Ubique Systems

TRPD-26-04354

Security Platform Engineer (Secrets Management & IAM)

Security Platform Engineering role supporting a hybrid multi-cloud environment (Azure, AWS, on-prem, Kubernetes and CI/CD). The focus is to assess and standardize enterprise secrets management and IAM end-to-end (identities, roles/policies, workload identity, privileged access, federation, audit/governance), define target-state architecture and operating model, and drive onboarding/migration of application teams to secure patterns. Requires hands-on Azure/AWS IAM and at least two secrets technologies, plus integration with CI/CD, Kubernetes and enterprise security controls; regulated enterprise experience and ability to produce practical reference architectures and playbooks are important.

Position summary

Location
India
Workplace
Hybrid
Employment
Full Time
Experience
Minimum 5 years and Maximum 10 years
Apply now

Role overview

Why This Role Matters.

Security Platform Engineering role supporting a hybrid multi-cloud environment (Azure, AWS, on-prem, Kubernetes and CI/CD). The focus is to assess and standardize enterprise secrets management and IAM end-to-end (identities, roles/policies, workload identity, privileged access, federation, audit/governance), define target-state architecture and operating model, and drive onboarding/migration of application teams to secure patterns. Requires hands-on Azure/AWS IAM and at least two secrets technologies, plus integration with CI/CD, Kubernetes and enterprise security controls; regulated enterprise experience and ability to produce practical reference architectures and playbooks are important.

Your Impact

Deliver Enterprise Value

Help organisations solve complex business problems through modern technology, consulting expertise and measurable outcomes.

Collaboration

Work Across Teams

Collaborate with consultants, architects, engineers and client stakeholders throughout the project lifecycle.

Growth

Learn Continuously

Gain exposure to enterprise technologies, certifications, mentoring and real-world project experience.

Career Path

Grow With Ubique

Build a long-term consulting career with opportunities to take on greater responsibility and leadership over time.

Responsibilities

What You'll Be Doing.

Every role at Ubique contributes directly to solving meaningful business challenges for our clients.

01

Assess current secrets management and IAM practices across Azure, AWS, on-premises, Kubernetes, CI/CD, applications, databases, APIs, and service accounts.

02

Define target-state architecture for secrets management, IAM integration, workload identity, privileged access, credential rotation, audit, and governance.

03

Create enterprise standards for secrets storage, access, rotation, ownership, naming, tagging, expiry, exception handling, and decommissioning.

04

Define when to use centralized secrets platforms versus cloud-native tools such as Azure Key Vault and AWS Secrets Manager.

05

Design IAM access models using Azure Entra ID, AWS IAM, roles, policies, groups, service principals, managed identities, OIDC federation, and least-privilege access.

06

Support onboarding and migration of application teams from insecure or inconsistent secrets and IAM practices.

07

Integrate secrets management with IAM, PAM, CI/CD pipelines, Kubernetes, databases, APIs, legacy applications, logging, monitoring, and SIEM.

08

Help establish operating model components such as ownership, support processes, governance, exception management, control monitoring, and reporting.

09

Produce practical documentation, reference architectures, onboarding playbooks, and implementation patterns for engineering teams.

10

B.E./ B.Tech. Or M.C.A. in Computer Science from a reputed University with 10-15 years of hands-on experience on below mentioned skills.

11

Proven experience delivering at least one enterprise transformation in secrets management, IAM, PAM, DevSecOps, cloud security, or machine identity.

12

Strong understanding of IAM concepts, including authentication, authorization, RBAC, ABAC, least privilege, federation, workload identity, privileged access, service accounts, access reviews, and audit controls.

Technology stack

Tools & Technologies.

The platforms and technologies you'll use to build modern, enterprise-grade solutions.

01

Azure

02

AWS

03

On-premises

04

Hybrid cloud

05

Kubernetes

06

CI/CD

07

Azure DevOps

08

GitHub Actions

09

Jenkins

10

GitLab

11

Azure Entra ID

12

Azure Managed Identity

13

Service Principal

14

AWS IAM

15

IAM Roles

16

IAM Policies

17

AWS STS

18

OIDC

19

Federation

20

RBAC

Requirements

Skills & Experience.

We value curiosity, collaboration and continuous learning. If you don't meet every requirement but believe you can make an impact, we'd still love to hear from you.

Essential

Required Qualifications

Secrets management architecture and engineering (enterprise standards, rotation, governance, audit)

IAM concepts end-to-end: authentication vs authorization, RBAC/ABAC, least privilege, federation, workload identity, privileged access, service accounts, access reviews, audit controls

Hands-on Azure IAM: Azure Entra ID, service principals, managed identities

Hands-on AWS IAM: roles, policies, STS, OIDC federation

Experience with at least two secrets management technologies (e.g., Azure Key Vault, AWS Secrets Manager, HashiCorp Vault, CyberArk Conjur, Akeyless, Thales CipherTrust, External Secrets Operator, Secrets Store CSI Driver)

Hybrid environment experience (cloud + on-prem workloads)

Integration of secrets/IAM with CI/CD tools (Azure DevOps, GitHub Actions, Jenkins, GitLab or similar)

Kubernetes integration for secrets/workload identity (implied by scope: Kubernetes + secrets operators/CSI)

Ability to define target-state architecture, enterprise standards, migration plans, governance/operating model, and engineering patterns

Stakeholder management across security, cloud/platform, infrastructure, application, risk and audit teams

Willingness/ability to provide support outside India business hours including weekends

Preferred

Nice to Have

Regulated enterprise environment experience (financial services, banking, insurance, healthcare or similar)

CyberArk PAM experience

HashiCorp Vault Enterprise experience

Machine identity, certificate lifecycle management, dynamic secrets

Policy-as-code and cloud governance tooling (Terraform, Azure Policy, AWS Organizations/SCPs, OPA, Sentinel, Checkov, Prisma Cloud, Wiz or similar)

Secret scanning/remediation tools (GitHub Advanced Security, GitGuardian, Gitleaks, TruffleHog or similar)

Dashboards/metrics for secrets compliance, IAM hygiene, rotation status, onboarding progress, exceptions and risk reduction

SIEM/logging/monitoring integration for audit and control monitoring

What you'll gain

More Than Just A Job.

We're committed to helping every team member grow professionally, personally and technically while working on meaningful projects.

Global Exposure

Collaborate with international clients and multicultural teams on enterprise programmes.

Continuous Learning

Expand your expertise through mentoring, certifications and hands-on project experience.

Career Growth

Take ownership, develop leadership skills and grow your consulting career over time.

Flexible Working

Hybrid and remote collaboration designed around trust and delivering exceptional outcomes.

People First

Join a supportive culture where collaboration, respect and long-term relationships come first.

Enterprise Projects

Work on meaningful technology initiatives for leading organisations across industries.

Apply

Apply for Security Platform Engineer (Secrets Management & IAM)

One page, about two minutes. We only ask for what we actually need to have a first conversation.

Your CV

Optional. A line or two is plenty.