> Markdown version of [/jobs/ext/552349-devsecops-platform-engineer-secrets-management-cyberark-hashicorp](https://www.wearedevelopers.com/jobs/ext/552349-devsecops-platform-engineer-secrets-management-cyberark-hashicorp). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # DevSecOps Platform Engineer (Secrets Management-Cyberark/Hashicorp) - **Company:** Matlen Silver - **Location:** Chandler, AZ, United States - **Experience:** Expert - **Salary:** $176,800.0 - $185,120.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Application Frameworks, Automation of Tests, Microsoft Azure, Cloud Computing, Continuous Integration, DevOps, Disaster Recovery, Failover, Key Management, OpenID, Reliability Engineering, Ansible, Runbook, Cyberark, System Availability, Multi-Cloud, Infrastructure as Code (IaC), Git, Containerization, Kubernetes, Hashicorp, Terraform, Software Version Control, Devsecops - **Published:** June 15, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=57be5071d72c44e4 ## About the Role Do you have experience in Version control systems?, * Experience building "Vault as a Service" / PAM as a platform capabilities * Knowledge of: * Dynamic secrets / short-lived credentials * JIT access models * Token-based or OIDC-based auth patterns * Experience with: * Kubernetes / container platforms * Multi-cloud environments (AWS, Azure) * Familiarity with CyberArk automation tooling (e.g., Ansible-based approaches) ? Required Skills * 6) High Availability, Resilience, and DR * Engineer resilient, high uptime architectures for secrets platforms: * Multi-zone / multi-region deployment patterns * Disaster recovery and failover automation * Validate resilience continuously via: * Failure injection * Controlled DR drills * Recovery validation pipelines * 7) Security, Governance, and Compliance * Implement strong governance patterns: * Segregation of duties (admin vs usage) * Approval workflows and just-in-time access * Least-privilege enforcement ## Description We are seeking a Senior DevSecOps Engineer to design and automate an enterprise dual?stack secrets management ecosystem built on CyberArk (PAM) and HashiCorp Vault (machine/app secrets). This role is responsible for transforming the platforms into a fully automated, highly available, "platform-as-a-service" capability, with zero/low-touch operations for: This candidate will operate at the intersection of DevOps, SRE, and Security Engineering, building automation-first solutions that scale across multi-cloud, hybrid environments, and CI/CD ecosystems. Key Responsibilities 1) Dual-Platform Strategy Integration Own the operating model for dual vaulting platforms, clearly delineating: CyberArk ? human privileged access (PAM) Vault ? application, dynamic, and non-human secrets Support enterprise initiatives for centralized secrets management across cloud and on-prem platforms. 2) Full Automation of Day-2 Operations Eliminate manual operations by engineering: Automated patching pipelines Automated version upgrades Lifecycle workflows (certificate rotation, secret rotation, platform hardening) Build reusable frameworks for: Safe maintenance windows Automated rollback Continuous compliance validation Standardize Day-2 operational patterns, runbooks, and platform engineering playbooks. 3) Upgrade, Patching, and Release Engineering Design and implement enterprise-grade upgrade strategies, including: Rolling upgrades (HA clusters) Blue/green or parallel cluster deployments Controlled failover patterns Introduce automated validation: Pre-checks (dependency/version compatibility) Post-checks (cluster health, secret access integrity) Ensure Vault and CyberArk platforms remain aligned to: Security patch baselines Enterprise upgrade cadences 4) Infrastructure as Code Pipeline Engineering Build and maintain modular IaC for secrets platform deployment and lifecycle: CyberArk components (Vault, CPM, PSM, connectors) Vault clusters (HA raft, DR, auto-unseal) Develop CI/CD pipelines to: Build, validate, and promote platform changes Securely inject and manage secrets in pipelines (DevSecOps alignment) Integrate secrets management securely into CI/CD systems, avoiding credential sprawl. 5) Observability, Health, and Self-Healing Define operational health KPIs for both platforms, including: Vault: seal/unseal state, raft performance, resource utilization, transaction latency CyberArk: component availability, credential lifecycle success, access workflows Implement: Automated health checks and drift detection Event-driven remediation End-to-end alerting integrated into enterprise monitoring tools Primary SkillDevOps Desired Skills, * Ensure all automation aligns with: * Audit requirements * Security best practice * IaC methodology * Infrastructure as Code (IaC) CICD: Terraform, Ansible * GitOps workflows version control (Git) * API automation: REST, CLI, SDK-based orchestration * Vault platforms: HashiCorp Vault, CyberArk, cloud secret managers ## Related Videos - [Securing Secrets in the GitOps era](https://www.wearedevelopers.com/videos/546-securing-secrets-in-the-gitops-era) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Best Practices for Using GitHub Secrets](https://www.wearedevelopers.com/videos/1214-best-practices-for-using-github-secrets) - [Stop Committing Your Secrets - GIt Hooks To The Rescue!](https://www.wearedevelopers.com/videos/573-stop-committing-your-secrets-git-hooks-to-the-rescue) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The Overflow: 5 Security and Privacy Tools for Developers](https://www.wearedevelopers.com/magazine/710-the-overflow-5-security-and-privacy-tools-for-developers)