps workflows, and automated deployment processes.
  • Experience with PKI, certificate management, encryption, key management, and certificate lifecycle automation.
  • Understanding of container and cloud security, including secrets integration for Kubernetes, containerized applications, and cloud-native workloads.
  • Experience designing credential rotation, dynamic secrets, machine identity, and privileged-access workflows.
  • Familiarity with FIPS 140-2/3 validated cryptography and cryptographic requirements for government or regulated environments.
  • Experience implementing controls to identify and eliminate hard-coded credentials and unmanaged secrets.
  • Strong understanding of Zero Trust principles, particularly least privilege, identity-based access, continuous verification, and credential minimization.
  • Experience supporting AWS GovCloud, government, defense, or other regulated cloud environments is preferred.
  • Experience with centralized logging, monitoring, auditing, compliance reporting, and security-event integration.
  • Strong troubleshooting, documentation, governance, automation, and cross-functional collaboration skills.

Requirements

  • Onboard applications, services, users, and machine identities into a centralized secrets management platform.
  • Design and implement secure processes for credential provisioning, storage, retrieval, rotation, revocation, and retirement.
  • Integrate AWS Secrets Manager and AWS Systems Manager Parameter Store with enterprise applications and cloud-native workloads.
  • Develop and enforce least-privilege Identity and Access Management policies.
  • Automate secrets management workflows using Python, Terraform, Ansible, and approved infrastructure-as-code technologies.
  • Integrate secrets management into CI/CD pipelines and DevSecOps workflows.
  • Design and support secrets integration for containers, Kubernetes-based workloads, cloud services, virtual machines, and application platforms.
  • Implement and maintain PKI and certificate management processes.
  • Eliminate hard-coded credentials, static passwords, embedded API keys, and unmanaged secrets.
  • Implement FIPS 140-2/3 validated cryptographic controls.
  • Configure authentication methods and access policies for users, applications, workloads, and machine identities.
  • Implement dynamic or short-lived credentials where supported.
  • Maintain centralized auditing, logging, monitoring, and alerting for secrets access.
  • Develop and enforce governance standards for secret ownership, naming, classification, access, rotation frequency, expiration, and lifecycle management.
  • Partner with application, cloud, platform, cybersecurity, and DevSecOps teams.
  • Troubleshoot authentication, authorization, credential rotation, certificate, API, and platform integration issues.
  • Maintain technical documentation, onboarding procedures, platform standards, operational runbooks, and governance processes.
  • Continuously improve platform availability, scalability, automation, security controls, onboarding efficiency, and operational resilience.

Benefits

  • Competitive salary, paid twice per month.
  • Best in class medical coverage.
  • 100% of medical premiums covered by True Zero.
  • Company wide new business incentive programs.
  • Contribution Incentives (i.e. white papers, blog posts, internal webinars, etc.).
  • 3 weeks of PTO starting + 11 Paid Holidays Annually.
  • 401k Program with 100% company match on the first 4%.
  • Monthly reimbursement of Cell Phone and Home Internet costs.
  • Paternity/Maternity Leave.
  • Investment in training and certifications to broaden and deepen your technical skills.
Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Secrets Management Platform Engineer @True Zero Technologies
All Others
Salary unspecified
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 1mth ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 126,233+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later