TRPD-26-04354
Security Platform Engineer (Secrets Management & IAM)
Security Platform Engineering role supporting a hybrid multi-cloud environment (Azure, AWS, on-prem, Kubernetes and CI/CD). The focus is to assess and standardize enterprise secrets management and IAM end-to-end (identities, roles/policies, workload identity, privileged access, federation, audit/governance), define target-state architecture and operating model, and drive onboarding/migration of application teams to secure patterns. Requires hands-on Azure/AWS IAM and at least two secrets technologies, plus integration with CI/CD, Kubernetes and enterprise security controls; regulated enterprise experience and ability to produce practical reference architectures and playbooks are important.
Position summary
- Location
- India
- Workplace
- Hybrid
- Employment
- Full Time
- Experience
- Minimum 5 years and Maximum 10 years
Role overview
Why This Role Matters.
Security Platform Engineering role supporting a hybrid multi-cloud environment (Azure, AWS, on-prem, Kubernetes and CI/CD). The focus is to assess and standardize enterprise secrets management and IAM end-to-end (identities, roles/policies, workload identity, privileged access, federation, audit/governance), define target-state architecture and operating model, and drive onboarding/migration of application teams to secure patterns. Requires hands-on Azure/AWS IAM and at least two secrets technologies, plus integration with CI/CD, Kubernetes and enterprise security controls; regulated enterprise experience and ability to produce practical reference architectures and playbooks are important.
Your Impact
Deliver Enterprise Value
Help organisations solve complex business problems through modern technology, consulting expertise and measurable outcomes.
Collaboration
Work Across Teams
Collaborate with consultants, architects, engineers and client stakeholders throughout the project lifecycle.
Growth
Learn Continuously
Gain exposure to enterprise technologies, certifications, mentoring and real-world project experience.
Career Path
Grow With Ubique
Build a long-term consulting career with opportunities to take on greater responsibility and leadership over time.
Responsibilities
What You'll Be Doing.
Every role at Ubique contributes directly to solving meaningful business challenges for our clients.
Define target-state architecture for secrets management, IAM integration, workload identity, privileged access, credential rotation, audit, and governance.
Create enterprise standards for secrets storage, access, rotation, ownership, naming, tagging, expiry, exception handling, and decommissioning.
Define when to use centralized secrets platforms versus cloud-native tools such as Azure Key Vault and AWS Secrets Manager.
Design IAM access models using Azure Entra ID, AWS IAM, roles, policies, groups, service principals, managed identities, OIDC federation, and least-privilege access.
Support onboarding and migration of application teams from insecure or inconsistent secrets and IAM practices.
Integrate secrets management with IAM, PAM, CI/CD pipelines, Kubernetes, databases, APIs, legacy applications, logging, monitoring, and SIEM.
Help establish operating model components such as ownership, support processes, governance, exception management, control monitoring, and reporting.
Produce practical documentation, reference architectures, onboarding playbooks, and implementation patterns for engineering teams.
B.E./ B.Tech. Or M.C.A. in Computer Science from a reputed University with 10-15 years of hands-on experience on below mentioned skills.
Proven experience delivering at least one enterprise transformation in secrets management, IAM, PAM, DevSecOps, cloud security, or machine identity.
Strong understanding of IAM concepts, including authentication, authorization, RBAC, ABAC, least privilege, federation, workload identity, privileged access, service accounts, access reviews, and audit controls.
Technology stack
Tools & Technologies.
The platforms and technologies you'll use to build modern, enterprise-grade solutions.
Azure
AWS
On-premises
Hybrid cloud
Kubernetes
CI/CD
Azure DevOps
GitHub Actions
Jenkins
GitLab
Azure Entra ID
Azure Managed Identity
Service Principal
AWS IAM
IAM Roles
IAM Policies
AWS STS
OIDC
Federation
RBAC
Requirements
Skills & Experience.
We value curiosity, collaboration and continuous learning. If you don't meet every requirement but believe you can make an impact, we'd still love to hear from you.
Essential
Required Qualifications
Secrets management architecture and engineering (enterprise standards, rotation, governance, audit)
IAM concepts end-to-end: authentication vs authorization, RBAC/ABAC, least privilege, federation, workload identity, privileged access, service accounts, access reviews, audit controls
Hands-on Azure IAM: Azure Entra ID, service principals, managed identities
Hands-on AWS IAM: roles, policies, STS, OIDC federation
Experience with at least two secrets management technologies (e.g., Azure Key Vault, AWS Secrets Manager, HashiCorp Vault, CyberArk Conjur, Akeyless, Thales CipherTrust, External Secrets Operator, Secrets Store CSI Driver)
Hybrid environment experience (cloud + on-prem workloads)
Integration of secrets/IAM with CI/CD tools (Azure DevOps, GitHub Actions, Jenkins, GitLab or similar)
Kubernetes integration for secrets/workload identity (implied by scope: Kubernetes + secrets operators/CSI)
Ability to define target-state architecture, enterprise standards, migration plans, governance/operating model, and engineering patterns
Stakeholder management across security, cloud/platform, infrastructure, application, risk and audit teams
Willingness/ability to provide support outside India business hours including weekends
Preferred
Nice to Have
Regulated enterprise environment experience (financial services, banking, insurance, healthcare or similar)
CyberArk PAM experience
HashiCorp Vault Enterprise experience
Machine identity, certificate lifecycle management, dynamic secrets
Policy-as-code and cloud governance tooling (Terraform, Azure Policy, AWS Organizations/SCPs, OPA, Sentinel, Checkov, Prisma Cloud, Wiz or similar)
Secret scanning/remediation tools (GitHub Advanced Security, GitGuardian, Gitleaks, TruffleHog or similar)
Dashboards/metrics for secrets compliance, IAM hygiene, rotation status, onboarding progress, exceptions and risk reduction
SIEM/logging/monitoring integration for audit and control monitoring
What you'll gain
More Than Just A Job.
We're committed to helping every team member grow professionally, personally and technically while working on meaningful projects.
Global Exposure
Collaborate with international clients and multicultural teams on enterprise programmes.
Continuous Learning
Expand your expertise through mentoring, certifications and hands-on project experience.
Career Growth
Take ownership, develop leadership skills and grow your consulting career over time.
Flexible Working
Hybrid and remote collaboration designed around trust and delivering exceptional outcomes.
People First
Join a supportive culture where collaboration, respect and long-term relationships come first.
Enterprise Projects
Work on meaningful technology initiatives for leading organisations across industries.
Apply
Apply for Security Platform Engineer (Secrets Management & IAM)
One page, about two minutes. We only ask for what we actually need to have a first conversation.