Demo

DevSecOps Platform Engineer (Secrets Management-Cyberark/Hashicorp)

Matlen Silver
Chandler, AZ Full Time
POSTED ON 6/21/2026
AVAILABLE BEFORE 7/21/2026
We are seeking a Senior DevSecOps Engineer to design and automate an enterprise dual?stack secrets management ecosystem built on CyberArk (PAM) and HashiCorp Vault (machine/app secrets).
This role is responsible for transforming the platforms into a fully automated, highly available, platform-as-a-service" capability, with zero/low-touch operations for:
This candidate will operate at the intersection of DevOps, SRE, and Security Engineering, building automation-first solutions that scale across multi-cloud, hybrid environments, and CI/CD ecosystems.
Key Responsibilities
1) Dual-Platform Strategy Integration
Own the operating model for dual vaulting platforms, clearly delineating:
CyberArk ? human privileged access (PAM)
Vault ? application, dynamic, and non-human secrets
Support enterprise initiatives for centralized secrets management across cloud and on-prem platforms.

2) Full Automation of Day-2 Operations
Eliminate manual operations by engineering:
Automated patching pipelines
Automated version upgrades
Lifecycle workflows (certificate rotation, secret rotation, platform hardening)
Build reusable frameworks for:
Safe maintenance windows
Automated rollback
Continuous compliance validation
Standardize Day-2 operational patterns, runbooks, and platform engineering playbooks.

3) Upgrade, Patching, and Release Engineering
Design and implement enterprise-grade upgrade strategies, including:
Rolling upgrades (HA clusters)
Blue/green or parallel cluster deployments
Controlled failover patterns
Introduce automated validation:
Pre-checks (dependency/version compatibility)
Post-checks (cluster health, secret access integrity)
Ensure Vault and CyberArk platforms remain aligned to:
Security patch baselines
Enterprise upgrade cadences

4) Infrastructure as Code Pipeline Engineering
Build and maintain modular IaC for secrets platform deployment and lifecycle:
CyberArk components (Vault, CPM, PSM, connectors)
Vault clusters (HA raft, DR, auto-unseal)
Develop CI/CD pipelines to:
Build, validate, and promote platform changes
Securely inject and manage secrets in pipelines (DevSecOps alignment)
Integrate secrets management securely into CI/CD systems, avoiding credential sprawl.

5) Observability, Health, and Self-Healing
Define operational health KPIs for both platforms, including:
Vault: seal/unseal state, raft performance, resource utilization, transaction latency
CyberArk: component availability, credential lifecycle success, access workflows
Implement:
Automated health checks and drift detection
Event-driven remediation
End-to-end alerting integrated into enterprise monitoring tools
Primary SkillDevOps
Desired Skills
  • Experience building Vault as a Service" / PAM as a platform capabilities
  • Knowledge of:
  • Dynamic secrets / short-lived credentials
  • JIT access models
  • Token-based or OIDC-based auth patterns
  • Experience with:
  • Kubernetes / container platforms
  • Multi-cloud environments (AWS, Azure)
  • Familiarity with CyberArk automation tooling (e.g., Ansible-based approaches) ?
Required Skills
  • 6) High Availability, Resilience, and DR
  • Engineer resilient, high uptime architectures for secrets platforms:
  • Multi-zone / multi-region deployment patterns
  • Disaster recovery and failover automation
  • Validate resilience continuously via:
  • Failure injection
  • Controlled DR drills
  • Recovery validation pipelines
  • 7) Security, Governance, and Compliance
  • Implement strong governance patterns:
  • Segregation of duties (admin vs usage)
  • Approval workflows and just-in-time access
  • Least-privilege enforcement
  • Ensure all automation aligns with:
  • Audit requirements
  • Security best practice
  • IaC methodology
  • Infrastructure as Code (IaC) CICD: Terraform, Ansible GitOps workflows version control (Git) API automation: REST, CLI, SDK-based orchestration Vault platforms: HashiCorp Vault, CyberArk, cloud secret managers

Salary : $85

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a DevSecOps Platform Engineer (Secrets Management-Cyberark/Hashicorp)?

Sign up to receive alerts about other jobs on the DevSecOps Platform Engineer (Secrets Management-Cyberark/Hashicorp) career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$117,024 - $149,811
Income Estimation: 
$137,568 - $176,908
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Matlen Silver

  • Matlen Silver Chandler, AZ
  • Job description Senior DevOps Engineer supporting quality engineering function and responsible for cloud infrastructure as code (IaC) development covering ... more
  • Just Posted

  • Matlen Silver Chandler, AZ
  • Senior Database Security Engineer focusing on database activity monitoring solution automation for cloud-based databases (AWS, AZURE) 10 years of experienc... more
  • Just Posted

  • Matlen Silver Chandler, AZ
  • SO5 - Public Cloud - Azure Sub-effort 68: The requested Azure SRE role will ensure reliability and operational excellence for Azure platform services deliv... more
  • Just Posted

  • Matlen Silver Chandler, AZ
  • Local candidates required. No C2c or w2 referrals please. Responsibilities include: Develop log scrapring strategies to limit cpu, memory usage and staging... more
  • Just Posted


Not the job you're looking for? Here are some other DevSecOps Platform Engineer (Secrets Management-Cyberark/Hashicorp) jobs in the Chandler, AZ area that may be a better fit.

  • DataAnnotation Arizona, AZ
  • We are looking for a Web Platform Engineer to join our team to train AI models. You will measure the progress of these AI chatbots, evaluate their logic, a... more
  • 13 Days Ago

  • TEKsystems Chandler, AZ
  • Chandler, AZ Hybrid (3 Days in 2 Days remote) 12-18 Month Contract Must work on W2* We are seeking a High‑level Platform Engineer to design, engineer, depl... more
  • 15 Days Ago

AI Assistant is available now!

Feel free to start your new journey!