About the Role
This position is part of a team managing data protection technologies, including Hashicorp Vault. Candidates need intermediate to advanced systems engineering experience in large enterprises, extensive Linux (Red Hat preferred) experience, and production support expertise with HSMs, security appliances, or data protection technologies. The role requires technical documentation skills, excellent communication, and proficiency in scripting and automation. You will interact with encryption technology and HSM vendors, ensuring their products align with company objectives and coordinating support for issue resolution. Collaboration with internal partners across the company is also key.
Responsibilities
- Independently design, implement, and manage secure, highly available HashiCorp Vault platform with minimal oversight from lead engineers
- Contribute to end-to-end automation of Vault provisioning, configuration, and lifecycle management using Ansible and Terraform
- Develop and enforce platform standards for secrets management, authentication, authorization, and Vault best practices across the organization
- Analyze and solve complex technical challenges, including cloud native and multi-cloud integrations, Kubernetes auth setups, PKI hierarchies, replication, and performance optimization
- Collaborate directly with cross-functional teams—security, platform engineering, application teams, product owners, and vendors—to deliver architecturally sound Vault solutions
- Troubleshoot deep technical issues independently, including HA failures, unseal workflows, auth method problems, and secret engine configuration errors
- Implement advanced Vault capabilities, such as static and dynamic secrets, PKI secret engine, dynamic Database secrets, and namespace management
- Guide and support engineering teams, providing Vault expertise, technical recommendations, and onboarding assistance without requiring constant supervision
- Drive continuous improvement, identifying opportunities for automation, performance tuning, reliability enhancements, and security hardening across Vault deployments
- Provide on-call support on rotational basis per team’s schedule
Requirements
- 5+ years of Technology Infrastructure Engineering and Solutions experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education
- 3+ years of hands-on experience with HashiCorp Vault, with a proven track record in enterprise-grade Vault design, deployment, and automation
- 1+ years of Linux system administration, required for installing, configuring, securing, and troubleshooting Vault clusters
- 1+ years of the Vault lifecycle, including installation, upgrades, HA deployment, scaling, and cluster maintenance
- Practical experience with Enterprise Change Management, change control processes, and operating within procedural, compliance-driven environments
- Hands-on expertise with Terraform, Ansible, CI/CD pipelines, and GitHub, with strong understanding of modern automation pipelines for Vault provisioning and configuration
- Proven experience designing, integrating, and maintaining Vault Secret Engines, including: KV, Database, PKI, Azure, GCP, LDAP, Dynamic secret engines, and secret rotation flows
- Strong experience designing, implementing, and maintaining Vault Auth Engines, such as: LDAP, AppRole, Kubernetes, JWT/OIDC, TLS Certificate authentication
- Hands-on experience implementing Vault Auto-Unseal using HSM-based solutions
- Experience configuring and maintaining Vault audit logging, monitoring, and metrics, using tools like Splunk, Grafana, and other observability platforms.
- Hands-on expertise with Vault Agent, templates, auto-auth, and Vault Proxy integrations
- Hands on experience in using Hashicorp Vault service like (Key management system, Secret and certificate management)
- Good knowledge of DevOps and SDLC for IaC CI/CD concepts, GitHub, branching strategies
Skills
- HashiCorp Vault
- Linux
- Red Hat
- Scripting
- Automation
- Ansible
- Terraform
- Secrets Management
- Authentication
- Authorization
- Cloud Native
- Multi-cloud
- Kubernetes
- PKI
- Replication
- Performance Optimization
- HA Failures
- Unseal Workflows
- Auth Method Problems
- Secret Engine Configuration
- Static Secrets
- Dynamic Secrets
- Database Secrets
- Namespace Management
- CI/CD
- GitHub
- KV Secret Engine
- Azure
- GCP
- LDAP
- Dynamic Secret Engines
- Secret Rotation Flows
- AppRole
- JWT/OIDC
- TLS Certificate Authentication
- HSM
- Vault Audit Logging
- Monitoring
- Metrics
- Splunk
- Grafana
- Observability
- Vault Agent
- Vault Templates
- Vault Auto-Auth
- Vault Proxy
- Key Management System
- Secret Management
- Certificate Management
- DevOps
- SDLC
- IaC
- Branching Strategies
Location
- Hybrid
Work Type
- Hybrid
- On-call
Experience Level
- Intermediate to Advanced
- 5+ years of Technology Infrastructure Engineering and Solutions experience
- 3+ years of hands-on experience with HashiCorp Vault
- 1+ years of Linux system administration
- 1+ years of Vault lifecycle experience
Education Level
- Professional HashiCorp Vault Certification (HVCP or equivalent)
Salary/Compensations
- $119,000.00 - $224,000.00
Benefits
- Health benefits
- 401(k) Plan
- Paid time off
- Disability benefits
- Life insurance, critical illness insurance, and accident insurance
- Parental leave
- Critical caregiving leave
- Discounts and savings
- Commuter benefits
- Tuition reimbursement
- Scholarships for dependent children
- Adoption reimbursement
About the Company
- Wells Fargo provides eligible employees with a comprehensive set of benefits.
- Wells Fargo maintains a drug free workplace.
- Employees support our focus on building strong customer relationships balanced with a strong risk mitigating and compliance-driven culture which firmly establishes those disciplines as critical to the success of our customers and company.
- They are accountable for execution of all applicable risk programs (Credit, Market, Financial Crimes, Operational, Regulatory Compliance), which includes effectively following and adhering to applicable Wells Fargo policies and procedures, appropriately fulfilling risk and compliance obligations, timely and effective escalation and remediation of issues, and making sound risk decisions.
- There is emphasis on proactive monitoring, governance, risk identification and escalation, as well as making sound risk decisions commensurate with the business unit’s risk appetite and all risk and compliance program requirements.
Equal Opportunity
- Wells Fargo is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other legally protected characteristic.
- To request a medical accommodation during the application or interview process, visit Disability Inclusion at Wells Fargo.
- Wells Fargo requires you to directly represent your own experiences during the recruiting and hiring process.
