Preference will be given to candidates residing in the Eastern or Central time zones.
As a Non-Human Identity (NHI) Manager, you will lead the enterprise program that secures machine and workload identities across cloud, on-premises, and CI/CD environments. You will guide the full identity lifecycle and partner with Platform Engineering, Cloud, DevOps, Security Operations and Application teams to reduce risk from hard-coded and unmanaged credentials.
What you will do:
- Own the enterprise non-human identity security strategy, roadmap, operating model, governance, and reporting.
- Establish identity and access controls for API credentials and emerging AI agent identities.
- Support SOX, HIPAA, ISO 27001, and NIST CSF compliance and audit requirements through non-human identity risk reporting.
Technical Responsibilities:
- Establish and operate discovery and inventory processes for service accounts, secrets, certificates, keys, and workload identities across the enterprise.
- Deploy and operate secrets management and machine identity platforms, including HashiCorp Vault, CyberArk Conjur, Azure Key Vault, or Venafi.
- Manage PKI and govern certificate issuance, renewal, rotation, revocation, and decommissioning to prevent outages caused by expired certificates.
- Automate secret rotation and eliminate hard-coded or embedded credentials in code and pipelines.
- Secure managed identities, IAM roles, service principals, and other cloud workload identities using least-privilege access and short-lived credentials.
- Integrate non-human identity controls into CI/CD pipelines, DevOps workflows, cloud platforms and infrastructure-as-code practices.
Leadership & People Management Responsibilities:
- Lead analysts and engineers by setting standards, priorities, performance expectations, and accountability for program delivery.
- Drive cross-functional adoption of service account onboarding, ownership, attestation, and decommissioning practices.
Knowledge and Capabilities:
- Assess identity risk, analyze complex security issues, and translate findings into practical controls and remediation priorities.
- Communicate non-human identity risks, decisions, and program requirements to technical teams, business partners, and audit stakeholders.
- Apply Zero Trust and least-privilege principles across machine, workload, cloud, API, and AI agent identities.
What You Need:
Required Qualifications:
- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or a related discipline.
- Minimum 8 years of experience in identity, cloud, or cybersecurity, including a minimum 3 years of experience focused on machine or non-human identity security.
- Hands-on experience with HashiCorp Vault, CyberArk Conjur, Azure Key Vault, Venafi, or comparable secrets management and machine identity platforms.
- Experience with PKI, certificate lifecycle management, and automated credential rotation.
- Experience securing cloud workload identities and service principals in Azure, AWS, or GCP.
- Experience with CI/CD, DevOps, infrastructure-as-code security, people leadership, Zero Trust, and least-privilege controls.
Preferred Qualifications:
- Master's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or a related discipline.
- CISSP, HashiCorp Vault, Venafi, or relevant cloud security certification.
United States of America Pay Ranges:
- USN: $135,600 - $225,900 USD Annual
- US5: $142,400 - $237,200 USD Annual
- US10: $149,200 - $248,500 USD Annual
- US15: $155,900 - $259,800 USD Annual
- US20: $162,700 - $271,100 USD Annual
- US30: $176,300 - $293,700 USD Annual