This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We’re seeking a Staff Infrastructure Security Engineer to architect and operationalize the foundational security services that enable our transition to a Zero Trust model. This is a highly strategic role focused on establishing the organization’s “roots of trust,” with immediate ownership of our enterprise HashiCorp Vault platform, from Proof of Concept through global production readiness. You’ll serve as the subject matter expert for secrets management and identity architecture, while designing scalable, self-service trust patterns across our hybrid, multi-cloud environment. Over time, this role will shape our long-term credentials management strategy and how engineering teams securely interact with core infrastructure.
Job Responsibility:
Architecting a highly available, disaster-resilient, multi-cluster secrets management platform as the foundation of our Zero Trust strategy
Driving Vault from PoC to enterprise-grade production, establishing standards, reliability, and scalability
Leading cross-functional alignment with Cloud Engineering, DevOps, and SRE teams on secure secret management workflows embedded into the SDLC
Designing and enforcing governance controls to meet internal policies and external compliance requirements (e.g., SOX, ISO 27001)
Implementing Policy as Code using Sentinel to automate guardrails and access decisions
Engineering Vault infrastructure using Terraform with fully automated, reproducible, and version-controlled deployments
Architecting integrations between Vault, identity providers (e.g., Okta), and workload identities (e.g., Kubernetes Service Accounts)
Configuring and tuning core Vault secrets engines (KV, Transit, KMIP) and Enterprise features such as performance replication and automated sealing
Operationalizing “Vault as a Service” through paved-road onboarding, self-service workflows, and clear developer documentation
Building observability across the platform, including monitoring, alerting, audit logging, and usage insights
Requirements:
8+ years of hands-on experience in cloud security, DevOps, or infrastructure engineering
Deep, production-grade experience deploying and operating HashiCorp Vault in enterprise environments (Enterprise edition strongly preferred)
Expert knowledge of secrets management, cryptography, PKI/X.509 certificate authorities, and trust systems
Strong experience with Google Cloud Platform (GCP) and cloud-native IAM models
Proven expertise using Infrastructure-as-Code tools (Terraform) to automate security platforms
Hands-on experience with Kubernetes and securely integrating secrets into microservices architectures
Fluency in at least one programming language (Go or Python preferred) for automation and tooling
Strong understanding of network security fundamentals, including segmentation, firewalls, routing, and Zero Trust concepts
Nice to have:
Experience building internal “security platforms” or Vault-as-a-Service offerings
Prior ownership of enterprise-wide identity or credential lifecycle programs
Experience operating Vault across hybrid or multi-cloud environments
Familiarity with advanced Vault governance patterns and large-scale developer onboarding
What we offer:
Industry competitive pay
Restricted Stock Units in a fast growing, well-funded technology company
Health insurance package options that include HDHP and PPO, vision, and dental for you and your dependents
Employer contributions to HSA accounts
Paid Parental Leave
Paid life insurance, short-term and long-term disability