À propos de ce poste Sr. Security Tools Engineer - HashiCorp Vault & AppViewX chez GSSTech Group
We are looking for an experienced Senior Security Tools Engineer with strong hands-on expertise in enterprise security platforms, particularly HashiCorp Vault and Certificate Management/AppViewX.
The role will focus on the deployment, integration, operationalization, automation, maintenance, and continuous improvement of enterprise security tools across technology platforms. The ideal candidate should have strong security engineering fundamentals, excellent scripting and automation skills, experience working with large-scale infrastructure environments, and the ability to collaborate with Architecture, Infrastructure, Security, Development, and business stakeholders.
Candidates should have strong hands-on experience in at least two primary security tool areas, with exposure to additional IAM, PAM, certificate management, database security, HSM, or tokenization technologies considered an advantage.
Requirements
Key Responsibilities
- Design, deploy, integrate, operationalize, and maintain enterprise security tools and platforms.
- Develop secure, reliable, scalable, and highly available security solutions.
- Customize and automate security tools and workflows using modern scripting and API-based integrations.
- Apply Site Reliability Engineering principles to the operation and maintenance of security platforms.
- Work closely with Infrastructure, Architecture, Security, Development, Change Management, and application support teams.
- Participate in solution design, implementation, migration, troubleshooting, and production support activities.
- Research emerging security technologies and contribute to security standards, policies, and technical baselines.
- Assess security risks and provide appropriate mitigation options to technical and business stakeholders.
- Support security operations and incident response activities when required.
- Ensure privileged identities, secrets, certificates, and other security assets are securely managed throughout their lifecycle.
- Participate in Agile delivery frameworks and contribute to continuous improvement and automation initiatives.
- Manage technical deliverables, dependencies, implementation timelines, and stakeholder expectations.
Primary Security Tool Expertise
Candidates should have strong hands-on experience in at least two primary security tool areas, with particular preference for AppViewX and HashiCorp Vault.
1. Certificate Management – AppViewX
Strong hands-on experience in:
- Certificate Lifecycle Management.
- Automated certificate renewal, revocation, provisioning, and deployment.
- SSL/TLS, SSH, and X.509 certificates.
- CSR generation and Public Key Infrastructure (PKI) hierarchies.
- Integration with internal and external Certificate Authorities.
- Experience integrating with Certificate Authorities such as:
- Microsoft CA
- Venafi
- DigiCert
- Entrust
- Certificate deployment and management across enterprise infrastructure.
- Linux and Windows Server administration.
- Python scripting and REST API integrations for automation and custom workflows.
- Basic understanding of network infrastructure and certificate deployment across:
- Load Balancers
- Firewalls
- Web Servers
- F5 BIG-IP
- NGINX
- Apache
- IIS
2. Secrets Management – HashiCorp Vault
Strong hands-on experience in:
- Designing, implementing, and maintaining centralized secrets management using HashiCorp Vault.
- Installation and operationalization of HashiCorp Vault and Consul/Raft storage components in on-premises and cloud environments.
- HashiCorp Vault integration with target applications for secure secrets management.
- Authentication methods including:
- LDAP
- AppRole
- Kubernetes
- Installation, administration, monitoring, and troubleshooting of HashiCorp Vault.
- Migration of storage from Consul to integrated Raft storage.
- Integration of Vault with Jenkins and Kubernetes for secure credential injection.
- Deployment of HashiCorp Vault Enterprise on Linux servers.
- High-availability deployment using OpenShift and VMware environments.
- Troubleshooting production issues involving:
- AppRole
- Secrets
- Namespaces
- KV secrets engine
- Transit secrets engine
- Authentication methods
- Hardening HashiCorp Vault according to industry security standards.
- Vault High Availability and Disaster Recovery strategies.
- Basic understanding of:
- Load Balancers
- Data-center affinity
- Network infrastructure
- Understanding of encryption, vulnerability assessment, SIEM, and broader security controls.
