채용
Director, Infrastructure Security Engineer - Secrets & Privileged Access Management / PKI

Director, Infrastructure Security Engineer - Secrets & Privileged Access Management / PKI
Newark, NJ, USA
·
On-site
·
Full-time
·
1mo ago
필수 스킬
Python
AWS
Kubernetes
Go
Terraform
Azure
Job Classification:
- Technology
- Engineering & Cloud
Are you interested in building capabilities that enable the organization with innovation, speed, agility, scalability and efficiency? The Global Technology team takes great pride in our culture where digital transformation is built into our DNA! When you join our organization at Prudential, you’ll unlock an exciting and impactful career – all while growing your skills and advancing your profession at one of the world’s leading financial services institutions.
Your Team & Role
As a Director, Infrastructure Security Engineer for Identity Governance and Administration, you will serve as a hands-on technical expert responsible for the architecture, delivery, and day-to-day operations of our security infrastructure platforms spanning Privileged Access Management (PAM), Secrets Management, and Public Key Infrastructure (PKI). You will specialize in one of these domains while contributing across the others, designing, building, operating, and continuously improving these critical platforms alongside product owners, tech leads, and engineering teams.
This role is for a highly skilled engineer who thrives on solving complex technical challenges and brings strong product knowledge in Cyber Ark Privileged Cloud, Hashi Corp Vault, or Keyfactor Command and EJBCA. You will drive automation, integrations, and operational excellence while ensuring all solutions meet Information Security Standards and regulatory requirements.
Key Responsibilities You will own one or more of the following platform areas and contribute across the others: - (PAM) Administer and mature Cyber Ark Privileged Cloud — onboarding privileged accounts, configuring CPM/PSM/PVWA components, building safe structures, defining connectors, and integrating with enterprise identity and SIEM platforms
-
(Secrets) Architect, deploy, and operate Hashi Corp Vault clusters — managing secrets engines (KV, PKI, database, AWS/Azure), auth methods (LDAP, App Role, Kubernetes), policies, leases, and DR/replication configurations
-
(PKI) Design, implement, and operate PKI platforms including Keyfactor Command and EJBCA — managing certificate authorities, certificate lifecycle automation, enrollment profiles, and integrations with enterprise systems
-
Build and maintain automation using Python, Go, Ansible, Terraform, and REST APIs to streamline platform operations, integrations, and self-service workflows
-
Develop and document platform patterns, runbooks, and self-service capabilities that enable application teams to consume PAM, Secrets Management, and PKI services consistently and at scale
-
Ensure platform security throughout the product lifecycle — integrating new features, responding to vulnerability disclosures, applying patches, and validating configurations against security baselines
-
Support audit and compliance engagements (PCI-DSS, SOX, and regulatory) by defining controls, producing evidence, and driving remediation for PAM, Secrets Management, and PKI findings
-
Collaborate with product owners and tech leads to define feature stories, technical design, and deliver robust, high-impact solutions
The Skills & Expertise You Bring
-
10+ years of experience in infrastructure or security engineering, with 5+ years focused on PAM, secrets management, or PKI platforms
-
Bachelor’s degree in Computer Science, Engineering, or related field, or equivalent hands-on experience
-
Ability to work independently with minimal guidance — a hands-on practitioner who can architect, operate, and troubleshoot platforms end-to-end
-
Strong problem-solving, communication, and collaboration skills with the ability to influence technical direction across teams
-
Understanding of risk management, compliance frameworks, and business context needed to make sound technical decisions aligned to the company's security posture
Significant experience and/or deep expertise with the following:
Privileged Access Management (PAM)
-
Strong expertise with Cyber Ark Privileged Cloud — Vault, CPM, PSM, PVWA, and REST/SCIM-based provisioning and automation
-
Privileged account lifecycle management including discovery, onboarding, automated rotation, and decommissioning
-
Just-in-Time (JIT) access, session recording, and privileged session management capabilities
-
PAM integrations with Active Directory/LDAP, SIEM platforms (Splunk), Service Now, and ITSM workflows
Secrets Management
-
Strong expertise with Hashi Corp Vault — cluster architecture, HA/DR replication, secrets engines, auth methods, and Vault Agent
-
Vault policy authoring, token lifecycle management, lease management, and automated secrets rotation
-
Hashi Corp Vault Enterprise features: namespaces, performance replication, HSM auto-unseal, and replication topology design
-
Secrets injection patterns for containerized workloads: Vault Agent Injector, CSI secrets provider, and Vault Secrets Operator for Kubernetes
