Senior Engineer - HashiCorp Vault
IBM · San Jose, CA · 2 mo ago
HybridEngineeringFull-time
Role Overview
We are seeking a seasoned engineer to design, build, and operate HashiCorp Vault as a service. The ideal candidate will be responsible for secure, highly available, and compliant secrets management services, delivered at scale across Kubernetes and OpenShift environments.
Responsibilities
- Design and resolve complex models and procedures for secure secrets management.
- Deliver creative, effective solutions while understanding cross-functional interdependencies.
- Lead the application of existing products and services, and influence the development of new policies and ideas.
- Own and drive the reliable execution of large projects (typically spanning 4–12 weeks), including end-to-end design, full lifecycle implementation, and troubleshooting.
- Evaluate trade-offs, propose solutions, remove blockers, and communicate progress to stakeholders.
- Collaborate directly with internal teams, customers, and external communities to design solutions based on real-world requirements.
- Debug and resolve complex issues, review code for quality and patterns, and mentor other engineers.
- Guide team collaboration activities such as pairing and knowledge sharing.
- Participate in hiring by leading interviews for junior candidates and contributing to calibration for mid-level roles.
- Participate in on-call rotations, pairing, and team planning to support product needs.
Preferred Education and Technical Expertise
- Bachelor's Degree Required
- Extensive experience building production-grade services in Golang with strong testing and code quality practices.
- Experience with managing Kubernetes workloads and platform components, including networking, storage, and security.
- Skilled in designing reliable, scalable, and operable distributed systems on AWS, Azure, or GCP.
- Cloud-native mindset with solid DevOps principles and automation expertise.
- Proven decision-making using data-driven approaches to solve technical challenges.
Preferred Technical and Professional Experience
- Hands-on experience operating HashiCorp Vault at scale (auth methods, PKI/Transit/KV engines, policies, HA/DR, backups).
- Experience with managing Kubernetes workloads and platform components, including networking, storage, and security.
- Experience with Openshift, Helm, Kustomize, Terraform, and GitOps workflows (Argo CD/Flux).
- Understanding of TLS/mTLS, certificate management, IAM, and secrets lifecycle.