HashiCorp Vault SME

Tetra Tech

United States

Remote

USD 170,000 - 180,000

Full time

29 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

LS Technologies, a Tetra Tech Company, seeks a senior System Engineer specializing in HashiCorp Vault to lead enterprise secrets management across cloud, hybrid, and on‑prem environments. You will design, deploy, and sustain Vault architectures, implement dynamic credentials, and integrate with AWS, Kubernetes, OpenShift, and CI/CD pipelines.

The role requires extensive Vault experience, strong security governance, and ability to mentor teams.

Qualifications

  • Bachelor’s degree in Computer Science, Information Systems, Engineering, Cybersecurity, or related field (or equivalent).
  • 8+ years in cloud engineering, DevOps, systems/platform engineering, or related disciplines.
  • 5+ years with AWS or comparable cloud platforms.
  • Extensive hands-on Vault experience in enterprise environments.
  • Experience with Vault authentication, policies, secret engines, dynamic credentials, PKI, encryption, and audit capabilities.

Responsibilities

  • Serve as FAA's senior technical SME for HashiCorp Vault and enterprise secrets-management architecture.
  • Design, implement, configure, and administer highly available Vault environments across cloud, hybrid, and on-premises infrastructure.
  • Develop enterprise Vault architectures with centralized secrets management, dynamic credentials, encryption, PKI, and application authentication.
  • Establish Vault policies, namespaces, authentication methods, secret engines, roles, access controls, and governance standards.
  • Integrate Vault with AWS, OpenShift, Kubernetes, CI/CD pipelines, applications, databases, and enterprise services.
  • Implement dynamic secrets and short-lived credentials to reduce static credential reliance and improve security.
  • Develop and maintain Vault PKI capabilities for automated certificate issuance, rotation, and revocation.
  • Build automated secret rotation and lifecycle-management processes.
  • Develop Vault backup, recovery, DR, and HA strategies.
  • Establish monitoring, logging, auditing, and operational procedures for Vault.

Skills

Cloud engineering
Security architecture
CI/CD
DevSecOps
Leadership

Education

Bachelor's degree in CS/Engineering/IT

Tools

HashiCorp Vault
AWS
Kubernetes
OpenShift
Terraform
Ansible
CloudFormation

Job description

Job Description

The Federal Aviation Administration (FAA) is seeking a highly skilled System Engineer to serve as a senior technical HashiCorp Vault SME responsible for the design, implementation, automation, security, and sustainment of enterprise cloud infrastructure and DevSecOps capabilities. The engineer serves as the technical subject matter expert for HashiCorp Vault, providing leadership in enterprise secrets management, privileged credential management, encryption, certificate management, and secure application integration across cloud and hybrid environments.


Salary is based on relative years of experience:

$170,000 - $180,000


Job Duties & Responsibilities

Essential Job Functions may include (but are not limited to) the following:


The following duties are considered essential to the role. Reasonable accommodations may be made to enable individuals with disabilities to perform these essential functions



  • Serve as the FAA's senior technical subject matter expert for HashiCorp Vault and enterprise secrets-management architecture.

  • Design, implement, configure, and administer highly available Vault environments across cloud, hybrid, and on-premises infrastructure.

  • Develop enterprise Vault architectures supporting centralized secrets management, dynamic credentials, encryption, PKI, certificates, and application authentication.

  • Establish Vault policies, namespaces, authentication methods, secret engines, roles, access controls, and governance standards.

  • Integrate Vault with AWS, Red Hat OpenShift, Kubernetes, CI/CD pipelines, applications, databases, and enterprise services.

  • Implement dynamic secrets and short-lived credentials to reduce reliance on static credentials and improve security posture.

  • Configure and manage Vault authentication methods including Kubernetes, AWS IAM, AppRole, LDAP, OIDC, and other enterprise authentication mechanisms.

  • Develop and maintain Vault PKI capabilities for automated certificate issuance, rotation, and revocation.

