Overview
Anaplan is searching for a Principal Infrastructure Engineer to lead the design and build of a new multi‑region HashiCorp Vault platform. This role will serve as a subject‑matter expert, shaping the future of secrets management and governance for a platform that supports hundreds of engineers and top‑flight companies around the world. The position is hybrid, requiring at least two days per week in the London office.
Responsibilities
- Lead the architecture, design, and implementation of a new, multi‑region HashiCorp Vault platform on public cloud.
- Take ownership of the solution architecture, creating and maintaining high‑quality design documents and Architecture Decision Records (ADRs).
- Ensure platform resilience by developing and testing robust strategies for performance, Disaster Recovery (DR), and High Availability (HA).
- Act as the primary SME for the organisation on all aspects of Vault and modern secrets management, actively championing and evangelising best practices.
- Collaborate with and influence stakeholders, platform teams, and software engineers to ensure the smooth and secure integration of their services with the Vault ecosystem.
- Partner with Security to define the control requirements for the Vault platform (policy standards, privileged access, audit/evidence, compliance needs) and ensure designs meet those requirements.
- Lead regular security design reviews for Vault architecture decisions (authn/authz, policy model, namespaces/tenancy, seal strategy with KMS/HSM, audit logging) and drive alignment/sign‑off with Security.
- Establish joint operating processes with Security for incident response and investigations, including break‑glass access, audit log access patterns, and post‑incident remediation.
- Coach and mentor other engineers on security best practices and the adoption of the new secrets management platform.
Skills & Qualifications
- Hands‑on expertise in designing, implementing, and operating HashiCorp Vault in large‑scale production environments.
- Proven experience with multi‑region deployments on public cloud platforms, preferably AWS. Experience with GCP and Azure is also highly valuable.
- Proficient with Infrastructure as Code (IaC) and Terraform.
- Knowledge of modern authentication and authorisation mechanisms (e.g., OIDC, SAML, JWT).
- Experience managing Public Key Infrastructure (PKI) and certificate lifecycles.
- Experience with observability tooling such as Grafana, Prometheus, and Loki.
- Proficient with Kubernetes and managed Kubernetes platforms such as EKS, GKS, and AKS.
- Experience with Kubernetes tooling such as Helm and Argo CD.
- Demonstrated experience in creating and automating testing strategies for critical infrastructure.
- Ability to write and maintain clear documentation for other teams.
- Excellent communication skills, with a proven ability to influence technical direction and mentor both junior and senior engineers.
Bonus Points For
- Scripting or development experience in Go, Python, or similar.
- Experience writing or maintaining Kubernetes Operators.
Commitment to Diversity, Equity, Inclusion and Belonging (DEIB)
We believe attracting and retaining the best talent and fostering an inclusive culture strengthens our business. DEIB improves our workforce, enhances trust with our partners and customers, and drives business success. Build your career in a place where diversity, equity, inclusion and belonging aren’t just words on paper – this is what drives our innovation, it’s how we connect, and it contributes to what makes us a market leader. We hire based on talent and potential, not on gender identity or expression, sexual orientation, religion, ethnicity, age, neurodiversity, disability status, citizenship, or any other aspect that makes people unique.
We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, perform essential job functions, and receive equitable benefits and all privileges of employment. Please contact us to request accommodation.
#J-18808-Ljbffr…
