06 Aug
|
Recrute Action
|
Toronto
06 Aug
Recrute Action
Toronto
Senior Security Platform Engineer — Remote
Join a collaborative engineering team responsible for advancing enterprise certificate management capabilities through automation, cloud-native technologies, and machine identity security initiatives. This position offers the opportunity to work on complex security platforms and large-scale infrastructure environments.
What is in it for you:
- Salaried: $65-85 per hour.
- Incorporated Business Rate: $80-100 per hour.
- 5-month contract with the potential for permanent employment.
- Full time position: 37.5 hours per week.
- Schedule: Daytime, 9:00 am to 5:00 pm EST.
- Work Model: Remote with onsite work every Wednesday in Toronto.
Responsibilities:
• Certificate Lifecycle Automation: Design, develop, and implement automated certificate lifecycle management solutions; build automation for certificate issuance, renewal, deployment, rotation, and revocation; support enterprise SSL certificate rotation initiatives across production and non-production environments; identify and eliminate manual certificate management processes through automation.
• Machine Identity Security & Venafi Engineering: Support and enhance CyberArk Machine Identity Security (Venafi) capabilities; develop integrations between certificate management platforms and enterprise systems; implement reusable onboarding and automation patterns for application teams; improve certificate visibility, compliance, governance, and operational efficiency.
• Platform Integration Engineering: Design and implement certificate management integrations with F5, Akamai, AWS Certificate Manager (ACM), Amazon EKS/Kubernetes, Microsoft Graph, HashiCorp Vault, container platforms, cloud-native workloads,
and additional enterprise applications and infrastructure services.
• HashiCorp Vault Automation: Develop certificate automation solutions leveraging HashiCorp Vault PKI capabilities; build and enhance integrations between Vault and enterprise applications; create automated certificate issuance and rotation workflows; support onboarding of applications to Vault-based certificate management services.
• Application Onboarding & Support: Partner with application and infrastructure teams to implement certificate automation solutions; provide technical guidance, troubleshooting, onboarding support, and best practices; develop technical documentation, implementation guides, and operational runbooks; lead knowledge-sharing and enablement sessions for stakeholders.
• Engineering & Delivery: Develop automation using scripting, APIs, Infrastructure-as-Code, and DevOps practices; participate in Agile delivery processes including backlog refinement, estimation, sprint planning, and implementation activities; contribute to platform resiliency, monitoring, operational support, and continuous improvement initiatives.
What you will need to succeed:
Required qualifications
- Bachelor Science degree in computer science.
- Experience with TLS/SSL certificate lifecycle workflows.
- 5+ years of experience in Security Engineering, Infrastructure Engineering, Platform Engineering,
or related disciplines.
- Strong experience with PKI, SSL/TLS certificates, and certificate lifecycle management.
- Hands-on experience with CyberArk Machine Identity Security (Venafi) or equivalent certificate management platforms.
- Experience implementing certificate automation at enterprise scale.
- Strong knowledge of cryptography principles, certificate trust chains, and machine identity security.
- Hands-on experience with AWS Certificate Manager (ACM), Amazon EKS / Kubernetes, Microsoft Graph, F5 Load Balancers, Akamai, Azure and/or AWS cloud services, REST APIs, and platform integrations.
- Experience with Python, PowerShell, Terraform, Ansible, Git, CI/CD pipelines, Infrastructure as Code, and API-based automation.
- Infrastructure skills including Linux and Windows administration, networking fundamentals, TLS/SSL protocols (including ACME), load balancers and reverse proxies, Kubernetes and container platforms, and monitoring and logging solutions.
Preferred qualifications
- Experience with HashiCorp Vault PKI Secrets Engine.
- Experience supporting large-scale certificate management programs.
- Experience working in Agile delivery environments.
- Security certifications such as CISSP, CCSP, Security+, GIAC, or equivalent.
- Experience supporting enterprise security platforms and cloud-native technologies.
Why Recruit Action?
Recruit Action (agency permit: AP-2504511) provides recruitment services through quality support and a personalized approach. As part of the screening process, some applications may be reviewed using artificial intelligence tools. Only candidates who meet the hiring criteria will be contacted.
📌 Senior Security Platform Engineer — 100% Remote (Toronto)
🏢 Recrute Action
📍 Toronto