Secondary Security Technologies – Good to Have
Exposure to one or more of the following will be an advantage:
- CyberArk – Privileged Access Management (PAM)
- SailPoint – Identity Services / Identity Governance
- Ping Identity – Single Sign-On / SSO
- Imperva – Database Access Monitoring
- Thales PayShield HSM
- Thales Luna HSM
- CipherTrust Manager (CTM)
- CTVL / Tokenization Engine
- Enterprise IAM and privileged identity management solutions.
Development, Scripting & Automation
Strong development and automation capability is required, including experience with:
- Python
- PowerShell
- Bash / Shell scripting
- Java
- .NET
- REST APIs
- API-based integrations
- Workflow automation
- Security tool customization and enhancement
Candidates should demonstrate the ability to identify manual security processes and develop automated solutions to improve operational efficiency and security.
Security & Infrastructure Knowledge
Strong understanding of:
- Enterprise security concepts.
- Identity and Access Management (IAM).
- Privileged Identity Management.
- Secrets management.
- Certificate and PKI management.
- Encryption and cryptographic concepts.
- Vulnerability assessment.
- SIEM and security monitoring.
- Security hardening and security baselines.
- High Availability and Disaster Recovery.
- Linux and Windows Server environments.
- Load balancing and basic network infrastructure.
- Cloud and on-premises infrastructure environments.
Delivery & Stakeholder Management
- Work with business and process owners to understand requirements and deliver secure technology solutions.
- Collaborate with Infrastructure teams to ensure consistency and operational readiness.
- Partner with Architecture teams to align solutions with enterprise architecture standards.
- Work with Security teams to ensure compliance with security standards and controls.
- Coordinate with Development, Change Management, and application support teams.
- Manage technical dependencies, implementation timelines, and project deliverables.
- Communicate technical risks, threats, issues, and mitigation options clearly to both technical and business stakeholders.
- Contribute to Agile delivery, sprint planning, technical implementation, and continuous improvement activities.
Key Success Areas
The successful candidate will be expected to:
- Design and implement secure, reliable, and scalable security platforms.
- Maintain high availability, stability, and efficiency of security tools.
- Deliver high-quality technical designs and implementation recommendations.
- Improve security automation and operational efficiency.
- Maintain strong security standards, baselines, and controls.
- Ensure secure lifecycle management of certificates, secrets, and privileged identities.
- Support Cyber Security Operations during security incidents.
- Identify and mitigate technical and security risks.
- Maintain strong stakeholder satisfaction and communication.
Required Qualifications & Experience
- Bachelor's or Master's degree in Computer Science, Information Technology, Cybersecurity, or a related discipline.
- 8+ years of relevant experience working with security technologies in large enterprise environments.
- Strong hands-on experience with enterprise security tools and platforms.
- Strong expertise in HashiCorp Vault and/or AppViewX, with experience across at least two relevant primary security tool areas preferred.
- Strong scripting and automation skills.
- Experience working with large-scale infrastructure and production environments.
- Strong troubleshooting and incident-resolution capabilities.
- Experience collaborating with Architecture, Infrastructure, Security, Development, and business stakeholders.
Preferred Certifications
The following certifications are advantageous:
- CISSP
- CISA
- CISM
- Relevant HashiCorp certifications
- Relevant IAM / PAM / Cybersecurity certifications
Behavioral & Leadership Competencies
- Strong security mindset.
- Highly organized and process-oriented.
- Innovative approach to automation and technical enhancement.
- Strong analytical and problem-solving ability.
- Comfortable taking ownership and accountability.
- Strong team player who actively collaborates and listens to others.
- Clear, concise, and effective communication.
- Ability to work across organizational boundaries.
- Ability to operate effectively in complex enterprise environments.
- Strong leadership and stakeholder management capability.
- Willingness to continuously learn and adapt to evolving security technologies.