3 months ago
Base Salary
$149k - $238k/yr
Responsibilities
- Design, deploy, and operate PKI infrastructure for secure authentication, encryption, and certificate lifecycle management.
- Manage certificates, secrets, keys, trust stores, and access controls, including issuance, renewal, rotation, and revocation.
- Build, maintain, and secure Kubernetes clusters hosting PKI and secrets-management services.
- Automate certificate lifecycle, secrets-management, and infrastructure operations using Infrastructure-as-Code, CI/CD pipelines, and Kubernetes-native tooling.
- Monitor and troubleshoot PKI, certificate, secrets, Kubernetes, and distributed infrastructure issues, including root cause analysis and remediation.
- Integrate PKI and secrets management into cloud-native applications and services in collaboration with SRE, platform, security, and engineering teams.
- Maintain PKI architecture documentation, runbooks, operational procedures, security best practices, and disaster recovery procedures.
- Ensure PKI and Kubernetes platforms meet security, reliability, scalability, and compliance requirements.
- Participate in on-call rotations, incident response, and operational improvement initiatives.
Requirements
- At least 7 years of experience in infrastructure, platform, SRE, or security engineering roles.
- Strong production experience managing and securing Kubernetes clusters and containerized workloads.
- Hands-on experience with PKI platforms, certificate lifecycle management, secrets management, and encryption technologies.
- Experience with AWS KMS, Azure Key Vault, HashiCorp Vault, EJBCA, Smallstep, Venafi, or similar cloud-native security solutions.
- Strong understanding of Linux systems, networking, distributed systems, and Kubernetes security best practices.
- Experience with automation, scripting, Infrastructure-as-Code, and CI/CD pipelines for PKI and infrastructure operations.
- Familiarity with IAM and access management platforms such as Okta, Entra ID, or Keycloak.
- Experience with monitoring, logging, alerting, and troubleshooting distributed infrastructure and security systems.
- Strong communication and collaboration skills across engineering, operations, and security teams.
Benefits
- Hybrid schedule based in Seattle, WA, with onsite work Tuesday through Friday and remote work on Mondays.
- Competitive salary and 401k with employer match.
- Discretionary paid time off.
- Paid parental leave.
- Medical, dental, and vision plans.
- Fitness programs and emotional and mental wellness support.
- Learning and development programs.
- Office snacks.
