Hybrid Secrets Management Platform Engineer

Posted 15 hours ago

Apply now

About the role

  • Infrastructure Engineer responsible for managing secrets and automated infrastructure for remote projects. Engaging in cluster operations and ensuring security and compliance while working with global teams.

Responsibilities

  • Manage the full lifecycle of clusters, including initialisation, unseal operations, upgrades, and migrations
  • Oversee Raft consensus functions, maintain quorum, and handle network partition scenarios
  • Coordinate the creation of namespaces, attach security policies, and configure authentication mounts
  • Manage audit devices and integrate log pipelines for rigorous compliance and monitoring
  • Utilise Terraform or OpenTofu to manage environment resources
  • Deploy applications to Kubernetes using Helm and leverage GitOps practices via ArgoCD or Flux
  • Fine-tune connection limits and storage I/O to optimise performance while minimising audit logging overhead
  • Implement procedures for encrypted offsite backups and disaster recovery snapshots
  • Design and execute secret injection solutions using Vault Agent, CSI driver, or External Secrets Operator, ensuring alignment with service mesh technologies and mTLS
  • Design and maintain Grafana dashboards and Prometheus metrics to track operational SLOs
  • Develop alerting rules for leader health, lease counts, and policy violations
  • Support certificate lifecycle management and maintain the essential separation between PKI and Secrets clusters
  • Produce clean, professional runbooks that allow other engineers to work independently
  • Resolve complex operational issues such as lease storms or instability.

Requirements

  • Proven experience with OpenBao or HashiCorp Vault, specifically regarding Raft consensus and cluster lifecycle management
  • High proficiency in Infrastructure as Code tools, including Terraform/OpenTofu, Helm, and ArgoCD or Flux
  • Technical expertise in Kubernetes authentication methods and various secret injection patterns (Agent, CSI, ESO)
  • Strong background in Observability tools, specifically Prometheus and Grafana, and the management of audit log pipelines
  • Experience authoring and validating Policy-as-Code using HCL within CI pipelines
  • Solid understanding of PKI fundamentals and certificate lifecycle management
  • Ability to interpret high-level architectural narratives and implement technical solutions without line-by-line instruction
  • Experience working within governance-constrained environments where security standards and procedural rigour are paramount
  • Familiarity with Agile frameworks and Scrum methodologies.

Benefits

  • Flexible working hours
  • Freedom to choose your own projects
  • Access to exciting projects in various industries
  • Competitive pay
  • Dedicated team support

Job title

Secrets Management Platform Engineer

Job type

Experience level

Mid levelSenior

Salary

Not specified

Degree requirement

No Education Requirement

Location requirements

HybridGermany

Report this job

See something inaccurate? Let us know and we'll update the listing.

Report job