> Markdown version of [/jobs/ext/1722072-principal-systems-analyst-non-human-identity-and-secrets-management](https://www.wearedevelopers.com/jobs/ext/1722072-principal-systems-analyst-non-human-identity-and-secrets-management). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Systems Analyst, Non-Human Identity and Secrets Management - **Company:** Fmr LLC - **Location:** Denton, TX, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Computer-Aided Design, Microsoft Azure, Cloud Computing, Cyber Security, Identity and Access Management, X.509, Software Requirements Analysis, Working Model 2D, Istio, Kubernetes, Information Technology, Hashicorp - **Published:** July 7, 2026 - **Apply:** https://find.jobs/jobs-near-me/apply/ats-redirect/?id=2860317096-2 ## About the Role * Bachelor's degree in Computer Science, Information Security, Engineering, or related field (Master's preferred). * Required: 5 years' experience in systems and technical analysis * Strong expertise in HashiCorp Vault and non-interactive secrets workflows (policies, auth methods, KV, Transit, dynamic secrets, integrations). * Advanced analytical and problem-solving skills with the ability to decompose complex, multi-domain problems into clear, actionable components. * Proven experience writing high-quality user stories, acceptance criteria, requirements documents, and systems/process specifications. * Excellent communication and facilitation skills, capable of driving alignment across engineering, product, and business stakeholders. * Strong understanding of cloud infrastructure and identity (AWS IAM roles/policies, Azure Managed Identities, Kubernetes workload identities, service mesh patterns). * Knowledge of non-human identity and workload identity technologies such as SPIFFE/SPIRE, cloud workload identities, X.509/SVID issuance, and service authentication models. ## Description The Principal Systems Analyst for Non-Interactive Secrets Management is the technical and analytical lead responsible for backlog refinement, requirements, and assisting in delivery of the firm's non-interactive secrets platforms. This role translates complex cybersecurity needs into clear requirements, structured user stories, measurable outcomes, and actionable acceptance criteria. With deep expertise in HashiCorp Vault and broader non-human identity frameworks, including SPIFFE/SPIRE, workload identities, and service authentication patterns, this ensures our platform architecture and onboarding models are robust, secure, and scalable. The analyst drives the earliest and most critical stages of work: discovery, requirements definition, dependency mapping, and bringing clarity to ambiguous, cross-domain challenges. The Expertise and Skills You Bring * Lead discovery, analysis requirements gathering. * Break large initiatives into well-defined epics and user stories. * Serve as the team's primary analytical authority, ensuring requirements are technically sound. * Define functional specifications, workflows, integration requirements, and service consumption models for secrets management. * Partner closely with engineers across the full delivery lifecycle, providing clarity and alignment from design through deployment. * Drive consistent onboarding and service patterns, self-service enablement, and operational excellence. * Contribute to platform roadmaps, architecture discussions, control patterns, and capability evolution. ## Related Videos - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [Bridging AI and Nomad: a Go-based MCP Server for Cluster Control](https://www.wearedevelopers.com/videos/2063-bridging-ai-and-nomad-a-go-based-mcp-server-for-cluster-control) - [Best Practices for Using GitHub Secrets](https://www.wearedevelopers.com/videos/1214-best-practices-for-using-github-secrets) - [Securing Secrets in the GitOps era](https://www.wearedevelopers.com/videos/546-securing-secrets-in-the-gitops-era) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)