Intercontinental Exchange

Lead Systems Engineer, Secrets and Vault Engineering

Intercontinental Exchange
Apply
4 months ago

Base Salary

$149k - $180k/yr

Responsibilities

  • Design, build, and maintain platform services for secrets management, certificate lifecycle, encryption key management, and policy enforcement.
  • Develop Python, Shell, and Ansible automation and tooling to streamline operations and enforce security controls.
  • Build self-service capabilities for application teams using templates, declarative manifests, and approval workflows integrated with enterprise systems such as ServiceNow.
  • Collaborate with application, infrastructure, security, and compliance teams to develop reliable and governed services.
  • Shape roadmap initiatives involving SPIFFE/SPIRE, policy-as-code, workload identity, and identity controls for AI and machine-driven workloads.
  • Participate in code reviews, design reviews, architecture discussions, documentation, runbooks, knowledge-sharing, and a light on-call rotation.
  • Mentor and coach engineers earlier in their careers.

Requirements

  • At least 7 years of infrastructure, platform, or systems engineering experience.
  • Production experience with HashiCorp Vault, including secret engines, authentication methods, policies, and operational concerns.
  • Strong proficiency in Python and Shell scripting, plus experience with Ansible for configuration management and orchestration.
  • Understanding of identity, authentication, and secure communication protocols including TLS, OAuth, OIDC, and x.509.
  • Working knowledge of CI/CD tooling such as Jenkins, GitHub Actions, or GitLab CI and Infrastructure-as-Code, preferably Terraform.
  • Experience designing and consuming APIs and strong Linux systems fundamentals.
  • Ability to write production-quality code, communicate design trade-offs, collaborate across teams, and mentor engineers.
  • Bachelor's degree in Computer Science, Engineering, or a related field is preferred.
  • Preferred experience includes self-service Vault, secrets, or cryptography platforms; SPIFFE/SPIRE; policy-as-code tools such as Open Policy Agent or HashiCorp Sentinel; AI/ML infrastructure; post-quantum cryptography; AWS, GCP, or hybrid cloud environments; AWS Secrets Manager or KMS; Docker, Kubernetes, or OpenShift; threat modeling; secrets rotation; secret-zero patterns; zero trust architectures; and regulated or security-sensitive industries.

Benefits

  • Regular full-time employees are eligible for medical, dental, and vision coverage, a 401(k) plan, life insurance, time off, and paid leave for qualifying circumstances.
  • The listed New York role is onsite, as indicated by the #LI-ONSITE designation.

Tech Stack

AnsibleAWSDockerGitHub ActionsGitLab CI/CDGoogle Cloud PlatformJenkinsKubernetesLinuxOpenShiftPythonTerraform

Categories

Intercontinental Exchange

About Intercontinental Exchange

10,000+ employees

ICE (NYSE: ICE) connects people to data, technology and expertise that create opportunity and inspire innovation. For terms of use, visit www.ice.com/privacy-security-center/terms-of-use

Contact me