Senior Security Platform Engineer — Remote
Support innovative enterprise security initiatives in Canada's insurance sector by contributing to automation, cloud technologies, and modern security platforms. Work in a collaborative environment with flexible remote work and opportunities to make a meaningful impact.
What is in it for you:
- Salaried: $65-85 per hour.
- Incorporated Business Rate: $80-100 per hour.
- 5-month contract with the potential for permanent employment.
- Full-time position: 37.5 hours per week.
- Schedule: Daytime, 9:00 am to 5:00 pm EST.
- Work Model: Remote with onsite work every Wednesday in Toronto.
Responsibilities:
- Design, develop, and implement automated certificate lifecycle management solutions.
- Build automation for certificate issuance, renewal, deployment, rotation, and revocation.
- Support enterprise SSL certificate rotation initiatives across production and non-production environments.
- Identify and eliminate manual certificate management processes through automation.
- Support and enhance CyberArk Machine Identity Security (formerly Venafi) capabilities.
- Develop integrations between certificate management platforms and enterprise systems.
- Implement reusable onboarding and automation patterns for application teams.
- Improve certificate visibility, compliance, governance, and operational efficiency.
- Design and implement certificate management integrations with F5, Akamai, AWS Certificate Manager (ACM), Amazon EKS/Kubernetes, Microsoft Graph, and HashiCorp Vault.
- Container platforms and cloud-native workloads.
- Additional enterprise applications and infrastructure services.
- Develop certificate automation solutions leveraging HashiCorp Vault PKI capabilities.
- Build and enhance integrations between HashiCorp Vault and enterprise applications.
- Create automated certificate issuance and rotation workflows.
- Support onboarding of applications to Vault-based certificate management services.
- Partner with application and infrastructure teams to implement certificate automation solutions.
- Provide technical guidance, troubleshooting, onboarding support, and best practices.
- Develop technical documentation, implementation guides, and operational runbooks.
- Lead knowledge-sharing and enablement sessions for stakeholders.
- Develop automation using scripting, APIs, Infrastructure as Code, and DevOps practices.
- Participate in Agile delivery processes, including backlog refinement, estimation, sprint planning, and implementation activities.
- Contribute to platform resiliency, monitoring, operational support, and continuous improvement initiatives.
What you will need to succeed:
Required qualifications
- Bachelor’s degree in computer science.
- 5 years of experience in Security Engineering, Infrastructure Engineering, Platform Engineering, or related disciplines.
- Strong experience with PKI, SSL/TLS certificates, and certificate lifecycle management.
- Hands-on experience with CyberArk Machine Identity Security (Venafi) or an equivalent certificate management platform.
- Experience implementing certificate automation at enterprise scale.
- Strong knowledge of cryptography principles, certificate trust chains, and machine identity security.
- Hands-on experience with several of the following technologies: HashiCorp Vault, AWS Certificate Manager (ACM), Amazon EKS/Kubernetes, Microsoft Graph, F5 Load Balancers, Akamai, Azure and/or AWS cloud services, and REST APIs and platform integrations.
- Experience with Python, PowerShell, Terraform, Ansible, Git, CI/CD pipelines, Infrastructure as Code, and API-based automation.
- Knowledge of Linux and Windows administration, networking fundamentals, TLS/SSL protocols, load balancers and reverse proxies, Kubernetes and container platforms, and monitoring and logging solutions.
Preferred qualifications
- Experience with HashiCorp Vault PKI Secrets Engine.
- Experience supporting large-scale certificate management programs.
- Experience working in Agile delivery environments.
- Security certifications such as CISSP, CCSP, Security+, GIAC, or equivalent.
- Experience supporting enterprise security platforms and cloud-native technologies.
Why Recruit Action?
Recruit Action (agency permit: AP-2504511) provides recruitment services through quality support and a personalized approach. As part of the screening process, some applications may be reviewed using artificial intelligence tools. Only candidates who meet the hiring criteria will be contacted.
Pay: $65.00-$100.00 per hour
Benefits:
Application question(s):
- Do you have hands-on experience with cloud and platform technologies? Please specify which (e.g., HashiCorp Vault, AWS ACM, EKS/Kubernetes, Microsoft Graph, F5, Akamai, Azure/AWS, REST APIs).
- Do you have experience with DevOps and automation tools? Please specify which (e.g., Python, PowerShell, Terraform, Ansible, Git, CI/CD, IaC, API automation).
- Do you have experience with infrastructure technologies? Please specify which (e.g., Linux/Windows administration, networking, TLS/SSL, load balancers, reverse proxies, Kubernetes, monitoring, logging).
Education:
- Bachelor's Degree (required)
Experience:
- PKI, SSL/TLS, and certificate lifecycle management: 1 year (required)
- Certificate management tools (e.g., CyberArk/Venafi): 1 year (required)
- Implementing certificate automation at the enterprise scale: 1 year (required)
- Cryptography, certificate trust chains & machine identity: 1 year (preferred)
- HashiCorp Vault PKI Secrets Engine: 1 year (preferred)
- Supporting large-scale certificate management programs: 1 year (preferred)
- Working in Agile delivery environments: 1 year (preferred)
- Enterprise security platforms & cloud-native technologies: 1 year (preferred)
- Security, Infrastructure, or Platform Engineering: 5 years (required)
Licence/Certification:
- Security certifications such as CISSP, CCSP, Security+, GIAC (preferred)
Work Location: Hybrid remote in Toronto, ON