Principal Systems Analyst, Non-Human Identity and Secrets Management

Fmr LLC
Euless, TX, United States
2 months ago
Apply on find.jobs
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Computer-Aided Design Microsoft Azure Cloud Computing Cyber Security Identity and Access Management X.509 Software Requirements Analysis Working Model 2D Istio Kubernetes Information Technology Hashicorp

Job description

The Principal Systems Analyst for Non-Interactive Secrets Management is the technical and analytical lead responsible for backlog refinement, requirements, and assisting in delivery of the firm’s non-interactive secrets platforms. This role translates complex cybersecurity needs into clear requirements, structured user stories, measurable outcomes, and actionable acceptance criteria. With deep expertise in HashiCorp Vault and broader non-human identity frameworks, including SPIFFE/SPIRE, workload identities, and service authentication patterns, this ensures our platform architecture and onboarding models are robust, secure, and scalable. The analyst drives the earliest and most critical stages of work: discovery, requirements definition, dependency mapping, and bringing clarity to ambiguous, cross-domain challenges.

The Expertise and Skills You Bring

  • Lead discovery, analysis requirements gathering.
  • Break large initiatives into well-defined epics and user stories.
  • Serve as the team’s primary analytical authority, ensuring requirements are technically sound.
  • Define functional specifications, workflows, integration requirements, and service consumption models for secrets management.
  • Partner closely with engineers across the full delivery lifecycle, providing clarity and alignment from design through deployment.
  • Drive consistent onboarding and service patterns, self-service enablement, and operational excellence.
  • Contribute to platform roadmaps, architecture discussions, control patterns, and capability evolution.

Requirements

  • Bachelor’s degree in Computer Science, Information Security, Engineering, or related field (Master’s preferred).
  • Required: 5 years’ experience in systems and technical analysis
  • Strong expertise in HashiCorp Vault and non-interactive secrets workflows (policies, auth methods, KV, Transit, dynamic secrets, integrations).
  • Advanced analytical and problem-solving skills with the ability to decompose complex, multi-domain problems into clear, actionable components.
  • Proven experience writing high-quality user stories, acceptance criteria, requirements documents, and systems/process specifications.
  • Excellent communication and facilitation skills, capable of driving alignment across engineering, product, and business stakeholders.
  • Strong understanding of cloud infrastructure and identity (AWS IAM roles/policies, Azure Managed Identities, Kubernetes workload identities, service mesh patterns).
  • Knowledge of non-human identity and workload identity technologies such as SPIFFE/SPIRE, cloud workload identities, X.509/SVID issuance, and service authentication models.

About the company

Please be advised that Fidelity’s business is governed by the provisions of the Securities Exchange Act of 1934, the Investment Advisers Act of 1940, the Investment Company Act of 1940, ERISA, numerous state laws governing securities, investment and retirement-related financial activities and the rules and regulations of numerous self-regulatory organizations, including FINRA, among others. Those laws and regulations may restrict Fidelity from hiring and/or associating with individuals with certain Criminal Histories.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on find.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:53 min

Configuring dynamic proxy updates with Istio Pilot

Jan Mensch Jan Mensch · World Congress 2026 Europe

5:24 min

Demonstrating database encryption at rest with HashiCorp Vault

Alex Soto Alex Soto · LIVE

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · World Congress 2024

7:15 min

Installing Istio programmatically with bash scripts

Thomas Südbröcker · LIVE

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

2:39 min

Generating dynamic application secrets using HashiCorp Vault engines

Alex Soto Alex Soto · LIVE

Videos

See all

Related articles

See all