> Markdown version of [/jobs/ext/500728-lead-associate-principal-security-engineering](https://www.wearedevelopers.com/jobs/ext/500728-lead-associate-principal-security-engineering). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Associate Principal, Security Engineering - **Company:** Hudson - **Location:** Chicago, IL, United States - **Experience:** Expert - **Salary:** $83,200.0 - $104,000.0 - **Contract:** Permanent contract - **Skills:** Active Directory, User Authentication, Cyber Security, Hardware Security Module, Identity and Access Management, Kerberos (Protocol), Key Management, Lightweight Directory Access Protocols (LDAP), OAuth, OpenID, Public Key Infrastructure, Cloud Platform System, Cyberark, Software Security, Kubernetes, Infrastructure Automation Frameworks, Hashicorp, Terraform, Software Version Control - **Published:** June 5, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=08e93fe8685d6827 ## About the Role Do you have experience in Terraform?, * Experience supporting Privileged Access Management (PAM) and access control programs. * Strong understanding of security architecture principles including Confidentiality, Integrity, and Availability (CIA). * Experience in Security Operations, Security Engineering, Security Development, or Security Architecture. * Hands-on experience supporting enterprise authentication and authorization systems. Technical Skills Required * CyberArk * HashiCorp Vault * Active Directory Certificate Services (ADCS) * Public Key Infrastructure (PKI) * Hardware Security Modules (HSM) ## Description We are seeking a Lead Associate Principal, Security Engineering to support and enhance enterprise Privileged Access Management (PAM), Secrets Management, and PKI platforms. This role will be responsible for operational support, platform engineering, automation, infrastructure security, and implementation of secure authentication and authorization solutions across on-premises and cloud environments., * Provide 24x7 operational support for privileged access and secrets management platforms such as CyberArk, HashiCorp Vault, and PKI solutions. * Troubleshoot production issues, implement hotfixes, perform break-fix activities, and manage secrets lifecycle processes. * Maintain platform health through patching, upgrades, version control, and compliance with security standards. * Serve as a subject matter expert for Privileged Access Management (PAM), Secrets Management, and security architecture. * Design and implement automated integrations and platform enhancements to improve user experience and operational efficiency. * Develop long-term solutions for operational challenges using automation and AI-assisted technologies. * Implement and enforce security-as-code principles across enterprise environments. * Support authentication and authorization technologies including Active Directory, OAuth 2.0, OIDC, AWS IAM, Kerberos, LDAPS, Certificates, Kubernetes, and AppRole. * Collaborate with engineering teams to integrate security controls within CI/CD pipelines and cloud platforms. * Create automation solutions using scripting and Infrastructure as Code (IaC) tools. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)