  • Implement encryption-as-a-service capabilities using Vault Transit to protect sensitive FAA application data.


Design automated secret rotation and lifecycle-management processes.



  • Develop Vault backup, recovery, disaster-recovery, and high-availability strategies.

  • Establish monitoring, logging, auditing, and operational procedures for Vault environments.

  • Troubleshoot complex Vault availability, authentication, authorization, integration, and performance issues.

  • Develop enterprise standards, reference architectures, implementation guides, and operational runbooks for Vault.

  • Mentor cloud engineers and development teams on secure Vault implementation and secrets-management best practices.

  • Design, build, automate, and maintain secure AWS cloud infrastructure supporting FAA mission and enterprise applications.

  • Develop and maintain Infrastructure as Code using Terraform, Ansible, CloudFormation, or equivalent technologies.


Build automated cloud environments using repeatable, version-controlled, policy-driven deployment processes.


Required Qualifications

A successful candidate will have



  • Bachelor's degree in Computer Science, Information Systems, Engineering, Cybersecurity, or a related technical discipline, or equivalent experience. (Master’s degree preferred).

  • 8+ years of experience in cloud engineering, DevOps, systems engineering, platform engineering, or related technical disciplines.

  • 5+ years of experience with AWS or comparable enterprise cloud platforms.

  • Extensive hands‑on experience with HashiCorp Vault in enterprise environments.

  • Demonstrated experience designing and implementing Vault authentication, policies, secret engines, dynamic credentials, PKI, encryption, and audit capabilities.

  • Strong experience with Kubernetes and/or Red Hat OpenShift.

  • Strong understanding of CI/CD and DevSecOps principles.

  • Experience integrating secrets management into automated application and infrastructure deployment pipelines.

  • Strong understanding of cloud security, IAM, encryption, certificates, networking, and zero‑trust principles.


Experience working in regulated, highly secure, or federal environments.


Education


  • Bachelor’s degree in Information Technology, Computer Science, Engineering, or related field (or equivalent experience).


Work Requirements and Additional Information


  • Work Location: Remote

  • Position is: Remote

  • Work Hours: 40

  • Travel: 0%

  • Background check: Must have the ability to obtain and maintain a public trust clearance, which requires U.S. citizenship.


Physical Requirements

Extended Computer Use: Regular and prolonged periods of working at a computer terminal.



  • Mobility: Ability to move around the office environment to access computer hardware, networking equipment, and server rooms.

  • Dexterity: Manual dexterity and visual acuity to operate computer equipment, troubleshoot issues, and perform tasks requiring precision.

  • Sitting/Standing: Both prolonged sitting and occasional standing may be required for troubleshooting and attending to system issues.


Primarily computer-based work; meetings or collaboration may be required.


About LS Technologies

At LS Technologies, a Tetra Tech Company, we're enhancing our nation’s critical infrastructure by providing engineering, technical, and professional services to Federal Government agencies. The quality of our work, deep technical expertise, and genuine passion for public service sets us apart. As a growing organization we are expanding our benefits and communication with our employees, offering add-ons that speak to our growing employees’ needs. Join us in delivering high-quality solutions and shaping the future of safety and innovation for our government partners. In 2024 we joined Tetra Tech, enabling us to combine our expertise with the reach and resources of a prestigious global organization.


EEO Commitment

LS Technologies, a Tetra Tech Company, is proud to be an Equal Opportunity Employer. All qualified candidates will be considered without regard to race, color, religion, national origin, age, disability, sex, marital or familial status, status as a protected veteran, or any other characteristic protected by law. Tetra Tech is a VEVRAA federal contractor, and we request priority referral of veterans.We invite applications from all interested parties.


Requesting an Accommodation

LS Technologies is committed to providing equal employment opportunities for persons with disabilities or religious observances, including reasonable accommodation when needed. If you are hired by LS Technologies and require accommodation to perform the essential functions of your role, you will be asked to participate in our reasonable accommodation process. Accommodations made to facilitate the recruiting process are not a guarantee of future or continued accommodations once hired.


