远程工作雷达

特权访问管理与密钥管理 高级工程师

Privileged Access Management & Secrets Management Sr Engineer

开发工程限定地区(需当地身份)
公司Lockheed Martin Corporation
薪资$88,300 - $227,600/年
工作地点United States
地域资格限定地区(需当地身份)
时区要求日间重叠约 9 小时,基本正常作息
用工类型Full Time
发布时间今天
数据来源Himalayas
前往 Himalayas 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

标准职位描述

洛克希德·马丁公司企业IT组织中的特权访问管理(PAM)团队正在招聘一位经验丰富的信息保障专业人员,具备网络安全软件工程经验,以及在特权访问管理(PAM)和秘密管理方面的深厚专业知识。

您将负责的工作:

在特权访问管理与秘密管理高级工程师的职位中,您将设计、实施和运营自动化凭证解决方案,以保护跨混合环境的特权访问。您将影响组织的秘密管理总体目标和长期目标,并参与开发和推出新服务,同时为DevOps社区推广现有解决方案。您的主要职责包括:

• 设计、部署和记录安全凭证平台
• 架构、安装和维护行业领先的PAM和秘密工具,如HashiCorp Vault和CyberArk Conjur
• 确保对本地、云和边缘系统的特权账户进行强有力的保护
• 将秘密集成到DevOps流水线中
• 协助开发团队将秘密检索、轮换和生命周期流程无缝嵌入CI/CD工作流

• 领导战略影响与思想引领
• 制定组织的长期秘密管理路线图
• 推广最佳实践解决方案
• 在DevOps社区中担任安全凭证管理的倡导者

关于此机会的更多信息:

此职位为完全远程办公。由于系统访问权限,需要美国公民身份;如果需要,也可能需要获得机密级别许可。

基本资格要求

  • 在大规模实施HashiCorp Vault、CyberArk Conjur或类似PAM/秘密管理平台方面有成功经验
  • 在将秘密管理集成到Jenkins、GitLab等CI/CD工具及相应Web服务和工作负载方面有较强背景
  • 有支持合规性经验,确保秘密管理符合DFARS、CMMC、SOX和ISO 27001等标准
  • 对程序化认证方法有清晰理解,从静态方法到基于令牌、基于密钥以及特定平台工作负载方法
  • 精通脚本编写(Python、PowerShell、Bash),以及基础设施即代码(Terraform、CloudFormation)
  • 有通过安全系统设计支持网络操作并增强防御可见性的经验
查看英文原文

Standard Job Description

The Privileged Access Management (PAM) team in Lockheed Martin'sEnterprise IT organization is hiring a seasoned Information Assurance professional with experience in cyber software engineering as well as deep expertise in Privileged Access Management (PAM) and secrets management.

What You Will Be Doing:

In this Privileged Access Management & Secrets Management Sr Engineer role, you will design, implement, and operate automated credential solutions that safeguard privileged access across hybrid environments. You will influence the overall objectives and long-range goals of Secrets Management for the organization and participate in developing and rolling out new services, and championing available solutions for the DevOps community. Your key responsibilities will include:

• Designing, Deploying and Documenting Secure Credential Platforms

•Architecting, installing, and maintaining industry-leading PAM and secrets tools such as HashiCorp Vault and CyberArk Conjur

• Ensuring robust protection of privileged accounts across on-premise, cloud, and edge systems
• Integrating Secrets into DevOps Pipelines
•Assisting development teams to seamlessly embed secret retrieval, rotation, and lifecycle processes into CI/CD workflows

• Leading strategic Influence & Thought

•Shaping the organization’s long term Secrets Management roadmap

• Championing best practice solutions

• Serving as an evangelist for secure credential management within the DevOps community

Further Information About This Opportunity:

This role is fully remote. US Citizenship is required due to system access; the ability to obtain Secret level clearance also may be required if needed.

