368,634open jobs
9,437companies
50,578added this week
Browse all
Salary
$106k – $238k per year (Estimated)
Location
Remote (United States)
Employment
Full-Time
Overview
Company
Impact
Profile match
True Zero Technologies is a veteran-owned cybersecurity services firm based in Fairfax, Virginia, founded in 2018. The company provides a broad range of solutions including security engineering, cyber operations, threat intelligence, penetration testing, and managed security services. It operates as a strategic partner to major technology providers and serves federal, state, and commercial clients through various government contract vehicles.

True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes. True Zero recognizes that those outcomes begin and end with our people, and that is what we have built a community of like-minded, driven, and passionate individuals and innovators who are aligned in a common goal of delivering top-tier services to our customers. Our culture and commitment have been recognized through numerous accolades, including being named one of the Best Places to Work in 2023 in two categories (“Prosperous and Thriving” ($5MM-$50MM in gross revenue) and “Mid-Atlantic Region” (DC, DE, MD, NC, VA, WV)), and again in 2025 as a Best Places to Work honoree. In addition, True Zero earned coveted spots on the Inc. 5000 list of fastest-growing companies in America in 2022, 2023, and 2025, a testament to our sustained growth driven by our people-first approach and unwavering dedication to excellence.

The Secrets Management Platform Engineer designs, implements, and operates a centralized enterprise secrets management platform that securely manages credentials, keys, certificates, tokens, and other sensitive authentication material across applications, services, cloud environments, and CI/CD workflows.

This role is responsible for onboarding thousands of applications and services into the secrets management platform; automating credential provisioning, retrieval, and rotation; integrating secrets management into DevSecOps and cloud-native workloads; enforcing least-privilege access; and maintaining compliance through auditing, monitoring, policy enforcement, and lifecycle governance.

The engineer will support AWS GovCloud and Zero Trust requirements by eliminating hard-coded credentials, implementing strong identity-based access controls, using FIPS 140-2/3 validated cryptography, and integrating with AWS KMS and approved secrets-management services.

Job Responsibilities

  • Onboard applications, services, users, and machine identities into a centralized secrets management platform such as CyberArk or HashiCorp Vault, based on the selected enterprise platform.
  • Design and implement secure processes for credential provisioning, storage, retrieval, rotation, revocation, and retirement.
  • Integrate AWS Secrets Manager and AWS Systems Manager Parameter Store with enterprise applications and cloud-native workloads.
  • Develop and enforce least-privilege Identity and Access Management policies for access to secrets, credentials, encryption keys, and privileged services.
  • Automate secrets management workflows using Python, Terraform, Ansible, and approved infrastructure-as-code technologies.
  • Integrate secrets management into CI/CD pipelines and DevSecOps workflows to eliminate manually managed or embedded credentials.
  • Design and support secrets integration for containers, Kubernetes-based workloads, cloud services, virtual machines, and application platforms.
  • Implement and maintain PKI and certificate management processes, including certificate issuance, renewal, rotation, revocation, and expiration monitoring.
  • Eliminate hard-coded credentials, static passwords, embedded API keys, and unmanaged secrets from source code, configuration files, scripts, pipelines, and application deployments.
  • Implement FIPS 140-2/3 validated cryptographic controls and integrate secrets-management solutions with AWS KMS in AWS GovCloud where required.
  • Configure authentication methods and access policies for users, applications, workloads, and machine identities.
  • Implement dynamic or short-lived credentials where supported to reduce reliance on long-lived static secrets.
  • Maintain centralized auditing, logging, monitoring, and alerting for secrets access, administrative activity, credential rotation, and policy violations.
  • Develop and enforce governance standards for secret ownership, naming, classification, access, rotation frequency, expiration, and lifecycle management.
  • Partner with application, cloud, platform, cybersecurity, and DevSecOps teams to integrate secrets-management capabilities into enterprise architectures and development workflows.
  • Troubleshoot authentication, authorization, credential rotation, certificate, API, and platform integration issues.
  • Maintain technical documentation, onboarding procedures, platform standards, operational runbooks, and governance processes.
  • Continuously improve platform availability, scalability, automation, security controls, onboarding efficiency, and operational resilience.

