Wells Fargo Logo

Wells Fargo

Lead Infrastructure Engineer (Encryption Security-Hashicorp Vault)

Posted Yesterday
Be an Early Applicant
Hybrid
Chandler, AZ
Senior level
Hybrid
Chandler, AZ
Senior level
About this role:
This position will be part of a Team that performs engineering and management of data protection technologies that includes Hashicorp Vault. Candidates must have intermediate to advanced systems engineering experience in medium to large Enterprise environments. Must have extensive experience with Linux Server operating systems, Red Hat preferred. Experience providing production support and end to end management of HSMs and/or security appliances and/or data protection/encryption technologies. Need to be capable of creating technical/engineering documentation and have excellent written and oral communication. Must have extensive experience with scripting and automation practices. Participates in interactions with encryption technology and HSM vendors - helps to ensure vendor product engineering is in line with the objectives and security requirements of Wells Fargo and coordinates with the vendor support teams to ensure issues impacting Wells Fargo are resolved quickly and effectively. Participates in interactions with technical, engineering and non-technical partners companywide for the technologies listed above.
In this role, you will:
  • Independently design, implement, and manage secure, highly available HashiCorp Vault platform with minimal oversight from lead engineers
  • Contribute to end-to-end automation of Vault provisioning, configuration, and lifecycle management using Ansible and Terraform
  • Develop and enforce platform standards for secrets management, authentication, authorization, and Vault best practices across the organization
  • Analyze and solve complex technical challenges, including cloud native and multi-cloud integrations, Kubernetes auth setups, PKI hierarchies, replication, and performance optimization
  • Collaborate directly with cross-functional teams-security, platform engineering, application teams, product owners, and vendors-to deliver architecturally sound Vault solutions
  • Troubleshoot deep technical issues independently, including HA failures, unseal workflows, auth method problems, and secret engine configuration errors
  • Implement advanced Vault capabilities, such as static and dynamic secrets, PKI secret engine, dynamic Database secrets, and namespace management
  • Guide and support engineering teams, providing Vault expertise, technical recommendations, and onboarding assistance without requiring constant supervision
  • Drive continuous improvement, identifying opportunities for automation, performance tuning, reliability enhancements, and security hardening across Vault deployments
  • Provide on-call support on rotational basis per team's schedule.

Required Qualifications:
  • 5+ years of Technology Infrastructure Engineering and Solutions experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education
  • 3+ years of hands-on experience with HashiCorp Vault, with a proven track record in enterprise-grade Vault design, deployment, and automation
  • Practical experience with Enterprise Change Management, change control processes, and operating within procedural, compliance-driven environments
  • Hands-on expertise with Terraform, Ansible, CI/CD pipelines, and GitHub, with strong understanding of modern automation pipelines for Vault provisioning and configuration
  • Solid understanding of Linux system administration, required for installing, configuring, securing, and troubleshooting Vault clusters
  • Deep understanding of the Vault lifecycle, including installation, upgrades, HA deployment, scaling, and cluster maintenance.

Desired Qualifications:
  • Proven experience designing, integrating, and maintaining Vault Secret Engines, including: KV, Database, PKI, Azure, GCP, LDAP, Dynamic secret engines, and secret rotation flows
  • Strong experience designing, implementing, and maintaining Vault Auth Engines, such as: LDAP, AppRole, Kubernetes, JWT/OIDC, TLS Certificate authentication.
  • Hands-on experience implementing Vault Auto-Unseal using HSM-based solutions.
  • Experience configuring and maintaining Vault audit logging, monitoring, and metrics, using tools like Splunk, Grafana, and other observability platforms.
  • Hands-on expertise with Vault Agent, templates, auto-auth, and Vault Proxy integrations.
  • Should have hands on experience in using Hashicorp Vault service like (Key management system, Secret and certificate management)
  • Good knowledge of DevOps and SDLC for IaC CI/CD concepts, GitHub, branching strategies
  • Professional HashiCorp Vault Certification (HVCP or equivalent)

Job Expectations:
  • This position offers a hybrid work schedule
  • Relocation assistance is not available for this position
  • Telecommuting is not an option for this position
  • This position is not eligible for visa sponsorship.

Top Skills

Ansible
Ci/Cd
Git
Hashicorp Vault
Hsm
Linux
Pki
Terraform

Similar Jobs at Wells Fargo

8 Hours Ago
Hybrid
Chandler, AZ, USA
Senior level
Senior level
Fintech • Financial Services
Lead the development and maintenance of infrastructure solutions, evaluate software, analyze outages, follow procedures, and collaborate with teams/vendors.
Top Skills: Agile Development PracticesIbm CicsJclRacfSmp/ETsoZ/OsZlinux
8 Hours Ago
Hybrid
Chandler, AZ, USA
Senior level
Senior level
Fintech • Financial Services
Lead End User Support within the CTO, overseeing IT services, managing teams, ensuring compliance, and driving operational efficiency.
Top Skills: Incident ManagementIt Service OperationsProblem ManagementRisk Management
Yesterday
Hybrid
Tempe, AZ, USA
Junior
Junior
Fintech • Financial Services
The role involves providing electronic payment solutions to business clients, educating them on compliance, managing relationships, and supporting inbound customer calls in the Merchant Services Call Center.
Top Skills: EcommerceMS OfficeMobile SolutionsMs DynamicsPos SystemsSales Force

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account