Lead HashiVault Engineer-29209] (Hyderabad)

Lead HashiVault Engineer-29209] (Hyderabad)

08 Sep
|
Talent500
|
Hyderabad

08 Sep

Talent500

Hyderabad

Talent500 is hiring for one of its clients.

Who are we:

Core Insurance Platforms (CIP) is Zurich’s global capability responsible for building, running, and evolving core insurance technology. We set a unified, scalable operating model—covering governance, standards, architecture, service delivery, and reuse—so our business units can deliver at speed and scale.

CIP is the strategic steward of Zurich’s Guidewire ecosystem, aligning platform roadmaps to business strategy while driving stability, modernization, reduced supplier dependency, and long term cost efficiency.

India delivery center is one of our global delivery and capability hub. We bring together experts in AI, engineering, analysis, quality, and architecture to deliver product & process solutions, application run services, change and transformation initiatives, and centralized platform services across both on prem and Guidewire Cloud environments. Our teams operate from multiple global delivery centers, supporting Zurich’s business units worldwide.

Role Overview:

We are looking for a highly skilled Senior Secrets Management Engineer to own, evolve, and secure our enterprise secrets management platform. You will be the subject matter expert for tools such as HashiCorp Vault (or equivalent), driving adoption, best practices, and engineering standards across the organisation.

This is a high-impact, hands-on technical role at the intersection of cybersecurity, DevSecOps, and infrastructure engineering. You will work closely with platform, cloud, and application engineering teams to ensure secrets — credentials, certificates, API keys, encryption keys — are managed securely, at scale, and in line with zero-trust principles.

Key Responsibilities:

Platform Ownership & Engineering:

- Design, deploy, and operate a highly available, scalable secrets management platform (e.g. HashiCorp Vault Enterprise, AWS Secrets Manager, Azure Key Vault, CyberArk).
- Define and enforce secrets management architecture, policies, and standards across multi-cloud and hybrid environments.
- Manage Vault clusters including HA configuration, replication, auto-unseal (e.g. via AWS KMS or Azure Key Vault), and disaster recovery.




- Build and maintain Terraform/IaC modules, Helm charts, and automation pipelines for platform deployment and configuration.
- Own the full lifecycle of secrets: creation, rotation, revocation, leasing, and auditing.

Security & Compliance:

- Implement and maintain dynamic secrets, PKI certificate management, and database credential rotation.
- Develop and enforce RBAC, ACL policies, and names pacing within Vault to enforce least-privilege access.
- Conduct regular access reviews, audit log analysis, and security assessments of the secrets platform.
- Ensure compliance with relevant frameworks and regulations including ISO 27001, SOC 2, PCI-DSS, and NIST guidelines.
- Drive zero-trust architecture principles across secrets distribution and access patterns.

DevSecOps & Integration:

- Integrate secrets management tooling with CI/CD pipelines (e.g. GitHub Actions, Jenkins, GitLab CI) to eliminate hard-coded credentials.
- Build Vault Agent, sidecar injection, and Kubernetes Secrets Store CSI Driver integrations for containerised workloads.
- Partner with application and DevOps teams to migrate away from legacy secrets handling patterns toward dynamic, short-lived credentials.
- Develop SDKs, libraries, and internal tooling to simplify developer adoption of secrets management APIs.

Leadership & Enablement:

- Act as the internal SME and evangelist for secrets management — mentoring engineers and running enablement sessions.
- Define and own the secrets management roadmap, balancing security uplift with engineering velocity.
- Produce and maintain runbooks, architecture documentation, and operational procedures.
- Collaborate with security architecture, risk, and compliance teams on controls and evidence for audits.

Required Skills & Experience:

Essential:





- 5+ years in a cybersecurity, infrastructure, or platform engineering role, with at least 3 years of hands-on HashiCorp Vault (or equivalent) experience.
- Deep expertise in Vault architecture: cluster setup, auth methods (AppRole, Kubernetes, AWS IAM, LDAP, OIDC), secret engines, policies, and audit devices.
- Strong scripting and automation skills — Python, Bash, Go, or similar.
- Infrastructure as Code proficiency — Terraform, Ansible, or Pulumi.
- Experience with Kubernetes and container-native secrets injection patterns (CSI driver, Vault Agent Injector).
- Solid understanding of PKI, TLS/mTLS, certificate lifecycle management, and encryption key management (HSM experience a plus).
- Familiarity with cloud-native secrets services across AWS (Secrets Manager, KMS, Parameter Store), Azure (Key Vault), and/or GCP (Secret Manager).
- Solid understanding of zero-trust architecture, least-privilege access, and RBAC.
- Experience with CI/CD pipeline integration and secrets hygiene in software delivery.

Desirable:

- HashiCorp Vault Associate or Professional certification.
- Experience with CyberArk, Conjur, or other PAM/secrets platforms.
- Exposure to SIEM integration and secrets-related threat detection (e.g. detecting credential misuse via audit logs).
- Experience in a regulated environment (financial services, healthcare, government).
- Familiarity with service mesh and mTLS patterns (Istio, Consul Connect).
- Open-source contributions or public technical writing related to secrets management.

What We Offer:

- Competitive salary and performance-based bonus.
- Flexible hybrid working arrangements.
- Dedicated learning and certification budget (including HashiCorp, cloud, and security certifications).
- Exposure to a complex, large-scale, multi-cloud environment.
- Collaborative, psychologically safe team culture with a genuine security-first mission.
- Private healthcare, pension, and extra benefits package.

We are an equal opportunity employer and welcome applications from all backgrounds. This is indicative and may be subject to change in line with business needs.

📌 Lead HashiVault Engineer-29209] (Hyderabad)
🏢 Talent500
📍 Hyderabad

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: lead hashivault engineer-29209] (hyderabad) / hyderabad

Subscribe to this job alert:

Get the latest job offers by email for: lead hashivault engineer-29209] (hyderabad) / hyderabad