Secrets Management Platform Engineer (R-00196)

🏢 True Zero Technologies · all True Zero Technologies jobs
📍 United States
📅 Posted 2026-08-16 · via Himalayas
🏷 Secrets-Management-Engineer,Platform-Engineering,Cybersecurity-Engineering,DevSecOps-Engineering,Cloud-Security-Engineering,Security-Platform-Engineer,Platform-Security-Engineer,Cybersecurity-Platform-Engineer,Identity-Platform-Engineer,Infrastructure-Platform-Engineer,IAM-Platform-Engineer
Apply on original site ↗
True Zero Technologies , a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes. True Zero recognizes that those outcomes begin and end with our people, and that is what we have built a community of like-minded, driven, and passionate individuals and innovators who are aligned in a common goal of delivering top-tier services to our customers. Our culture and commitment have been recognized through numerous accolades, including being named one of the Best Places to Work in 2023 in two categories (“Prosperous and Thriving” ($5MM–$50MM in gross revenue) and “Mid-Atlantic Region” (DC, DE, MD, NC, VA, WV)), and again in 2025 as a Best Places to Work honoree. In addition, True Zero earned coveted spots on the Inc. 5000 list of fastest-growing companies in America in 2022, 2023, and 2025 , a testament to our sustained growth driven by our people-first approach and unwavering dedication to excellence. The Secrets Management Platform Engineer designs, implements, and operates a centralized enterprise secrets management platform that securely manages credentials, keys, certificates, tokens, and other sensitive authentication material across applications, services, cloud environments, and CI/CD workflows. This role is responsible for onboarding thousands of applications and services into the secrets management platform; automating credential provisioning, retrieval, and rotation; integrating secrets management into DevSecOps and cloud-native workloads; enforcing least-privilege access; and maintaining compliance through auditing, monitoring, policy enforcement, and lifecycle governance. The engineer will support AWS GovCloud and Zero Trust requirements by eliminating hard-coded credentials, implementing strong identity-based access controls, using FIPS 140-2/3 validated cryptography, and integrating with AWS KMS and approved secrets-management services. Job Responsibilities - Onboard applications, services, users, and machine identities into a centralized secrets management platform such as CyberArk or HashiCorp Vault, based on the selected enterprise platform. - Design and implement secure processes for credential provisioning, storage, retrieval, rotation, revocation, and retirement. - Integrate AWS Secrets Manager and AWS Systems Manager Parameter Store with enterprise applications and cloud-native workloads. - Develop and enforce least-privilege Identity and Access Management policies for access to secrets, credentials, encryption keys, and privileged services. - Automate secrets management workflows using Python, Terraform, Ansible, and approved infrastructure-as-code technologies. - Integrate secrets management into CI/CD pipelines and DevSecOps workflows to eliminate manually managed or embedded credentials. - Design and support secrets integration for containers, Kubernetes-based workloads, cloud services, virtual machines, and application platforms. - Implement and maintain PKI and certificate management processes, including certificate issuance, renewal, rotation, revocation, and expiration monitoring. - Eliminate hard-coded credentials, static passwords, embedded API keys, and unmanaged secrets from source code, configuration files, scripts, pipelines, and application deployments. - Implement FIPS 140-2/3 validated cryptographic controls and integrate secrets-management solutions with AWS KMS in AWS GovCloud where required. - Configure authentication methods and access policies for users, applications, workloads, and machine identities. - Implement dynamic or short-lived credentials where supported to reduce reliance on long-lived static secrets. - Maintain centralized auditing, logging, monitoring, and alerting for secrets access, administrative activity, credential rotation, and policy violations. - Develop and enforce governance standards for secret ownership, naming, classificati

← All remote jobs