Jobs · Engineering · California

Lead Infrastructure Engineer (Encryption Security-Hashicorp Vault)

Wells Fargo · San Francisco, CA · 1 wk ago
Engineering$119k–$224k/yrFull-time

About the role

This position is part of a team that performs engineering and management of data protection technologies, including HashiCorp Vault. The role involves providing production support and end-to-end management of HSMs, security appliances, and data protection/encryption technologies in medium to large enterprise environments.

Responsibilities

  • Independently design, implement, and manage a secure, highly available HashiCorp Vault platform with minimal oversight.
  • Contribute to end-to-end automation of Vault provisioning, configuration, and lifecycle management using Ansible and Terraform.
  • Develop and enforce platform standards for secrets management, authentication, authorization, and Vault best practices.
  • Analyze and solve complex technical challenges, including cloud-native and multi-cloud integrations, Kubernetes auth setups, PKI hierarchies, replication, and performance optimization.
  • Collaborate with cross-functional teams—security, platform engineering, application teams, product owners, and vendors—to deliver architecturally sound Vault solutions.
  • Troubleshoot deep technical issues independently, including HA failures, unseal workflows, auth method problems, and secret engine configuration errors.
  • Implement advanced Vault capabilities, such as static and dynamic secrets, PKI secret engine, dynamic database secrets, and namespace management.
  • Guide and support engineering teams by providing Vault expertise, technical recommendations, and onboarding assistance.
  • Drive continuous improvement by identifying opportunities for automation, performance tuning, reliability enhancements, and security hardening.
  • Provide on-call support on a rotational basis per the team's schedule.
  • Interact with encryption technology and HSM vendors to align product engineering with Wells Fargo’s objectives and security requirements, and coordinate with vendor support teams to resolve issues.
  • Engage with technical, engineering, and non-technical partners companywide for the technologies listed above.
  • Create technical and engineering documentation with excellent written and oral communication.

Requirements

  • 5+ years of Technology Infrastructure Engineering and Solutions experience, or equivalent demonstrated through work experience, training, military experience, or education.
  • 3+ years of hands-on experience with HashiCorp Vault, including enterprise-grade Vault design, deployment, and automation.
  • 1+ years of Linux system administration for installing, configuring, securing, and troubleshooting Vault clusters.
  • 1+ years of experience with the Vault lifecycle, including installation, upgrades, HA deployment, scaling, and cluster maintenance.

Qualifications

  • Practical experience with Enterprise Change Management, change control processes, and compliance-driven environments.
  • Hands-on expertise with Terraform, Ansible, CI/CD pipelines, and GitHub for Vault provisioning and configuration.
  • Proven experience designing, integrating, and maintaining Vault Secret Engines (KV, Database, PKI, Azure, GCP, LDAP, Dynamic secret engines, and secret rotation flows).
  • Strong experience designing, implementing, and maintaining Vault Auth Engines (LDAP, AppRole, Kubernetes, JWT/OIDC, TLS Certificate authentication).
  • Hands-on experience implementing Vault Auto-Unseal using HSM-based solutions.
  • Experience configuring and maintaining Vault audit logging, monitoring, and metrics using tools like Splunk and Grafana.
  • Hands-on expertise with Vault Agent, templates, auto-auth, and Vault Proxy integrations.
  • Experience with HashiCorp Vault services such as Key Management System, secret, and certificate management.
  • Good knowledge of DevOps and SDLC for IaC CI/CD concepts, GitHub, and branching strategies.
  • Professional HashiCorp Vault Certification (HVCP or equivalent).

Schedule

This position offers a hybrid work schedule.

Relocation assistance is not available for this position.

Telecommuting is not an option for this position.

This position is not eligible for visa sponsorship.

On-call rotation required.

Pay

The base pay range for this position is $119,000.00 - $224,000.00. Pay may vary depending on factors including but not limited to demonstrated prior performance, skills, experience, or work location. Employees may also be eligible for incentive opportunities.

Benefits

  • Health benefits
  • 401(k) Plan
  • Paid time off
  • Disability benefits
  • Life insurance, critical illness insurance, and accident insurance
  • Parental leave
  • Critical caregiving leave
  • Discounts and savings
  • Commuter benefits
  • Tuition reimbursement
  • Scholarships for dependent children
  • Adoption reimbursement

Similar jobs