Basic Qualifications

  • Proven track record implementing HashiCorp Vault, CyberArk Conjur, or comparable PAM/secret management platforms at scale
  • Strong background in integration of secrets management into Jenkins, GitLab, similar CI/CD tools and the corresponding web services and workloads
  • Experience supporting compliance ensuring secrets management complies with standards such as DFARS, CMMC, SOX, and ISO 27001
  • Clear understanding of programmatic authentication methods ranging from static methods to token based, key based and specific platform workload methods
  • Proficiency in scripting (Python, PowerShell, Bash), and infrastructureascode (Terraform, CloudFormation)
  • Experience supporting cyber operations through secure system design and enhancing defensive visibility with identity and access management
  • Excellent communication and stakeholder management abilities; capable of influencing cross functional teams and advocating security best practices
  • Ability to translate complex security requirements into practical, automated solutions
  • Passion for staying current with emerging threats, cryptographic standards, and evolving PAM technologies
  • Collaborative mindset, fostering a security first culture within DevOps and engineering squads
  • US Citizenship is required due to system access

Desired Skills

  • Ansible experience
  • Knowledge of managing security for AWS IAM resources
  • SailPoint IIQ experience - Information Security experience
  • Active Directory experience
  • Active Secret Clearance

Pay Information
GeoZone Definition: GeoZones are geographic groupings created by Lockheed Martin to align compensation ranges with regional labor markets and cost-of-labor differences across the United States. Locations are assigned a Geo Zone based on the primary work location of the role.

  • Full-time salary range (GEOZONE 1): $122600.00 - $227600.00 · Includes metropolitan areas such as Sunnyvale CA; Pal Alto, CA; New York City metropolitan area; Newark, New Jersey; etc.
  • Full-time salary range (GEOZONE 2): :$110300.00 - $204900.00 · Includes metropolitan areas such as Denver, CO; King of Prussia, PA; Stratford, CT; Moorestown, NJ; etc.
  • Full-time salary range (GEOZONE 3): :$98100.00 - $182100.00· Includes metropolitan areas such as Dallas–Fort Worth, TX; Orlando, FL; Grand Prairie, TX; Marietta, GA; etc.
  • Full-time salary range (GEOZONE 4): :$88300.00 - $163900.00· Includes metropolitan areas such as Camden, AR; Lexington, KY; Ocala, FL; Lufkin, TX; etc.

At Lockheed Martin, we know mission success starts with taking care of our people. Our Total Rewards program is designed to attract top talent, support your well-being, and help you grow—both professionally and personally.
The salary range for this position is as listed on the requisition. Please note that the salary information listed is a general guideline only.
Lockheed Martin considers factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience, education/ training, key skills as well as market(work location) and business considerations when extending an offer.
Benefits offered: Medical, Dental, Vision, Flexible work arrangements and schedules (e.g., 4x10), 401(k) match, Paid time off, Holidays, Parental Leave, EAP, Flexible Spending Accounts, Education Assistance, Life Insurance, Short-Term Disability, and Long-Term Disability.

  • Annual short-term and/or long-term incentive compensation programs may be offered depending on the position. Payments under these annual programs are not guaranteed and can vary from year to year and are tied to a range of performance metrics.
  • For (Washington state applicants only) Non-represented full-time employees: accrue at least 10 hours per month of Paid Time Off (PTO) to be used for incidental absences and other reasons; receive at least 90 hours for holidays. Represented full time employees accrue 6.67 hours of Vacation per month; accrue up to 52 hours of sick leave annually; receive at least 96 hours for holidays. PTO, Vacation, sick leave, and holiday hours are prorated based on start date during the calendar year.

Originally posted on Himalayas

本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

A/AI 机器学习工程高级

Lockheed Martin CorporationUnited States$110,300 - $204,900/年Full Time今天
AI开发工程限定地区(需当地身份)

分包项目管理主管

Lockheed Martin CorporationUnited States$178,500 - $331,500/年Full Time今天
其他限定地区(需当地身份)

SAP 业务分析师 高级 - E4

Lockheed Martin CorporationUnited States$94,400 - $243,500/年Full Time昨天
职能支持限定地区(需当地身份)

← 返回全部职位