Lead Infrastructure Engineer (Encryption Security-Hashicorp Vault)
Wells Fargo · Iselin, NJ · 1 wk ago
Engineering$119k–$224k/yrFull-time
This position will be part of a team that performs engineering and management of data protection technologies, including HashiCorp Vault. Candidates must have intermediate to advanced systems engineering experience in medium to large enterprise environments.
Responsibilities
- Independently design, implement, and manage secure, highly available HashiCorp Vault platform with minimal oversight from lead engineers
- Contribute to end-to-end automation of Vault provisioning, configuration, and lifecycle management using Ansible and Terraform
- Develop and enforce platform standards for secrets management, authentication, authorization, and Vault best practices across the organization
- Analyze and solve complex technical challenges, including cloud native and multi-cloud integrations, Kubernetes auth setups, PKI hierarchies, replication, and performance optimization
- Collaborate directly with cross-functional teams—security, platform engineering, application teams, product owners, and vendors—to deliver architecturally sound Vault solutions
- Troubleshoot deep technical issues independently, including HA failures, unseal workflows, auth method problems, and secret engine configuration errors
- Implement advanced Vault capabilities, such as static and dynamic secrets, PKI secret engine, dynamic Database secrets, and namespace management
- Guide and support engineering teams, providing Vault expertise, technical recommendations, and onboarding assistance without requiring constant supervision
- Drive continuous improvement, identifying opportunities for automation, performance tuning, reliability enhancements, and security hardening across Vault deployments
- Provide on-call support on a rotational basis per team's schedule
- Participate in interactions with encryption technology and HSM vendors to ensure vendor product engineering aligns with Wells Fargo’s objectives and security requirements, and coordinate with vendor support teams to resolve issues
- Engage with technical, engineering, and non-technical partners companywide for the technologies listed above
- Create technical and engineering documentation
Requirements
- 5+ years of Technology Infrastructure Engineering and Solutions experience, or equivalent demonstrated through work experience, training, military experience, or education
- 3+ years of hands-on experience with HashiCorp Vault, with a proven track record in enterprise-grade Vault design, deployment, and automation
- 1+ years of Linux system administration, required for installing, configuring, securing, and troubleshooting Vault clusters
- 1+ years of experience with the Vault lifecycle, including installation, upgrades, HA deployment, scaling, and cluster maintenance
- Extensive experience with Linux Server operating systems (Red Hat preferred)
- Experience providing production support and end-to-end management of HSMs, security appliances, and/or data protection/encryption technologies
- Extensive experience with scripting and automation practices
- Excellent written and oral communication skills
Qualifications
- Practical experience with Enterprise Change Management, change control processes, and operating within procedural, compliance-driven environments
- Hands-on expertise with Terraform, Ansible, CI/CD pipelines, and GitHub, with a strong understanding of modern automation pipelines for Vault provisioning and configuration
- Proven experience designing, integrating, and maintaining Vault Secret Engines, including: KV, Database, PKI, Azure, GCP, LDAP, Dynamic secret engines, and secret rotation flows
- Strong experience designing, implementing, and maintaining Vault Auth Engines, such as: LDAP, AppRole, Kubernetes, JWT/OIDC, TLS Certificate authentication
- Hands-on experience implementing Vault Auto-Unseal using HSM-based solutions
- Experience configuring and maintaining Vault audit logging, monitoring, and metrics, using tools like Splunk, Grafana, and other observability platforms
- Hands-on expertise with Vault Agent, templates, auto-auth, and Vault Proxy integrations
- Hands-on experience using HashiCorp Vault services like Key Management System, Secret and Certificate Management
- Good knowledge of DevOps and SDLC for IaC CI/CD concepts, GitHub, and branching strategies
- Professional HashiCorp Vault Certification (HVCP or equivalent)
Schedule
- This position offers a hybrid work schedule
- On-call rotation required
Relocation assistance is not available for this position. Telecommuting is not an option. This position is not eligible for visa sponsorship.
Pay
$119,000.00 - $224,000.00 base pay range. Pay may vary depending on factors including but not limited to demonstrated examples of prior performance, skills, experience, or work location. Employees may also be eligible for incentive opportunities.
Benefits
- Health benefits
- 401(k) Plan
- Paid time off
- Disability benefits
- Life insurance, critical illness insurance, and accident insurance
- Parental leave
- Critical caregiving leave
- Discounts and savings
- Commuter benefits
- Tuition reimbursement
- Scholarships for dependent children
- Adoption reimbursement