Job Description
Job Purpose
To design, implement, operate, and govern enterprise-grade encryption key management, secrets management, and vault platforms across multi-cloud environments including Azure, AWS, GCP, Oracle Cloud, and IBM Cloud. The role involves supporting day-to-day cloud operations, resolving escalated issues, assisting in large-scale cloud migrations, and ensuring performance, security, and reliability of mission-critical workloads hosted on Azure.
Duties and Responsibilities
A-Minimum required Accountabilities for this role
B-Additional Accountabilities pertaining to the role
Major Challenges
Managing consistent encryption and secrets strategy across five different cloud providers
Ensuring high availability and lowlatency access to vault services for missioncritical workloads
Handling key rotation and zerodowntime secrets updates for production systems
Meeting strict regulatory and audit requirements in financial services
Securing secrets across diverse runtimes: VMs, containers, Kubernetes, serverless, and legacy systems
Coordinating with multiple teams under tight delivery and security SLAs
Required Qualifications and Experience
a)Qualifications
Bachelors degree in Computer Science, Information Technology, Cybersecurity, or related field
710 years of overall IT experience with 5+ years in Cloud Security / Key Management
b)Work Experience
Key Management Cryptography
Strong handson experience with:
Azure Key Vault Managed HSM
AWS KMS CloudHSM
GCP Cloud KMS
OCI Vault
IBM Key Protect
Understanding of encryption algorithms, TLS, certificates, PKI, asymmetric/symmetric cryptography
CMK, BYOK, HYOK, envelope encryption patterns
Secrets Vault Management
Secrets lifecycle management for:
Database credentials
API keys, tokens, certificates
Application and platform secrets
HashiCorp Vault architecture, HA setup, and integrations (preferred)
Cloud Platform Integration
Kubernetes secrets integration (AKS, EKS, GKE, OKE)
Secure CI/CD integrations (Azure DevOps, Jenkins, GitHub Actions)
IAM, RBAC, workload identity, and leastprivilege access
Automation DevSecOps
Infrastructure as Code using Terraform
Automation using Python, PowerShell, Bash
Policy as Code and security guardrails
Monitoring, Audit Compliance
Key usage logging, audit trails, alerting
Compliance mapping for PCIDSS, ISO, SOC2, RBI guidelines
Incident management and root cause analysis (RCA)