> Markdown version of [/jobs/ext/578969-devsecops-platform-engineer](https://www.wearedevelopers.com/jobs/ext/578969-devsecops-platform-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # DevSecOps Platform Engineer - **Company:** Matlen Silver - **Location:** Chandler, AZ, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Application Frameworks, Automation of Tests, Microsoft Azure, Cloud Computing, Continuous Integration, DevOps, Disaster Recovery, Failover, OpenID, Reliability Engineering, Ansible, Runbook, Cyberark, System Availability, Multi-Cloud, Infrastructure as Code (IaC), Git, Containerization, Kubernetes, Hashicorp, Terraform, Software Version Control, Devsecops - **Published:** June 18, 2026 - **Apply:** https://www.dice.com/job-detail/97501b18-0b4b-4ecf-9423-80891c858f39 ## About the Role * 6) High Availability, Resilience, and DR * Engineer resilient, high uptime architectures for secrets platforms: * Multi-zone / multi-region deployment patterns * Disaster recovery and failover automation * Validate resilience continuously via: * Failure injection * Controlled DR drills * Recovery validation pipelines * 7) Security, Governance, and Compliance * Implement strong governance patterns: * Segregation of duties (admin vs usage) * Approval workflows and just-in-time access * Least-privilege enforcement ## Description We are seeking a Senior DevSecOps Engineer to design and automate an enterprise dual?stack secrets management ecosystem built on CyberArk (PAM) and HashiCorp Vault (machine/app secrets). This role is responsible for transforming the platforms into a fully automated, highly available, platform-as-a-service" capability, with zero/low-touch operations for: This candidate will operate at the intersection of DevOps, SRE, and Security Engineering, building automation-first solutions that scale across multi-cloud, hybrid environments, and CI/CD ecosystems., 1) Dual-Platform Strategy Integration Own the operating model for dual vaulting platforms, clearly delineating: CyberArk ? human privileged access (PAM) Vault ? application, dynamic, and non-human secrets Support enterprise initiatives for centralized secrets management across cloud and on-prem platforms. 2) Full Automation of Day-2 Operations Eliminate manual operations by engineering: Automated patching pipelines Automated version upgrades Lifecycle workflows (certificate rotation, secret rotation, platform hardening) Build reusable frameworks for: Safe maintenance windows Automated rollback Continuous compliance validation Standardize Day-2 operational patterns, runbooks, and platform engineering playbooks. 3) Upgrade, Patching, and Release Engineering Design and implement enterprise-grade upgrade strategies, including: Rolling upgrades (HA clusters) Blue/green or parallel cluster deployments Controlled failover patterns Introduce automated validation: Pre-checks (dependency/version compatibility) Post-checks (cluster health, secret access integrity) Ensure Vault and CyberArk platforms remain aligned to: Security patch baselines Enterprise upgrade cadences 4) Infrastructure as Code Pipeline Engineering Build and maintain modular IaC for secrets platform deployment and lifecycle: CyberArk components (Vault, CPM, PSM, connectors) Vault clusters (HA raft, DR, auto-unseal) Develop CI/CD pipelines to: Build, validate, and promote platform changes Securely inject and manage secrets in pipelines (DevSecOps alignment) Integrate secrets management securely into CI/CD systems, avoiding credential sprawl. 5) Observability, Health, and Self-Healing Define operational health KPIs for both platforms, including: Vault: seal/unseal state, raft performance, resource utilization, transaction latency CyberArk: component availability, credential lifecycle success, access workflows Implement: Automated health checks and drift detection Event-driven remediation End-to-end alerting integrated into enterprise monitoring tools Primary SkillDevOps Desired Skills * Experience building Vault as a Service" / PAM as a platform capabilities * Knowledge of: * Dynamic secrets / short-lived credentials * JIT access models * Token-based or OIDC-based auth patterns * Experience with: * Kubernetes / container platforms * Multi-cloud environments (AWS, Azure) * Familiarity with CyberArk automation tooling (e.g., Ansible-based approaches) ?, * Ensure all automation aligns with: * Audit requirements * Security best practice * IaC methodology * Infrastructure as Code (IaC) CICD: Terraform, Ansible GitOps workflows version control (Git) API automation: REST, CLI, SDK-based orchestration Vault platforms: HashiCorp Vault, CyberArk, cloud secret managers ## Related Videos - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Best Software Developer Blogs to Read](https://www.wearedevelopers.com/magazine/156-the-best-software-developer-blogs-to-read)