
Senior Specialist, Cybersecurity Engineering
- Secrets Management
- CI/CD
- Risk Management
- Windows
- Linux
- Unix
- GitHub Actions
- GitLab CI
- Jenkins
- Azure DevOps
- IaC
- Terraform
- Ansible
- PowerShell
- Python
- Active Directory
- Identity Management
- ServiceNow
- Incident Management
- NIST
- ITIL
- CISSP
- Zero Trust
- Azure Active Directory
- IAM
- Incident Response
- Pension
Job Description
Privileged Access & Secrets Management Engineer (R3)
HashiCorp Vault & CI/CD Automation
Role Summary
Join our IT Risk Management & Security team and play a key role in protecting a global enterprise’s most critical systems, accounts, and secrets. As a Privileged Access & Secrets Management Engineer, you will design, deploy, and operate HashiCorp Vault and privileged access capabilities that reduce cyber risk and enable secure, automated secrets delivery. This role offers the opportunity to help shape enterprise privileged access and secrets management capabilities while working across identity, automation, cloud, infrastructure, and application teams.
What You'll Do
- Design, implement, and support HashiCorp Vault in on-premises environments.
- Develop reusable patterns, standards, and onboarding guidance for HashiCorp Vault and secrets management across application, infrastructure, and automation teams.
- Support HashiCorp Vault integrations with CI/CD platforms, deployment pipelines, automation workflows, and application delivery processes.
- Enable secure injection, retrieval, rotation, and lifecycle management of secrets used by build, release, and runtime environments.
- Integrate PAM with enterprise applications, infrastructure and cloud platforms, and APIs.
- Troubleshoot complex technical issues and support production operations.
- Develop automation, standards, and operational processes that improve security, efficiency, and improve audit readiness.
Required Qualifications
- Bachelor’s degree (or equivalent experience), preferably in Computer Science, Information Systems, or a related field.
- 5+ years of experience designing, deploying, and supporting HashiCorp Vault in on-premises environments, including integrations with CI/CD tools, automation frameworks, APIs, and application deployment workflows.
- Strong understanding of secrets lifecycle management including dynamic secrets, secrets engines, and auth methods for service accounts, workloads, applications, and non-human identities.
- Practical knowledge of privileged account management techniques: vaulting, password rotation, secrets management, least-privilege access, and service account security.
- Experience integrating security platforms with Windows, Linux/Unix, databases, cloud services, applications, and APIs.
- Ability to manage multiple priorities, adapt to change, and work effectively within large, global, matrixed organizations.
- Strong analytical, troubleshooting, problem-solving, and communication skills, with the ability to collaborate effectively across global teams and explain technical concepts to varied technical and non-technical audiences.
Preferred Qualifications
- Experience with CI/CD platforms such as GitHub Actions, GitLab CI, Jenkins, Azure DevOps, or similar tools.
- Experience with infrastructure-as-code and automation tools such as Terraform, Ansible, PowerShell, Python, or similar technologies.
- Hands-on experience with identity platforms such as Active Directory and Microsoft Entra ID, cloud identity management, etc.
- Familiarity with ServiceNow for change and incident management and experience automating tasks with PowerShell or similar technologies.
- Familiarity with NIST, ITIL, or related security frameworks.
- Relevant certifications such as CISSP, Security+, or similar credentials.
- Experience in healthcare, life sciences, or other highly regulated industries.
- Knowledge of Zero Trust principles, cloud security, and modern identity security practices.
Required Skills:
Access Management Software, Access Management Software, Azure Active Directory (AD), Certificate Services, Cloud Security, Cybersecurity, Cybersecurity Analytics, Cybersecurity Operations, Delivery of Security Applications, Design Applications, HashiCorp Vault, Identity Access Management (IAM), Incident Response, Information Assurance, Information Security, IT Security Architecture, Linux, Network Segmentation, Operational Technology (OT) Security, Red Hat Ansible, Security Analysis, Security Analytics, Security Controls, Security Evaluations, Security Fundamentals {+ 9 more}Preferred Skills:
Current Employees applyHERE
Current Contingent Workers applyHERE
US and Puerto Rico Residents Only:
Our company is committed to inclusion, ensuring that candidates can engage in a hiring process that exhibits their true capabilities. Pleaseclick here if you need an accommodation during the application or hiring process.
As an Equal Employment Opportunity Employer, we provide equal opportunities to all employees and applicants for employment and prohibit discrimination on the basis of race, color, age, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability status, or other applicable legally protectedcharacteristics.  As a federal contractor, we comply with all affirmative action requirements for protected veterans and individuals with disabilities. For more information about personal rights under the U.S. Equal Opportunity Employment laws, visit:
EEOC Know Your Rights
EEOC GINA Supplement​
We are proud to be a company that embraces the value of bringing together, talented, and committed people with diverse experiences, perspectives, skills and backgrounds. The fastest way to breakthrough innovation is when people with diverse ideas, broad experiences, backgrounds, and skills come together in an inclusive environment. We encourage our colleagues to respectfully challenge one another’s thinking and approach problems collectively.
Learn more about your rights, including under California, Colorado and other US State Acts
The salary range for this role is
$117,000.00 - $184,200.00This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting. An employee’s position within the salary range will be based on several factors including, but not limited to relevant education, qualifications, certifications, experience, skills, geographic location, government requirements, and business or organizational needs.
The successful candidate will be eligible for annual bonus and long-term incentive, if applicable.
We offer a comprehensive package of benefits. Available benefits include medical, dental, vision healthcare and other insurance benefits (for employee and family), retirement benefits, including 401(k), paid holidays, vacation, and compassionate and sick days. More information about benefits is available athttps://jobs.merck.com/us/en/compensation-and-benefits.
You can apply for this role throughhttps://jobs.merck.com/us/en (or via the Workday Jobs Hub if you are a current employee). The application deadline for this position is stated on this posting.
San Francisco Residents Only:Â We will consider qualified applicants with arrest and conviction records for employment in compliance with the San Francisco Fair Chance Ordinance
Los Angeles Residents Only: We will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws, including the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance
Search Firm Representatives Please Read CarefullyÂ
Merck & Co., Inc., Rahway, NJ, USA, also known as Merck Sharp & Dohme LLC, Rahway, NJ, USA, does not accept unsolicited assistance from search firms for employment opportunities. All CVs / resumes submitted by search firms to any employee at our company without a valid written search agreement in place for this position will be deemed the sole property of our company. Â No fee will be paid in the event a candidate is hired by our company as a result of an agency referral where no pre-existing agreement is in place. Where agency agreements are in place, introductions are position specific. Please, no phone calls or emails.Â
Employee Status:
RegularRelocation:
VISA Sponsorship:
Travel Requirements:
Flexible Work Arrangements:
HybridShift:
Valid Driving License:
Hazardous Material(s):
Job Posting End Date:
10/12/2026*A job posting is effective until 11:59:59PM on the dayBEFOREÂ the listed job posting end date. Please ensure you apply to a job posting no later than the dayBEFORE the job posting end date.
Senior Specialist, Cybersecurity Engineering · Intervet International Gm