Lead HashiVault Engineer [T500-29209]

Talent500

Hyderabad

Hybrid

INR 3,000,000 - 6,000,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Competitive salary + bonus
Hybrid work
Learning budget
Multi-cloud environment
Healthcare & pension
Collaborative culture

Job summary

Talent500 partners with Zurich’s Core Insurance Platforms (CIP) to hire a Senior Secrets Management Engineer. You will own and evolve a scalable secrets platform, primarily HashiCorp Vault, across multi-cloud and hybrid environments.

You will implement zero-trust principles, RBAC, and automation pipelines with Terraform, Kubernetes, and CI/CD integrations. A hands-on specialist who mentors teams and drives security craftsmanship across platforms.

Qualifications

  • 5+ years in cybersecurity, infrastructure, or platform engineering.
  • 3+ years hands-on HashiCorp Vault experience.
  • Deep Vault architecture: clusters, auth methods, engines, policies.
  • Scripting: Python, Bash, Go.
  • IaC: Terraform, Ansible, or Pulumi.
  • Kubernetes and secrets injection patterns.
  • PKI, TLS/mTLS, certificate lifecycle management.
  • Cloud-native secrets services across AWS/Azure/GCP.
  • Zero-trust, RBAC, least-privilege access.
  • CI/CD integration and secrets hygiene.
  • Vault Associate or Professional certification.
  • Experience with CyberArk/Conjur.
  • Regulated environment exposure.
  • Service mesh with Istio/Consul Connect.
  • Open-source contributions.

Responsibilities

  • Design, deploy, and operate a highly available, scalable secrets platform.
  • Define and enforce secrets architecture, policies across multi-cloud and hybrid environments.
  • Manage Vault clusters including HA, replication, auto-unseal, DR.
  • Build Terraform/IaC modules, Helm charts, and automation pipelines.
  • Own lifecycle of secrets: creation, rotation, revocation, auditing.

Skills

Vault expertise
HashiCorp Vault
Scripting (Python/Bash/Go)
Infrastructure as Code
Kubernetes
PKI/tls management
Cloud-native secrets
Zero-trust/RBAC
CI/CD integration
Certifications (Vault)
CyberArk/Conjur
Regulated environments
Service mesh (Istio/Consul)
Open-source contributions

Tools

Terraform
Ansible
Pulumi
Kubernetes
CyberArk
Conjur
IAM

Job description

Talent500 is hiring for one of its clients.

Who are we:

Core Insurance Platforms (CIP) is Zurich’s global capability responsible for building, running, and evolving core insurance technology. We set a unified, scalable operating model—covering governance, standards, architecture, service delivery, and reuse—so our business units can deliver at speed and scale.

CIP is the strategic steward of Zurich’s Guidewire ecosystem, aligning platform roadmaps to business strategy while driving stability, modernization, reduced supplier dependency, and long term cost efficiency.

India delivery center is one of our global delivery and capability hub. We bring together experts in AI, engineering, analysis, quality, and architecture to deliver product & process solutions, application run services, change and transformation initiatives, and centralized platform services across both on prem and Guidewire Cloud environments. Our teams operate from multiple global delivery centers, supporting Zurich’s business units worldwide.

Role Overview:

We are looking for a highly skilled Senior Secrets Management Engineer to own, evolve, and secure our enterprise secrets management platform. You will be the subject matter expert for tools such as HashiCorp Vault (or equivalent), driving adoption, best practices, and engineering standards across the organisation.

This is a high-impact, hands‑on technical role at the intersection of cybersecurity, DevSecOps, and infrastructure engineering. You will work closely with platform, cloud, and application engineering teams to ensure secrets — credentials, certificates, API keys, encryption keys — are managed securely, at scale, and in line with zero-trust principles.

