Job descriptionJob Description
Senior Security Platform Engineer — Remote
Support innovative enterprise security initiatives in Canada's insurance sector by contributing to automation, cloud technologies, and modern security platforms. Work in a collaborative environment with flexible remote work and opportunities to make a meaningful impact.
What is in it for you:
• Salaried: $65-85 per hour.
• Incorporated Business Rate: $80-100 per hour.
• 5-month contract with the potential for permanent employment.
• Full-time position: 37.5 hours per week.
• Schedule: Daytime, 9:00 am to 5:00 pm EST.
• Work Model: Remote with onsite work every Wednesday in Toronto.
Responsibilities:
• Design, develop, and implement automated certificate lifecycle management solutions.
• Build automation for certificate issuance, renewal, deployment, rotation, and revocation.
• Support enterprise SSL certificate rotation initiatives across production and non-production environments.
• Identify and eliminate manual certificate management processes through automation.
• Support and enhance CyberArk Machine Identity Security (formerly Venafi) capabilities.
• Develop integrations between certificate management platforms and enterprise systems.
• Implement reusable onboarding and automation patterns for application teams.
• Improve certificate visibility, compliance, governance, and operational efficiency.
• Design and implement certificate management integrations with F5, Akamai, AWS Certificate Manager (ACM), Amazon EKS/Kubernetes, Microsoft Graph, and HashiCorp Vault.
• Container platforms and cloud-native workloads.
• Additional enterprise applications and infrastructure services.
• Develop certificate automation solutions leveraging HashiCorp Vault PKI capabilities.
• Build and enhance integrations between HashiCorp Vault and enterprise applications.
• Create automated certificate issuance and rotation workflows.
• Support onboarding of applications to Vault-based certificate management services.
• Partner with application and infrastructure teams to implement certificate automation solutions.
• Provide technical guidance, troubleshooting, onboarding support, and best practices.
• Develop technical documentation, implementation guides, and operational runbooks.
• Lead knowledge-sharing and enablement sessions for stakeholders.
• Develop automation using scripting, APIs, Infrastructure as Code, and DevOps practices.
• Participate in Agile delivery processes, including backlog refinement, estimation, sprint planning, and implementation activities.
• Contribute to platform resiliency, monitoring, operational support, and continuous improvement initiatives.
What you will need to succeed:
Required qualifications
• Bachelor’s degree in computer science.
• 5 years of experience in Security Engineering, Infrastructure Engineering, Platform Engineering, or related disciplines.
• Strong experience with PKI, SSL/TLS certificates, and certificate lifecycle management.
• Hands-on experience with CyberArk Machine Identity Security (Venafi) or an equivalent certificate management platform.
• Experience implementing certificate automation at enterprise scale.
• Strong knowledge of cryptography principles, certificate trust chains, and machine identity security.
• Hands-on experience with several of the following technologies: HashiCorp Vault, AWS Certificate Manager (ACM), Amazon EKS/Kubernetes, Microsoft Graph, F5 Load Balancers, Akamai, Azure and/or AWS cloud services, and REST APIs and platform integrations.
• Experience with Python, PowerShell, Terraform, Ansible, Git, CI/CD pipelines, Infrastructure as Code, and API-based automation.
• Knowledge of Linux and Windows administration, networking fundamentals, TLS/SSL protocols, load balancers and reverse proxies, Kubernetes and container platforms, and monitoring and logging solutions.
Preferred qualifications
• Experience with HashiCorp Vault PKI Secrets Engine.
• Experience supporting large-scale certificate management programs.
• Experience working in Agile delivery environments.
• Security certifications such as CISSP, CCSP, Security+, GIAC, or equivalent.
• Experience supporting enterprise security platforms and cloud-native technologies.
Why Recruit Action?
Recruit Action (agency permit: AP-2504511) provides recruitment services through quality support and a personalized approach. As part of the screening process, some applications may be reviewed using artificial intelligence tools. Only candidates who meet the hiring criteria will be contacted.
Requirements
—