Job Qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related technical discipline.
  • Demonstrated experience implementing or administering an enterprise secrets management platform such as CyberArk or HashiCorp Vault.
  • Experience with AWS Secrets Manager, AWS Systems Manager Parameter Store, and AWS KMS.
  • Strong understanding of Identity and Access Management, role-based access control, policy-based access, and least-privilege principles.
  • Hands-on automation experience using Python, Terraform, and/or Ansible.
  • Experience integrating secrets-management solutions with CI/CD pipelines, DevSecOps workflows, and automated deployment processes.
  • Experience with PKI, certificate management, encryption, key management, and certificate lifecycle automation.
  • Understanding of container and cloud security, including secrets integration for Kubernetes, containerized applications, and cloud-native workloads.
  • Experience designing credential rotation, dynamic secrets, machine identity, and privileged-access workflows.
  • Familiarity with FIPS 140-2/3 validated cryptography and cryptographic requirements for government or regulated environments.
  • Experience implementing controls to identify and eliminate hard-coded credentials and unmanaged secrets.
  • Strong understanding of Zero Trust principles, particularly least privilege, identity-based access, continuous verification, and credential minimization.
  • Experience supporting AWS GovCloud, government, defense, or other regulated cloud environments is preferred.
  • Experience with centralized logging, monitoring, auditing, compliance reporting, and security-event integration.
  • Strong troubleshooting, documentation, governance, automation, and cross-functional collaboration skills.
  • Preferred Certifications:

    • AWS Certified Security - Specialty
    • AWS Certified Solutions Architect - Associate
    • HashiCorp Certified: Vault Associate or applicable CyberArk Defender/Sentry certification, based on the selected secrets-management platform
    • Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM)
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,634 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$40k – $86k per year (Estimated) • Remote/Hybrid • Full-Time • Élancourt
Bash
PowerShell
Python
SQL
Databases
MySQL
PostgreSQL
Redis
DevOps
Amazon CloudWatch
Ansible
AWS
Azure
CentOS Stream
CI/CD
Debian
Docker
GCP
GitLab
GitLab CI
Grafana
Hyper-V
IAM
Jenkins
Kubernetes
Nagios
Prometheus
Proxmox VE
Terraform
Ubuntu
VMWare
Windows Server
Zabbix
Apply
$89k – $212k per year (Estimated) • Remote/Hybrid • Full-Time • 6+ years exp • Rehovot
Bash
Python
DevOps
Amazon CloudWatch
Amazon EKS
AWS
CI/CD
Datadog
GitLab
GitLab CI
GitOps
Grafana
IAM
Kubernetes
PagerDuty
Pulumi
Terraform
Terragrunt
VictoriaMetrics
Apply
$142k – $215k per year • In office • Full-Time • 12+ years exp • Princeton
JavaScript
TypeScript
Java
Java
Gradle
Hibernate
Maven
Spring Boot
Databases
Databricks
Snowflake
AI/ML
AI Agents
Claude
Claude Code
Frontend
Angular
React.js
Vue.js
DevOps
Amazon CloudWatch
Amazon ECS
Amazon EKS
Amazon EventBridge
Amazon S3
API Gateway
AWS
AWS Lambda
AWS Step Functions
Azure
CI/CD
IAM
Platform Engineering
Rest API
Kubernetes
Apply
Data Scientist 8 hours ago
$17k – $47k per year (Estimated) • Remote/Hybrid • Full-Time • 1+ year exp • Bachelor's Degree • Pune
Python
SQL
AI/ML
MLFlow
PyTorch
RAG
Scikit-learn
TensorFlow
DevOps
AWS
Azure
GCP
Analytics
Matplotlib
Seaborn
Apply
$18k – $48k per year (Estimated) • In office • Full-Time • 7+ years exp • Mumbai
JavaScript
SQL
TypeScript
Java
Java
Spring Boot
Frontend
Angular
DevOps
AWS
Azure
Kubernetes
Rest API
Apply
$116k – $241k per year (Estimated) • Remote • Full-Time • 5+ years exp • Bachelor's Degree
Cybersecurity
Zero Trust
Apply
$136k – $244k per year (Estimated) • Remote • Full-Time • 5+ years exp • Bachelor's Degree
SQL
DevOps
AWS
Azure
Splunk
Cybersecurity
Zero Trust
Analytics
Power BI
Tableau
Apply
$134k – $240k per year (Estimated) • Remote • Full-Time • Bachelor's Degree
PowerShell
Python
DevOps
AWS
Azure
CI/CD
Cybersecurity
Zero Trust
Apply
$92k – $190k per year (Estimated) • Remote • Full-Time • 3+ years exp • Bachelor's Degree
Cybersecurity
Zero Trust
Apply
$119k – $220k per year (Estimated) • Remote • Full-Time • Bachelor's Degree
Bash
PowerShell
Python
DevOps
Amazon EKS
Ansible
AWS
AWS CDK
Azure
CI/CD
CloudFormation
Configuration Management
GitOps
Jenkins
Kubernetes
Splunk
Terraform
Windows Server
Amazon ECS
Cybersecurity
CyberArk
FedRAMP
Keycloak
LogRhythm
Okta
Prisma Cloud
Management
Confluence
Jira
Apply
See all jobs
This is one of many
368,634 more open roles from verified company boards, updated every day.