Principal Security Engineer

Citizens Bank
Johnston, RI, United States
29 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$142,000.0 - $186,000.0
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Agile Methodology Amazon Web Services Microsoft Azure Bioinformatics Cloud Computing Cloud Engineering Cyber Security Continuous Integration Data Normalization Linux DevOps
+18 more
Identity and Access Management Windows Servers Scrum Methodology Secure Coding Trello Datadog Cloud Platform System Delivery Pipeline Git Kubernetes Information Technology Atlassian Tools Hashicorp Terraform Splunk Software Version Control Devsecops Jenkins

Job description

Description DevSecOps Engineer - IAM As a DevSecOps Engineer, you will be responsible for the development, administration, maintenance, promotion, and support of the HashiCorp Vault identity-based secrets and encryption management system across multiple environments for the Citizens Bank Identity and Access Management (IAM) Engineering team. As a team, IAM Engineering is responsible for developing and IAM solutions that facilitate the acceleration and adoption of cloud-native, computing, secrets management in code for Citizens Bank. This includes building patterns and processes that allow for reduced friction in cloud development and applications teams to ingest IAM secure code, API, policies, and controls as part of the normal CI/CD pipeline. The DevSecOps Engineer will work to ensure that the HashiCorp Vault technical design is sound, that services are highly available and performant, that customers are onboarded and configured dependent on their needs, and that required maintenance is performed as necessary. Responsibilities include:· Knowledge of AWS, Azure, and HashiCorp Vault· Using an Agile methodology, assist with setting task and project priority and following through the board as decided and set· Perform version upgrades, machine image builds and deployment, and other maintenance tasks as needed· Meet and work with others to understand application and user needs from HashiCorp Vault· Using Git and Terraform, define, and configure HashiCorp Vault namespaces for a variety of secrets engines and backends· Assist with Jenkins pipeline creation, configuration, and HashiCorp Vault interoperability· Using the DataDog and Splunk data aggregation tools to monitor health and performance of the HashiCorp Vault infrastructure· Ensure that security policy, compliance requirements, and Cloud platforms best practices are implemented across all projects Experience and Skills: · Previous experience in Identity and Access Management or Information Security with a solid understanding of the requirements and goals of IAM as a regulatory and security function· Expert level experience with HashiCorp Vault· Experience with the Dev/Sec/Ops model and Agile tools and processes, including Atlassian products such as Jira and Confluence, Trello, Scrum and KanBan· Experience with HashiCorp Terraform· Experience with the Linux and Windows Server operating systems· Experience with version control systems, primarily Git· Experience with Kubernetes and Docker· Experience with automation/CI/CD systems, primarily Jenkins· Experience with building scalable Cloud infrastructure and processes· Experience in CI/CD methodology and applying the DevOps mindset and principles· Experience in systems operations management and maintaining environments for enterprise applications· Proven experience in collaborating with cross-functional business units· Experience managing Cloud platform spending through metrics and reporting· Excellent written and verbal communication skills Education:· Bachelor’s degree in computer science or comparable field or equivalent experience Hours & Work Schedule Hours per Week: 40Work Schedule: Monday through Friday, occasional after-hours as needed to perform job dutiesPay TransparencyThe salary range for this position is $142,000-$186,000 per year, plus an opportunity to earn additional incentive earnings (if applicable). Actual pay is based on various factors including, but not limited to, the budget, work location, and relevant skills and experience. We offer competitive pay, comprehensive medical, dental and vision coverage, retirement benefits, maternity/paternity leave, flexible work arrangements, education reimbursement, wellness programs and more. Note, Citizens’ paid time off policy exceeds the mandatory, paid sick or paid time-away policy of every local and state jurisdiction in the United States. For an overview of our benefits, visit Citizens Benefits. Some job boards have started using jobseeker-reported data to estimate salary ranges for roles. If you apply and qualify for this role, a recruiter will discuss accurate pay guidance. Equal Employment OpportunityCitizens, its parent, subsidiaries, and related companies (Citizens) provide equal employment and advancement opportunities to all colleagues and applicants for employment without regard to age, ancestry, color, citizenship, physical or mental disability, perceived disability or history or record of a disability, ethnicity, gender, gender identity or expression, genetic information, genetic characteristic, marital or domestic partner status, victim of domestic violence, family status/parenthood, medical condition, military or veteran status, national origin, pregnancy/childbirth/lactation, colleague’s or a dependent’s reproductive health decision making, race, religion, sex, sexual orientation, or any other category protected by federal, state and/or local laws. At Citizens, we are committed to fostering an inclusive culture that enables all colleagues to bring their best selves to work every day and everyone is expected to be treated with respect and professionalism. Employment decisions are based solely on merit, qualifications, performance and

