Infrastructure Engineer responsible for managing secrets and automated infrastructure for remote projects. Engaging in cluster operations and ensuring security and compliance while working with global teams.
Responsibilities
Manage the full lifecycle of clusters, including initialisation, unseal operations, upgrades, and migrations
Coordinate the creation of namespaces, attach security policies, and configure authentication mounts
Manage audit devices and integrate log pipelines for rigorous compliance and monitoring
Utilise Terraform or OpenTofu to manage environment resources
Deploy applications to Kubernetes using Helm and leverage GitOps practices via ArgoCD or Flux
Fine-tune connection limits and storage I/O to optimise performance while minimising audit logging overhead
Implement procedures for encrypted offsite backups and disaster recovery snapshots
Design and execute secret injection solutions using Vault Agent, CSI driver, or External Secrets Operator, ensuring alignment with service mesh technologies and mTLS
Design and maintain Grafana dashboards and Prometheus metrics to track operational SLOs
Develop alerting rules for leader health, lease counts, and policy violations
Support certificate lifecycle management and maintain the essential separation between PKI and Secrets clusters
Produce clean, professional runbooks that allow other engineers to work independently
Resolve complex operational issues such as lease storms or instability.
Requirements
Proven experience with OpenBao or HashiCorp Vault, specifically regarding Raft consensus and cluster lifecycle management
High proficiency in Infrastructure as Code tools, including Terraform/OpenTofu, Helm, and ArgoCD or Flux
Technical expertise in Kubernetes authentication methods and various secret injection patterns (Agent, CSI, ESO)
Strong background in Observability tools, specifically Prometheus and Grafana, and the management of audit log pipelines
Experience authoring and validating Policy-as-Code using HCL within CI pipelines
Solid understanding of PKI fundamentals and certificate lifecycle management
Ability to interpret high-level architectural narratives and implement technical solutions without line-by-line instruction
Experience working within governance-constrained environments where security standards and procedural rigour are paramount
Familiarity with Agile frameworks and Scrum methodologies.
Security Platform Engineer at NTT DATA responsible for security incident handling and monitoring. Collaborating with a 24/7 team on various security tools and technologies.
Power Platform Developer leveraging cutting - edge technology solutions at global consultancy firm. Focus on Capital Markets, Trading and Risk Management functions to deliver innovation.
Cloud Security Platform Engineer at Alan, focusing on securing healthcare delivery systems through cloud infrastructure and strengthening security practices and tooling.
Technical Lead managing a team to deliver capabilities within Fidelity's Observability Platform. Leading design, development, and support of observability integrations with various frameworks.
Platform Engineer creating and supporting DevOps tools with emerging technologies at Capital One. Collaborating within Agile teams to improve software engineering practices and drive transformation.
Software Engineer developing scalable data pipelines and cloud solutions for Cummins' products. Collaborating with teams to ensure data quality and governance in a modern engineering environment.
Senior Platform Engineer at Rootly building infrastructure for incident management and enhancing system reliability. Collaborate with product teams to drive performance and scalability of services in a high - impact environment.
Founding leader of Platform Engineering at Rootly, shaping reliable incident management infrastructure. Building and leading teams to ensure high performance and operational maturity in a fast - growing environment.
Cloud Platform Engineer developing software solutions for federal government customers. Working with Cloud technology (AWS), Go, and Linux in a hybrid environment.