Role Overview
NIQ is looking to expand our Identity and Access Management (IAM) Program. In this role, the Engineer will put a distinct focus on Secrets Management technology and associated processes to align with the enhancement of DevSecOps capabilities. The areas for this position are research, analysis, design, deployment, integration, administration, and day to day operations of the Secrets Management solution. The Engineer will also support DevSecOps activities with knowledge in programming languages and CI/CD pipeline workflows.
Responsibilities
- Research, perform gap analysis, design, implement, and manage secrets management infrastructure.
- Collaborate with cross-functional teams to understand secrets management requirements.
- Develop and implement secure coding practices to mitigate risks associated with hardcoded secrets.
- Establish and enforce policies for key lifecycle management, rotation, and expiration.
- Monitor and analyze key usage, providing insights for continuous improvement.
- Collaborate with cybersecurity teams to ensure compliance with industry standards and regulations.
- Conduct regular audits and vulnerability assessments to identify secret management risks.
- Develop automation using programming languages like Python.
- Handle CI/CD pipelines using tools like GitHub and GitHub Actions.
- Design and implement secure sharing mechanisms for controlled access to secrets.
- Provide technical expertise and support for incident response related to secrets management.
- Deploy and manage Vault instances in high availability, hybrid and multi cloud environments.
Requirements
- Bachelor's degree in computer science, Information Technology, or related field.
- Minimum 4 years of proven experience in implementing and supporting secrets management solutions.
- Proficiency in using and configuring secrets management tools (e.g., HashiCorp Vault, CyberArk Conjur).
- Strong understanding of secure coding practices and the identification of hardcoded secrets.
- Knowledge of key management principles, including rotation, expiration, and lifecycle.
- Familiarity with cybersecurity best practices and industry standards.
- Proficient in operating within multi-cloud, DevOps, and CI/CD environments.
- Implement and manage Infrastructure as Code (Terraform, CloudFormation, ARM, Bicep, etc.).
- Expertise in cloud platforms (AWS, Azure, GCP) and containerization technologies (Docker, Kubernetes).
- Strong communication skills, both verbal and written.
- Ability to work in a dynamic and fast-paced environment.
Skills
- HashiCorp Vault
- Python
- Terraform
- AWS
- GitHub Actions
Benefits
- Flexible working environment
- Volunteer time off
- LinkedIn Learning
- Employee-Assistance-Program (EAP)