Senior HashiCorp Architect and Implementation Consultant @Invicta Solutions Group
All Others
Salary unspecified
Remote Location
Employment Type contract
Posted 1mth ago

[Hiring] Senior HashiCorp Architect and Implementation Consultant @Invicta Solutions Group

1mth ago - Invicta Solutions Group is hiring a remote Senior HashiCorp Architect and Implementation Consultant. πŸ’Έ Salary: unspecified πŸ“Location: Worldwide

Role Description

This is a remote position.

We are seeking a Senior HashiCorp Architect and Implementation Consultant to design and implement enterprise-grade HashiCorp Vault solutions supporting secure workload identity, privileged access, dynamic credential delivery, Kubernetes platforms, and AI and agentic application security. This consultant will serve as the HashiCorp technical lead for an integrated Enterprise Trust Operating Model (ETOM) implementation, with particular responsibility for agentic identity, delegated authority, MCP/API enforcement, controlled credential injection, and end-to-end provenance. The role combines architecture leadership, hands-on configuration, systems integration, testing, documentation, knowledge transfer, and operational readiness.

Qualifications

  • HashiCorp Vault Enterprise architecture, implementation, administration, and troubleshooting
  • Vault authentication methods, identity system, tokens, leases, policies, namespaces, and secrets engines
  • Dynamic database and cloud credentials, PKI, transit encryption, key management, and credential brokering
  • Vault Agent, Agent Injector, Secrets Store CSI Driver, Kubernetes authentication, and workload identity
  • Integrated Storage, high availability, performance replication, disaster recovery replication, backup, and recovery
  • Terraform, HCL, REST APIs, CLI automation, and policy-as-code
  • Kubernetes and OpenShift security and platform integration
  • Cloud IAM and secrets-management integration across AWS, Microsoft Azure, and Google Cloud
  • Enterprise identity federation using OIDC, OAuth 2.0, JWT, SAML, LDAP, and related identity standards
  • API gateways, service-to-service security, MCP or agent-tool enforcement, and controlled credential injection
  • AI and agentic security architecture, including agent identity, subagent delegation, human-in-the-loop approval, tool authorization, decision lineage, and secure runtime integration
  • MCP clients, servers, gateways, routers, registries, tool catalogs, request normalization, policy enforcement, and secure tool-execution patterns
  • API security and enforcement using OAuth 2.0, OIDC, JWT, token exchange, mTLS, workload identity, fine-grained authorization, gateway policy, and service-mesh controls
  • Kubernetes security architecture, including service accounts, projected service-account tokens, RBAC, admission controls, network policies, sidecar and CSI injection patterns, and multi-cluster workload identity
  • AI platform integration across enterprise agent runtimes, model gateways, orchestration frameworks, and custom agent applications
  • Audit logging, SIEM integration, observability, incident response, and compliance evidence
  • Linux administration, networking, TLS, certificates, load balancing, and enterprise infrastructure architecture

Requirements

  • 8+ years of cybersecurity, identity, cloud security, platform engineering, or secrets-management experience.
  • 5+ years of hands-on HashiCorp Vault architecture and implementation experience in enterprise environments.
  • Demonstrated experience leading at least two production Vault implementations or major enterprise expansions.
  • Experience designing highly available, multi-environment, and disaster-recovery Vault architectures.
  • Experience integrating Vault with Kubernetes, cloud platforms, enterprise identity providers, applications, databases, and CI/CD systems.
  • Hands-on experience securing AI or agentic systems, including agent identity, delegated authority, MCP tool use, API enforcement, and controlled access to downstream credentials.
  • Experience implementing Vault in Kubernetes or OpenShift using Kubernetes authentication, Vault Agent Injector, Secrets Store CSI Driver, service accounts, Helm, operators, and infrastructure-as-code.
  • Experience integrating Vault with MCP gateways, API gateways, service meshes, agent runtimes, or custom AI orchestration frameworks is strongly preferred.
  • Experience implementing dynamic credentials, workload identity, least-privilege access, credential rotation, and revocation.
  • Experience developing Terraform automation, reusable deployment patterns, test plans, and operational runbooks.
  • Ability to facilitate executive and technical workshops and translate security requirements into implementable architecture.
  • Excellent documentation, presentation, troubleshooting, and client-facing consulting skills.

Preferred Qualifications

  • HashiCorp Certified: Vault Associate certification; advanced HashiCorp or Terraform credentials are preferred.
  • Experience with IBM Verify, enterprise privileged-access management, certificate lifecycle management, HSMs, or external key-management systems.
  • Experience securing agentic AI platforms, MCP clients and servers, agent gateways, or automated tool-execution environments.
  • Experience with regulated or high-assurance environments such as financial services, healthcare, government, or critical infrastructure.
  • Familiarity with Zero Trust Architecture, NIST guidance, identity threat modeling, and secure software delivery practices.

Ideal Candidate Profile

The ideal consultant combines deep HashiCorp Vault expertise with strong enterprise architecture, implementation, Kubernetes, API security, and AI security capabilities. They can move confidently from whiteboard design to production configuration, explain complex human-to-agent-to-subagent identity and credential flows to both executives and engineers, and implement enforceable controls across Vault, Kubernetes, MCP gateways, API gateways, and agent runtimes. They understand how to preserve actor lineage and delegated authority, bind approval and intent to credential release, prevent bypass and caller-supplied credentials, and provide end-to-end evidence and scoped revocation. Success in this role requires disciplined security engineering, transparent documentation of assumptions and dependencies, a strong focus on least privilege and fail-closed behavior, and the ability to deliver a supportable solution that client teams can operate after transition.

Before You Apply
️
worldwide Be aware of the location restriction for this remote position: Worldwide
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior HashiCorp Architect and Implementation Consultant @Invicta Solutions Group
All Others
Salary unspecified
Remote Location
Employment Type contract
Posted 1mth ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
worldwide Be aware of the location restriction for this remote position: Worldwide
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 127,508+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later