Key Responsibilities:
  • Design, deploy, and operate a highly available, scalable secrets management platform (e.g. HashiCorp Vault Enterprise, AWS Secrets Manager, Azure Key Vault, CyberArk).
  • Define and enforce secrets management architecture, policies, and standards across multi‑cloud and hybrid environments.
  • Manage Vault clusters including HA configuration, replication, auto‑unseal (e.g. via AWS KMS or Azure Key Vault), and disaster recovery.
  • Build and maintain Terraform/IaC modules, Helm charts, and automation pipelines for platform deployment and configuration.
  • Own the full lifecycle of secrets: creation, rotation, revocation, leasing, and auditing.
Security & Compliance:
  • Implement and maintain dynamic secrets, PKI certificate management, and database credential rotation.
  • Develop and enforce RBAC, ACL policies, and names pacing within Vault to enforce least‑privilege access.
  • Conduct regular access reviews, audit log analysis, and security assessments of the secrets platform.
  • Ensure compliance with relevant frameworks and regulations including ISO 27001, SOC 2, PCI‑DSS, and NIST guidelines.
  • Drive zero‑trust architecture principles across secrets distribution and access patterns.
DevSecOps & Integration:
  • Integrate secrets management tooling with CI/CD pipelines (e.g. GitHub Actions, Jenkins, GitLab CI) to eliminate hard‑coded credentials.
  • Build Vault Agent, sidecar injection, and Kubernetes Secrets Store CSI Driver integrations for containerised workloads.
  • Partner with application and DevOps teams to migrate away from legacy secrets handling patterns toward dynamic, short‑lived credentials.
  • Develop SDKs, libraries, and internal tooling to simplify developer adoption of secrets management APIs.
Leadership & Enablement:
  • Act as the internal SME and evangelist for secrets management — mentoring engineers and running enablement sessions.
  • Define and own the secrets management roadmap, balancing security uplift with engineering velocity.
  • Produce and maintain runbooks, architecture documentation, and operational procedures.
  • Collaborate with security architecture, risk, and compliance teams on controls and evidence for audits.
Required Skills & Experience:
  • 5+ years in a cybersecurity, infrastructure, or platform engineering role, with at least 3 years of hands‑on HashiCorp Vault (or equivalent) experience.
  • Deep expertise in Vault architecture: cluster setup, auth methods (AppRole, Kubernetes, AWS IAM, LDAP, OIDC), secret engines, policies, and audit devices.
  • Strong scripting and automation skills — Python, Bash, Go, or similar.
  • Infrastructure as Code proficiency — Terraform, Ansible, or Pulumi.
  • Experience with Kubernetes and container‑native secrets injection patterns (CSI driver, Vault Agent Injector).
  • Solid understanding of PKI, TLS/mTLS, certificate lifecycle management, and encryption key management (HSM experience a plus).
  • Familiarity with cloud‑native secrets services across AWS (Secrets Manager, KMS, Parameter Store), Azure (Key Vault), and/or GCP (Secret Manager).
  • Strong understanding of zero‑trust architecture, least‑privilege access, and RBAC.
  • Experience with CI/CD pipeline integration and secrets hygiene in software delivery.
  • HashiCorp Vault Associate or Professional certification.
  • Experience with CyberArk, Conjur, or other PAM/secrets platforms.
  • Exposure to SIEM integration and secrets‑related threat detection (e.g. detecting credential misuse via audit logs).
  • Experience in a regulated environment (financial services, healthcare, government).
  • Familiarity with service mesh and mTLS patterns (Istio, Consul Connect).
  • Open‑source contributions or public technical writing related to secrets management.
What We Offer:
  • Competitive salary and performance‑based bonus.
  • Flexible hybrid working arrangements.
  • Dedicated learning and certification budget (including HashiCorp, cloud, and security certifications).
  • Exposure to a complex, large‑scale, multi‑cloud environment.
  • Collaborative, psychologically safe team culture with a genuine security‑first mission.
  • Private healthcare, pension, and additional benefits package.

We are an equal opportunity employer and welcome applications from all backgrounds. This job description is indicative and may be subject to change in line with business needs.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Hashicorp vault engineer
Hashicorp vault engineer

Wroots Global • Hyderabad, Bengaluru

Hybrid
INR 1,200,000 - 1,800,000
Sr Software Development Engineer - Vault Cloud
Sr Software Development Engineer - Vault Cloud

HashiCorp, Inc. • Bengaluru

On-site
USD <2,000
Info Security Controls Specialist II B
Info Security Controls Specialist II B

Bank of America • Mumbai

On-site
INR 1,800,000 - 3,000,000
Info Security Controls Specialist II B
Info Security Controls Specialist II B

Bank of America • Hyderabad

On-site
INR 1,600,000 - 2,600,000
Info Security Controls Specialist II B
Info Security Controls Specialist II B

Bank of America • Bengaluru

On-site
INR 1,500,000 - 2,300,000
HashiCorp, Azure Key Vault and AWS Secret Manager
HashiCorp, Azure Key Vault and AWS Secret Manager

Photon • Bengaluru

On-site
INR 2,500,000 - 3,800,000
Site Reliability Engineering(SRE) & HashiCorp Consultant
Site Reliability Engineering(SRE) & HashiCorp Consultant

Capgemini • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Professional, Machine Identity & Secrets Engineer
Professional, Machine Identity & Secrets Engineer

Zinnov Management Consulting • Bengaluru

Hybrid
INR 1,800,000 - 3,000,000
T&T | Cyber : D&R | Manager | Security Platform Engineer| Delhi
T&T | Cyber : D&R | Manager | Security Platform Engineer| Delhi

Deloitte & Touche GmbH Wirtschaftsprüfungsgesellschaft • Delhi

On-site
INR 2,500,000 - 3,500,000
HashiCorp, Azure Key Vault and AWS Secret Manager (6-9 YRS)- BLR
HashiCorp, Azure Key Vault and AWS Secret Manager (6-9 YRS)- BLR

Photon • Bengaluru

On-site
INR 1,200,000 - 1,800,000