Requirements

necessary. Responsibilities include:¡ Knowledge of AWS, Azure, and HashiCorp Vault¡ Using an Agile methodology, assist with setting task and project priority and following through the board as decided and set¡ Perform version upgrades, machine image builds and deployment, and other maintenance tasks as needed¡ Meet and work with others to understand application and user needs from HashiCorp Vault¡ Using Git and Terraform, define, and configure HashiCorp Vault namespaces for a variety of secrets engines and backends¡ Assist with Jenkins pipeline creation, configuration, and HashiCorp Vault interoperability¡ Using the DataDog and Splunk data aggregation tools to monitor health and performance of the HashiCorp Vault infrastructure¡ Ensure that security policy, compliance requirements, and Cloud platforms best practices are implemented across all projects Experience and Skills: ¡ Previous experience in Identity and Access Management or Information Security with a solid understanding of the requirements and goals of IAM as a regulatory and security function¡ Expert level experience with HashiCorp Vault¡ Experience with the Dev/Sec/Ops model and Agile tools and processes, including Atlassian products such as Jira and Confluence, Trello, Scrum and KanBan¡ Experience with HashiCorp Terraform¡ Experience with the Linux and Windows Server operating systems¡ Experience with version control systems, primarily Git¡ Experience with Kubernetes and Docker¡ Experience with automation/CI/CD systems, primarily Jenkins¡ Experience with building scalable Cloud infrastructure and processes¡ Experience in CI/CD methodology and applying the DevOps mindset and principles¡ Experience in systems operations management and maintaining environments for enterprise applications¡ Proven experience in collaborating with cross-functional business units¡ Experience managing Cloud platform spending through metrics and reporting¡ Excellent written and verbal communication skills Education:¡

Benefits & conditions

Bachelor’s degree in computer science or comparable field or equivalent experience Hours & Work Schedule Hours per Week: 40Work Schedule: Monday through Friday, occasional after-hours as needed to perform job dutiesPay TransparencyThe salary range for this position is $142,000-$186,000 per year, plus an opportunity to earn additional incentive earnings (if applicable). Actual pay is based on various factors including, but not limited to, the budget, work location, and relevant skills and experience. We offer competitive pay, comprehensive medical, dental and vision coverage, retirement benefits, maternity/paternity leave, flexible work arrangements, education reimbursement, wellness programs and more. Note, Citizens’ paid time off policy exceeds the mandatory, paid sick or paid time-away policy of every local and state jurisdiction in the United States. For an overview of our benefits, visit Citizens Benefits. Some job boards have started using jobseeker-reported data to estimate salary ranges for roles. If you apply and qualify for this role, a recruiter will discuss accurate pay guidance. Equal Employment OpportunityCitizens, its parent, subsidiaries, and related companies (Citizens) provide equal employment and advancement opportunities to all colleagues and applicants for employment without regard to age, ancestry, color, citizenship, physical or mental disability, perceived disability or history or record of a disability, ethnicity, gender, gender identity or expression, genetic information, genetic characteristic, marital or domestic partner status, victim of domestic violence, family status/parenthood, medical condition, military or veteran status, national origin, pregnancy/childbirth/lactation, colleague’s or a dependent’s reproductive health decision making, race, religion, sex, sexual orientation, or any other category protected by federal, state and/or local laws. At Citizens, we are committed to fostering an inclusive culture that enables all aa military to bring their best selves to work every day and everyone is expected to be treated with respect and professionalism. Employment decisions are based solely on merit, qualifications, performance and

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.citizensbank.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler ¡ LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 ¡ LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard ¡ WWC 2025

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer ¡ Coffee With Developers

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 ¡ LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani ¡ Europe 2026 Virtual

Videos

See all

Related articles

See all