If you would like to be considered for employment opportunities with LS Technologies and have accommodation needs for a disability or religious observance, please send us an email hr@lstechllc.com or speak with your recruiter.


Compensation (Pay Bands)

Salary at LST is determined by a wide array of factors, such as (but not limited to) education, certifications, knowledge, skills, competencies, and experience, location, and clearance level, as well as contract-specific affordability and organizational requirements and applicable employment laws. Please note that the salary information is a general guideline only.


The projected compensation range for this position is provided within the posting and is based on full-time, 40 hour/week status. Part-time staff receive compensation at an hourly rate. The estimated minimum and maximum displayed represents the broadest range for this position (inclusive of high geographic and high clearance requirements) and is just one component of LSTs total compensation package for employees. ** In compliance with local laws, LS Technologies presents this reasonable compensation range as a guideline for roles in California, Colorado, New York, or Washington D.C.


Benefits offered to all employees who work 30+ hours per week: Medical, Dental, Vision, Life Insurance, Short-Term Disability, Long-Term Disability, 401(k) match, Flexible Spending Accounts, EAP, Education Assistance, Parental Leave, Annual Leave, and Holidays.



  • The perks of working at Tetra Tech include:

  • Comprehensive and market‑competitive benefits.

  • Merit‑based financial rewards.

  • Flexibility and company‑wide commitment to work/life balance.

  • Collaborative team atmosphere that values the contributions of all employees.

  • Learning and development opportunities for ongoing professional growth.


About Tetra Tech:

Tetra Tech is the leader in water, environment, and sustainable infrastructure, providing high-end consulting and engineering services for projects worldwide. With 30,000 employees working together, Tetra Tech provides clear solutions to complex problems by Leading with Science to address the entire water cycle, protect and restore the environment, design sustainable and resilient infrastructure, and support the clean energy transition.


Follow us on social media to learn more about our people, culture, and opportunities: LinkedIn: TetraTechCareers; X (Twitter): @TetraTechJobs

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

DevOps Engineer (IDP/Keycloak SME)
DevOps Engineer (IDP/Keycloak SME)

Tetra Tech • United States

Remote
USD 130,000 - 150,000
FAA Systems Engineers
FAA Systems Engineers

230 LST • Atlantic City (NJ)

On-site
USD 100,000 - 120,000
Full Stack Developer - Federal Aviation Administration
Full Stack Developer - Federal Aviation Administration

Tetra Tech • Atlantic City (NJ)

On-site
USD 100,000 - 110,000
Competitive benefits
Merit-based rewards
Work-life balance
+2
Junior Data Scientist
Junior Data Scientist

230 LST • Warrenton (VA)

Hybrid
USD 60,000 - 70,000
Medical Insurance
Dental Insurance
Vision Insurance
+4
Senior Red Hat Linux Engineer
Senior Red Hat Linux Engineer

Tetra Tech • Atlantic City (NJ)

On-site
USD 120,000 - 150,000
Cloud Security Engineer
Cloud Security Engineer

Tetra Tech • Town of Egg Harbor (WI)

On-site
USD 140,000 - 190,000
Cloud Security Tech Support
Cloud Security Tech Support

Tetra Tech • Washington

On-site
USD 80,000 - 120,000
Comprehensive benefits
Merit-based financial rewards
Learning and development opportunities
+1
Electrical Engineer (Communication Systems)
Electrical Engineer (Communication Systems)

230 LST • Atlantic City (NJ)

On-site
USD 90,000 - 120,000
Medical benefits
Dental benefits
Vision benefits
+2
Red Hat OpenShift Subject Matter Expert
Red Hat OpenShift Subject Matter Expert

Tetra Tech • United States

Remote
USD 170,000 - 180,000
Junior Data Scientist
Junior Data Scientist

Tetra Tech • Warrenton (VA)

On-site
USD 60,000 - 70,000
Benefits package
Merit-based rewards
Work/life balance
+2