100%remote

Salary
—
Posted
Aug 13, 2026
Location
100%
Last confirmed open
Sep 24, 2026

What this job asks for AI summary

This role designs, implements, and operates an enterprise-wide secrets management platform — covering credentials, keys, certificates, and tokens — across cloud, containerized, and CI/CD environments. The engineer onboards thousands of applications and services, automates credential lifecycle workflows, enforces least-privilege IAM policies, and ensures compliance with Zero Trust and AWS GovCloud requirements including FIPS 140-2/3 cryptographic controls. It suits an experienced security engineer with hands-on platform engineering and automation skills.

Senior level · Washington-Arlington-Alexandria, DC-VA-MD-WV · Bachelor's required · Full-time

Quick apply — this platform usually takes a CV and a few fields.

Must have (10)
CyberArk or VaultAWS Secrets ManagerAWS KMSPythonTerraformAnsibleCI/CDPKIKubernetesIAM
Nice to have (5)
AWS GovCloudAWS Certified Security – SpecialtyAWS Certified Solutions Architect – AssociateHashiCorp Vault Associate or Cyberark DefenderCISSP or Cism

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 80 people in the Washington-Arlington-Alexandria, DC-VA-MD-WV area plausibly meet what this posting asks for (information security analysts). range 25–120

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What gives you an edge
Ansible8%Terraform11%

Rare in this occupation — lead with these, and say what you built with them.

What won't set you apart
Python51%CI/CD45%IAM45%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $152,225 (middle half $125,286–$177,673).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Aug 15, 2026. It is a model, not a headcount.

Why we read it this way (6)

The role sits at the intersection of security engineering and platform/automation engineering — it builds and operates a secrets management platform (suggesting 15-1252 Software Developers) but the primary mission is security controls, compliance, and credential governance (suggesting 15-1212 Information Security Analysts). 15-1212 was chosen as the primary classification given the dominant security-governance framing.

The posting names CyberArk and HashiCorp Vault as interchangeable platform options ('such as CyberArk or HashiCorp Vault, based on the selected enterprise platform'); both are captured as alternatives on a single required skill.

AWS GovCloud experience is explicitly called 'preferred' in the qualifications section, so it is marked as a preferred skill.

All listed certifications (AWS Security Specialty, AWS Solutions Architect Associate, HashiCorp Vault Associate / CyberArk Defender, CISSP / CISM) appear under a 'Preferred Certifications' heading and are marked accordingly.

No compensation figures are stated in the posting beyond a general reference to 'competitive salary paid twice per month.'

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): AWS Systems Manager Parameter Store.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