Seeking a IAM Security Engineer with strong expertise in securing and managing enterprise environments. The ideal candidate will have hands-on experience with HashiCorp Vault Enterprise Edition, Terraform, RHEL, and Ansible, and will be expected to maintain, support and enhance the on-premises Swift Secrets Management Service (= SSMS) that is based upon HashiCorp Vault - Enterprise edition (Vault), tools, processes, and technologies including but not limited to:
• Develop, test and perform OS and software upgrades, prepare for and perform business continuity activities and address vulnerabilities for our Hashicorp Vault Enterprise edition infrastructures
• Interact with Vendor and Swift internal teams to ensure availability of, maintenance, enhancements to, and integrated with all the Swift ecosystems (MS-AD, monitoring, backup, SIEM, …) of SSMS /Vault infrastructure
• Investigate and resolve issues that impacts or could potentially impact the availability of SSMS and its Vault infrastructure
• Troubleshoot and monitor performance and security of Vault infrastructure
• Assist application team(s) with onboarding digital secrets to the Secret Management including reviewing environment for authentication method, secrets engine to onboard secrets, assist in developing compliance reporting, policy review/enforcement, end to end lifecycle management activities
• Work with team to expand services and visibility by continuing to review offering, speaking with stakeholders and assisting new application teams to adopt and automate
• Develop and maintain automation workflows using ansible.
• Develop and maintain Terraform modules for secure infrastructure provisioning.
• Enhance and provide regular reporting and accountability on key metrics and agreed upon deliverables and ensure that the team is performing according to them
• Maintain a customer guide that can be reused by the application team(s) for future onboarding actions
• Maintain a runbook for the Secret Management service infrastructure and work with the administrators to maintain and enhance the administrators guide
• On-call on a rotational basis
• On-site presence for at least 2 days a week (Hybrid mode)
Skills
1.Ansible experience (developing roles, playbooks, AWX or Ansible Tower) 4 Years Professional (4-5)
2.Experience with DevOps and DevOps tooling (Jira, Git, Jenkins, etc.) 4 Years Professional (4-5)
3.Experience with Phyton and scripting 4 Years Professional (4-5)
4.Go development (especially for Vault plugin) 2 Years Junior (1-3)
5. HashiCorp Vault Enterprise Edition management (deployment/upgrade in HA,
troubleshooting, monitoring, hardening, integrations 3 Years Junior (1-3)
6. Red Hat Linux 7 and 8 system administration (troubleshooting, monitoring, hardening) 5 Years Professional (4-5)
7. Red Hat Linux 9 system administration (troubleshooting, monitoring, hardening) 2 Years Junior (1-3)
8. SELinux (policy development and troubleshooting) 3 Years Junior (1-3)
9. Terraform hands-on experience (module development) 4 Years Professional (4-5)