Design, deploy, configure, and maintain HashiCorp Vault and CyberArk services across production and non production environments.Engineer secure secrets management patterns for applications, human administrators, service accounts, workloads, APIs, CI/CD pipelines, and cloud native platforms.Implement HashiCorp Vault Enterprise capabilities such as namespaces, integrated storage, performance and disaster recovery replication, high availability, auto unseal, Sentinel policies, and audit devices.Configure Vault authentication methods and secrets engines, including AppRole, Kubernetes, LDAP/OIDC, cloud authentication, KV, database dynamic credentials, PKI, SSH, transit encryption, and cloud secrets, as applicableAdminister and engineer CyberArk components including Digital Vault, PVWA, CPM, PSM/PSMP, Safes, Platforms, account discovery, onboarding, credential rotation, reconciliation, session management, and audit controls Design integration and coexistence patterns between HashiCorp Vault and CyberArk, with clear ownership for human privileged credentials, application secrets, machine identities, API keys, certificates, and service accountsIntegrate secrets management platforms with AWS, Azure, GCP, Kubernetes, Docker, Terraform, Ansible, Jenkins, GitLab CI, GitHub Actions, ServiceNow, SIEM, and enterprise identity providersDevelop Infrastructure as Code, scripts, APIs, reusable modules, and automated workflows using Terraform, Python, Bash, PowerShell, or Go.Perform platform upgrades, patching, certificate renewal, backup and recovery validation, capacity management, health checks, performance tuning, and vulnerability remediation. Troubleshoot complex authentication, authorization, connectivity, replication, unseal, policy, token, certificate, password rotation, reconciliation, and privileged session issues.Drive incident, problem, change, and release activities in accordance with enterprise ITIL and security processes; lead root cause analysis for recurring issues.Create and maintain HLDs, LLDs, SOPs, runbooks, operational standards, support procedures, architecture diagrams, and knowledge transfer materials.Provide technical leadership, design reviews, engineering guidance, training, and mentoring to operations teams and junior engineersParticipate in US time zone meetings, planned maintenance windows, technical escalations, and on call support as agreed for the engagement.Hands on enterprise experience with HashiCorp Vault architecture, implementation, administration, security hardening, and troubleshooting.Hands on experience with CyberArk PAM engineering and administration, including Vault, PVWA, CPM, PSM/PSMP, Safes, Platforms, onboarding, rotation, reconciliation, and session controlsStrong understanding of secrets lifecycle management, privileged access management, least privilege, Zero Trust, machine identity, RBAC, policy as code, and separation of duties.Practical knowledge of PKI, TLS/mTLS, certificates, encryption, tokenization, key management, HSM/KMS concepts, authentication methods, and identity federation.Experience building highly available and disaster recovery architectures and validating backups, failover, replication, and recovery procedures.Proficiency in Terraform and working knowledge of Ansible or equivalent configuration management / IaC tooling.Experience with Kubernetes, Docker, Linux/Unix, Windows Server, networking fundamentals, DNS, proxies, firewalls, load balancers, SSH, and REST APIs Experience integrating security platforms into CI/CD pipelines and cloud environments such as AWS, Azure, or GCP.Scripting and automation capability in at least two of Python, Bash, PowerShell, or Go.Experience with monitoring and observability tools such as Prometheus, Grafana, Splunk, or equivalent, including alerting and audit log integration. Ability to independently own engineering deliverables, production issues, stakeholder communication,