Overview
Company
Profile match
Impact
Conditions
Benefits
Hiring process
Similar jobs
State Street is a major American financial services and bank holding company headquartered in Boston, Massachusetts. As one of the world's largest custodian banks and asset managers, it provides comprehensive asset servicing, fund administration, foreign exchange, and investment management through its State Street Global Advisors division.

Role Summary

Senior-level HashiCorp Vault Engineer responsible for advanced administration, platform engineering, and reliability of enterprise secrets management solutions. The role focuses on ensuring secure secrets lifecycle management, platform scalability, automation, and alignment with Zero Trust and DevSecOps practices.

Key Responsibilities

  • Manage and support HashiCorp Vault clusters (HA setups with integrated storage or external backends).
  • Ensure high availability, performance tuning, and optimal configuration of Vault environments.
  • Perform advanced troubleshooting for Vault-related issues (auth failures, secret access issues, token lifecycle, performance bottlenecks).
  • Monitor platform health, audit logs, and telemetry.
  • Design and manage secrets engines (KV, Database, PKI, Transit, Cloud secrets).
  • Configure and manage authentication methods (LDAP, AD, Kubernetes, AppRole, OIDC).
  • Implement fine-grained policies and access controls (ACLs).
  • Manage token lifecycle, leases, and secret rotation.
  • Integrate Vault with enterprise platforms:
  • Kubernetes / OpenShift
  • CI/CD pipelines (Jenkins, GitHub Actions, Azure DevOps)
  • Cloud environments (Azure, AWS, GCP)
  • Automate secret injection, dynamic secrets provisioning, and credential rotation.
  • Develop scripts using APIs, CLI, Terraform, or Ansible for onboarding and lifecycle automation.
  • Enforce secure secrets management practices aligned with Zero Trust and least privilege models.
  • Manage encryption-as-a-service using Vault transit engine.
  • Enable audit logging and support forensic investigations.
  • Support compliance requirements (audit evidence, access tracking, policy validation).
  • Perform upgrades, patching, and version management for Vault clusters.
  • Design and maintain Disaster Recovery (DR) and replication (performance, DR clusters).
  • Conduct failover testing and resilience validation.
  • Handle certificate management and TLS configurations.
  • Lead L3-level incident resolution and root cause analysis for Vault issues, SOP standardization.
  • Provide escalation support for L1/L2 team.
  • Identify systemic issues and drive long-term fixes and platform improvements.
  • Develop operational dashboards, usage metrics, and risk insights.
  • Provide executive summaries on platform health, risk posture, and adoption maturity.
  • Collaborate with application teams, DevOps, and security architecture teams.
  • Provide design validation and optimization, Automation, integration, and scaling
  • Provide Audit &Governance support and security alignment

Required Skills & Experience

Core Technical Skills

  • 10+ years of IAM experience; 3-5+ years in HashiCorp Vault operations/engineering.
  • Bachelor’s/Master’s degree in Computer Science, Information Security, or related field
  • Strong expertise in:
    • Vault architecture (HA, clustering, storage backends)
    • Secrets engines & authentication methods
    • Policy (ACL) design and secure access frameworks
  • Hands-on experience with:
    • Linux system administration
    • Networking concepts (TLS, certificates, load balancers)
  • Experience integrating Vault with:
    • Kubernetes (sidecar injection, CSI driver)
    • CI/CD pipelines
    • Cloud IAM (AWS IAM roles, Azure AD, etc.)
  • Strong experience with:
    • Terraform (Vault provider)
    • REST APIs / scripting (Python, Shell)
  • Strong understanding of:
    • Secrets management frameworks
    • Encryption, key management, and PKI
    • Zero Trust, least privilege, and identity-based access
  • Experience with audit logging, compliance controls, and risk remediation.

Soft Skills

  • Strong analytical and troubleshooting capability (L3 depth)
  • Ability to lead incident response and mentor L1/L2 teams
  • Clear communication with technical and executive stakeholders
  • Proactive ownership and continuous improvement mindset
  • Strong problem-solving and troubleshooting mindset
  • Ability to work in a 24x7 operational support model
  • Detail-oriented with focus on risk and compliance

Additional Skills (Preferred)

  • Experience with:
    • HSM integration (for auto-unseal)
    • Service mesh integrations
    • Hybrid / multi-cloud environments
  • Exposure to other PAM tools (CyberArk, BeyondTrust) is an advantage.

About State Street

Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.

We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.

As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.

Discover more information on jobs at StateStreet.com/careers

Read our CEO Statement

Recommended for you based on this role

Similar stack
Same company
In your city
Full-Time • 3+ year exp • Bachelor's Degree • Bengaluru
Java
SQL
DevOps
CI/CD
Git
Jenkins
QA
Cucumber
Rest-Assured
Selenium
TestNG
Apply
Full-Time • 5+ year exp • Bachelor's Degree • Bengaluru
Cybersecurity
Defense in Depth
Apply
Full-Time • 6+ year exp • Hyderabad
PowerShell
Python
Databases
Apache Kafka
AI/ML
AI Agents
DevOps
Ansible
AWS
Azure
CI/CD
Dynatrace
Platform Engineering
Rest API
Splunk
Cybersecurity
CyberArk
Management
Confluence
Jira
Apply
Full-Time • 6+ year exp • Master's Degree • Bengaluru
Java
Java
Gradle
Maven
Mobile
JUnit
DevOps
Bitbucket
CI/CD
Jenkins
QA
Appium
JMeter
Selenium
TestNG
Apply
Remote/Hybrid • Full-Time • 14+ year exp • Bachelor's Degree
AI/ML
AWS Bedrock
DevOps
AWS
Azure
CI/CD
GCP
Kubernetes
Cybersecurity
Zero Trust
Apply
Threat Modeler, AVP 11 hours ago
Remote/Hybrid • Full-Time • 12+ year exp • Bachelor's Degree
DevOps
AWS
Azure
CI/CD
GCP
Kubernetes
Cybersecurity
MITRE ATT&CK
OWASP Top 10
STRIDE
Apply
Full-Time • Bachelor's Degree
Java
Node JS
Python
C#
JavaScript
Java
Maven
C#
.NET
DevOps
Ansible
AWS
Azure
CI/CD
JFrog Artifactory
Kubernetes
Terraform
Cybersecurity
SLSA
Apply
Full-Time • 8+ year exp
Apply
Full-Time • 15+ year exp • Master's Degree
SQL
Apply
$120k – $203k per year • Full-Time • 10+ year exp • Bachelor's Degree
Cybersecurity
ISO 27001
Apply
Career impact
Discover how this job can transform your career
Get a personal career forecast for this job - salary uplift, next-level role, skill boost and a 3-year financial impact, all calculated from your profile.
Personal salary uplift vs. your current pay
Your 3-year career trajectory
Skills you will level up in this role
3-year financial impact in dollars
Create free account
Free forever • Less than a minute • No credit card

Work setup

Location
Bengaluru
Employment
Full-Time

Compensation

Benefits
Flexible schedule