Ähnliche Jobs

IAM Tier 3 Operations Engineer (m/w/d) Vault Integration - Remote & Berlin/Frankfurt

IAM Tier 3 Operations Engineer (m/w/d) Vault Integration - Remote & Berlin/Frankfurt

IAM Tier 3 Operations Engineer (m/w/d) Vault Integration - Remote & Berlin/Frankfurt

IAM Tier 3 Operations Engineer (m/w/d) Vault Integration - Remote & Berlin/Frankfurt

percision services GmbH

IT-Dienstleister

Berlin

  • Art der Anstellung: Vollzeit
  • 57.500 € – 81.500 € (von XING geschätzt)
  • Hybrid
  • Zu den Ersten gehören

IAM Tier 3 Operations Engineer (m/w/d) Vault Integration - Remote & Berlin/Frankfurt

Über diesen Job

IAM Tier 3 Operations Engineer (m/w/d) Vault Integration - Remote & Berlin/Frankfurt

Projektnummer
#8938
Region
Remote und Berlin oder Frankfurt
Zeitraum
Oktober bis Ende 2025 + Option 2026
Teilen:

Für unseren Kunden in Berlin suchen wir im Rahmen eines langfristigen Greenfield Projektes erfahrene Unterstützung als IAM Engineer (m/w/d) Vault Integration. Die Tätigkeit erfolgt Remote und in der Regel eine Woche für 3-4 Tage pro Monat vor Ort in Berlin oder Frankfurt . Je nach Projektphase wird eine Bereitschaft vor Ort von bis zu 50% vorausgesetzt. Hintergrund ist ein großes Plattformprojekt im Energiesektor.

Project:

The team is building an internal platform for software product developers to accelerate the development and delivery of software products to tackle the massive challenges facing the energy sector. The Platform is a service oriented, cloud-native platform that is being built to provide application teams with self-service capabilities to develop, run and operate their software products. Platform provides services for application infrastructure, data, service lifecycle management, application build and delivery as well as services to operate their software products. The Platform is deployed as a hybrid cloud, encompassing both private cloud and select public clouds.

The IAM Service is responsible for the conception and designing of identity and access management (IAM) services for the platform. The primary goals are providing a scalable, secure, and federated access to applications, ensuring seamless integration across the hybrid cloud environment

Objective 1: Deploy and configure Vault services in enterprise environments:

Installation and configuration of HashiCorp Vault Enterprise.

Setting up of namespaces, secret engines, authentication backends, entities, and AppRoles.

Integration with Kubernetes clusters using VSO / ESO.

Documentation of deployed setups for reuse in further environments.

Objective 2: Implement secure lifecycle handling of secrets:

Configuration of secret rotation, renewal, and expiration.

Integration of Hardware Security Module (HSM) for key storage.

Setting up of PKI workflows for certificate generation and renewal.

Verification of compliance with project security requirements.

Objective 3: Automate Vault provisioning and management:

Creation of Helm charts, Terraform modules, and GitOps workflows.

Automation of application onboarding to Vault.

Implementation of CI/CD integrations for secret injection during deployments.

Documentation of automation steps for reproducibility.

Objective 4: Ensure stable operations and technical alignment:

Monitor and tune of Vault clusters for performance and availability.

Execution of upgrades and patching activities.

Co-ordinate integration points between with IAM and platform.

Record operational changes in technical documentation.

Objective 5: Knowledge transfer and continuous improvement:

Prepare runbooks and operational guidelines.

Share of best practices in internal sessions or documentation.

Deploy new Vault features and community practices.

Prototype the improvements for secrets management workflows.

Must-have experience

Experience with Vault Enterprise administration, configuring Vault namespaces, ACLs, identity groups, DR, auto-unseal:

Secrets management integrations (VSO/ESO, CI/CD).

OIDC and RBAC/ABAC patterns.

HA/DR and secure operational runbooks.

Experience with the integration of Keycloak OIDC/JWT and Terraform policy-as-code.

Experienced with onboarding workflows (agents, sidecars, templates) and managing secret rotation engines and expiry alerts.

Experience with implementation of mTLS, IP allow-lists, JIT access, SIEM integration along with delivering tamper-evident audit logging.

Experience with the broader Vault architecture and its best-practices.

Experience with Hardware Security Module (HSM) which needs to be integrated with infrastructure level with a basic knowledge of Public Key Infrastructure (PKI).

Experience with short-lived certs via Vault PKI (not ceremonies).

Fluent English (C1).

Knowledge about IAM solutions based on OpenID Connect (OIDC), such as Keycloak, for auth backends.

Working with Scrum and general experience in agile frameworks.

Fluent in German.

Sie suchen in eigener Sache?

Wir freuen uns auf ihre projektbezogene Bewerbung & Unterlagen über unser Bewerbungstool unten .

Gehalts-Prognose

Unternehmens-Details

company logo

percision services GmbH

IT-Dienstleister

1-10 Mitarbeitende

Köln, Deutschland

Wir benachrichtigen Dich gern über ähnliche Jobs in Berlin:

Ähnliche Jobs

Externes Job-Angebot. Partner-Angebot

Senior Site Reliability Engineer - AI Platform

N26 GmbH

Berlin

68.000 €94.500 €

Externes Job-Angebot. Partner-Angebot

Senior Site Reliability Engineer - AI Platform

Berlin

N26 GmbH

68.000 €94.500 €

Site Reliability Engineer / DevOps (m/f/x)

flaschenpost SE

Berlin

Site Reliability Engineer / DevOps (m/f/x)

Berlin

flaschenpost SE

Senior IoT Platform Engineer (m/f/d)

1KOMMA5˚

Berlin

72.500 €88.000 €

Senior IoT Platform Engineer (m/f/d)

Berlin

1KOMMA5˚

72.500 €88.000 €

ClimateTech - Senior DevOps (all genders)

Global Changer

Berlin

61.000 €82.000 €

ClimateTech - Senior DevOps (all genders)

Berlin

Global Changer

61.000 €82.000 €

Kubernetes Spezialist (m/w/d) in Berlin

Grühn GmbH

Berlin

60.000 €85.000 €

Kubernetes Spezialist (m/w/d) in Berlin

Berlin

Grühn GmbH

60.000 €85.000 €

Senior Cloud Engineer - Azure & AWS

MEvents Cross Media GmbH

Berlin

80.000 €100.000 €

Senior Cloud Engineer - Azure & AWS

Berlin

MEvents Cross Media GmbH

80.000 €100.000 €

Site Reliability Engineer (m/w/d)

S-Kreditpartner

Berlin

69.000 €92.500 €

Site Reliability Engineer (m/w/d)

Berlin

S-Kreditpartner

69.000 €92.500 €

Senior Cloud Engineer (f/m/x) – CB Data / AI Integration Services

Deutsche Bank AG

Berlin

68.500 €84.500 €

Senior Cloud Engineer (f/m/x) – CB Data / AI Integration Services

Berlin

Deutsche Bank AG

68.500 €84.500 €

Lead Cloud Engineer (f/m/x) – CB Data / AI Integration Services

Deutsche Bank AG

Berlin

69.500 €89.000 €

Lead Cloud Engineer (f/m/x) – CB Data / AI Integration Services

Berlin

Deutsche Bank AG

69.500 €89.000 €