Junior IAM Security Engineer
RemoteNorth Holland, NetherlandsentryFull-time
- Posted
- today
- Source
- LinkedIn (remote, Europe)
- Field
- Engineering, Security
Skills
OnboardingTerraformSecurityAnsiblePythonDevOpsSwiftLinuxJiraGitGo
Description
Description:
Seeking an IAM Security Engineer with strong expertise in securing and managing enterprise environments.
The ideal candidate will have hands-on experience with HashiCorp Vault, Terraform, RHEL, and Ansible, and will be expected to maintain, support and enhance the on-premises Swift Secrets Management Service (SSMS) that is based upon HashiCorp Vault Enterprise Edition (Vault), tools, processes, and technologies including but not limited to:
- Develop, test and perform OS and software upgrades, prepare for and perform business continuity activities and address vulnerabilities for our HashiCorp Vault Enterprise infrastructures.
- Interact with the vendor and Swift internal teams to ensure availability of, maintenance, enhancements to, and integration with all the Swift ecosystems (MS-AD, monitoring, backup, SIEM, …) of SSMS/Vault infrastructure.
- Investigate and resolve issues that impact or could potentially impact the availability of SSMS and its Vault infrastructure.
- Troubleshoot and monitor performance and security of HashiCorp Vault.
- Assist application team(s) with onboarding digital secrets to the Secret Management, including reviewing the environment for authentication methods, secrets engines to onboard secrets, assisting in developing compliance reporting, policy review/enforcement, and end-to-end lifecycle management activities.
- Work with the team to expand services and visibility by continuing to review the offering, speaking with stakeholders and assisting new application teams to adopt and automate.
- Develop and maintain automation workflows using Ansible.
- Develop and maintain Terraform modules for secure infrastructure provisioning.
- Enhance and provide regular reporting and accountability on key metrics and agreed-upon deliverables and ensure that the team is performing according to them.
- Maintain a customer guide that can be reused by the application team(s) for future onboarding actions.
- Maintain a runbook for the Secret Management service infrastructure and work with the administrators to maintain and enhance the administrators' guide.
- On-call on a rotational basis.
- On-site presence for at least 2 days a week (hybrid mode).
Skills and Required Experience:
- Ansible experience (developing roles, playbooks, AWX or Ansible Tower): 2 years.
- Experience with DevOps and DevOps tooling (Jira, Git, Jenkins, etc.): 3 years.
- Experience with Python and scripting: 2 years.
- Experience with Python and scripting: 3 years.
- Go development (especially for Vault plugin): 1 year.
- HashiCorp Vault (Open Source) management (deployment/upgrade in HA, troubleshooting, monitoring, hardening, integrations): 3 years.
- HashiCorp Vault Enterprise management (deployment/upgrade in HA, troubleshooting, monitoring, hardening, integrations): 1 year.
- Red Hat Linux 7 and 8 system administration (troubleshooting, monitoring, hardening): 3 years.
- Red Hat Linux 9 system administration (troubleshooting, monitoring, hardening): 1 year.
- SELinux (policy development and troubleshooting): 2 years.
- Terraform hands-on experience (module development): 2 years.
JobMatch aggregates public listings. Always apply through the original posting.