Job DescriptionThe Federal Aviation Administration (FAA) is seeking a highly skilled System Engineer to serve as a senior technical HashiCorp Vault SME responsible for the design, implementation, automation, security, and sustainment of enterprise cloud infrastructure and DevSecOps capabilities. The engineer serves as the technical subject matter expert for HashiCorp Vault, providing leadership in enterprise secrets management, privileged credential management, encryption, certificate management, and secure application integration across cloud and hybrid environments.
Salary is based on relative years of experience: $170,000 - $180,000
Job Duties & Responsibilities - Essential Job Functions may include (but are not limited to) the following:
The following duties are considered essential to the role. Reasonable accommodations may be made to enable individuals with disabilities to perform these essential functions
- Serve as the FAA's senior technical subject matter expert for HashiCorp Vault and enterprise secrets-management architecture.
- Design, implement, configure, and administer highly available Vault environments across cloud, hybrid, and on-premises infrastructure.
- Develop enterprise Vault architectures supporting centralized secrets management, dynamic credentials, encryption, PKI, certificates, and application authentication.
- Establish Vault policies, namespaces, authentication methods, secret engines, roles, access controls, and governance standards.
- Integrate Vault with AWS, Red Hat OpenShift, Kubernetes, CI/CD pipelines, applications, databases, and enterprise services.
- Implement dynamic secrets and short-lived credentials to reduce reliance on static credentials and improve security posture.
- Configure and manage Vault authentication methods including Kubernetes, AWS IAM, AppRole, LDAP, OIDC, and other enterprise authentication mechanisms.
- Develop and maintain Vault PKI capabilities for automated certificate issuance, rotation, and revocation.
- Implement encryption-as-a-service capabilities using Vault Transit to protect sensitive FAA application data.
- Design automated secret rotation and lifecycle-management processes.
- Develop Vault backup, recovery, disaster-recovery, and high-availability strategies.
- Establish monitoring, logging, auditing, and operational procedures for Vault environments.
- Troubleshoot complex Vault availability, authentication, authorization, integration, and performance issues.
- Develop enterprise standards, reference architectures, implementation guides, and operational runbooks for Vault.
- Mentor cloud engineers and development teams on secure Vault implementation and secrets-management best practices.
- Design, build, automate, and maintain secure AWS cloud infrastructure supporting FAA mission and enterprise applications.
- Develop and maintain Infrastructure as Code using Terraform, Ansible, CloudFormation, or equivalent technologies.
- Build automated cloud environments using repeatable, version-controlled, policy-driven deployment processes.
Required Qualifications - A successful candidate will have - Bachelor's degree in Computer Science, Information Systems, Engineering, Cybersecurity, or a related technical discipline, or equivalent experience. (Master's degree preferred).
- 8+ years of experience in cloud engineering, DevOps, systems engineering, platform engineering, or related technical disciplines.
- 5+ years of experience with AWS or comparable enterprise cloud platforms.
- Extensive hands-on experience with HashiCorp Vault in enterprise environments.
- Demonstrated experience designing and implementing Vault authentication, policies, secret engines, dynamic credentials, PKI, encryption, and audit capabilities.
- Strong experience with Kubernetes and/or Red Hat OpenShift.
- Strong understanding of CI/CD and DevSecOps principles.
- Experience integrating secrets management into automated application and infrastructure deployment pipelines.
- Strong understanding of cloud security, IAM, encryption, certificates, networking, and zero-trust principles.
- Experience working in regulated, highly secure, or federal environments.
Education- Bachelor's degree in Information Technology, Computer Science, Engineering, or related field (or equivalent experience).
Work Requirements and Additional Information- Work Location: Remote
- Position is: Remote
- Work Hours: 40
- Travel: 0%
- Background check: Must have the ability to obtain and maintain a public trust clearance, which requires U.S. citizenship.
- Physical Requirements:
- Extended Computer Use: Regular and prolonged periods of working at a computer terminal.
- Mobility: Ability to move around the office environment to access computer hardware, networking equipment, and server rooms.
- Dexterity: Manual dexterity and visual acuity to operate computer equipment, troubleshoot issues, and perform tasks requiring precision.
- Sitting/Standing: Both prolonged sitting and occasional standing may be required for troubleshooting and attending to system issues.
- Work Environment/Environmental Factors
- Primarily computer-based work; meetings or collaboration may be required.
}