Public Key Infrastructure (PKI)
-
Experience with Keyfactor Command — including CA management, certificate templates, enrollment profiles, ACME/SCEP/EST, REST API integrations, and reporting
-
Experience with EJBCA — CA hierarchy design, end-entity profiles, certificate profiles, RA operations, and REST API integration
-
PKI lifecycle management: certificate issuance, renewal, revocation, CRL/OCSP, and key escrow/recovery workflows
-
Certificate automation and DevOps PKI integration (ACME, cert-manager, Keyfactor integrations with Kubernetes and CI/CD pipelines)
-
HSM (Hardware Security Module) integration
-
Microsoft ADCS administration and/or migration experience to enterprise CA platforms
Infrastructure Fundamentals
-
Linux/Unix: file permissions, systemd services, network configuration, process management, and hardening for security platform components
-
Windows Server: Active Directory, Group Policy, Windows Certificate Services, and PowerShell administration
-
Containers: Kubernetes and container runtimes — deploying and operating security platform components in containerized environments
-
Networking: TCP/IP, TLS/mTLS, DNS, load balancing, firewall rules, and proxy configurations for PAM/Vault/PKI
-
Cloud: AWS and/or Azure — cloud IAM integrations with Vault and Cyber Ark, cloud-native secrets management, and PKI for cloud workloads
Programming & Automation
-
Python and Shell/Bash/PowerShell scripting for platform automation, REST API integration, and operational tooling
-
Ansible and Terraform for infrastructure-as-code, configuration management, and platform provisioning
-
REST API consumption and development — building integrations between PAM, Vault, PKI, and enterprise systems
-
CI/CD integration (Jenkins, GitLab CI, GitHub Actions) for secrets management pipelines and certificate lifecycle automation
Security & Compliance
-
Identity, authentication, authorization, and zero-trust architecture principles
-
Audit and compliance (PCI-DSS, SOX, and regulatory) — controls definition, evidence collection, and remediation for PAM, PKI, and Secrets Management findings
-
Infrastructure & Cloud Security best practices including Dev Sec Ops and secure SDLC
You’ll Love Working Here Because You Can
Join a team and culture where your voice matters; where every day, your work transforms our experiences to make lives better. As you put your skills to use, we’ll help you make an even bigger impact with learning experiences that can grow your technical AND leadership capabilities. You’ll be surprised by what this rock-solid organization has in store for you.
What we offer you:
Prudential is required by state specific laws to include the salary range for this role when hiring a resident in applicable locations. The salary range for this role is from $171,500.00 to $257,300.00. Specific pricing for the role may vary within the above range based on many factors including geographic location, candidate experience, and skills.-
Market competitive base salaries, with a yearly bonus potential at every level.
-
Medical, dental, vision, life insurance, disability insurance, Paid Time Off (PTO), and leave of absences, such as parental and military leave.
-
401(k) plan with company match (up to 4%).
-
Company-funded pension plan.
-
Wellness Programs including up to $1,600 a year for reimbursement of items purchased to support personal wellbeing needs.
-
Work/Life Resources to help support topics such as parenting, housing, senior care, finances, pets, legal matters, education, emotional and mental health, and career development.
-
Education Benefit to help finance traditional college enrollment toward obtaining an approved degree and many accredited certificate programs.
-
Employee Stock Purchase Plan: Shares can be purchased at 85% of the lower of two prices (Beginning or End of the purchase period), after one year of service.
Eligibility to participate in a discretionary annual incentive program is subject to the rules governing the program, whereby an award, if any, depends on various factors including, without limitation, individual and organizational performance. To find out more about our Total Rewards package, visit Work Life Balance | Prudential Careers. Some of the above benefits may not apply to part-time employees scheduled to work less than 20 hours per week.
Prudential Financial, Inc. of the United States is not affiliated with Prudential plc. which is headquartered in the United Kingdom.
Prudential is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, ancestry, sex, sexual orientation, gender identity, national origin, genetics, disability, marital status, age, veteran status, domestic partner status, medical condition or any other characteristic protected by law.
If you need an accommodation to complete the application process, please email accommodations.hw@prudential.com.
If you are experiencing a technical issue with your application or an assessment, please email careers.technicalsupport@prudential.com to request assistance.
총 조회수
0
총 지원 클릭 수
0
모의 지원자 수
0
스크랩
0
비슷한 채용공고

Manager I, Security Engineering - Vulnerability Management
Datadog · New York, New York, USA

Director, WB Games Business Information Security Office
Warner Bros. Discovery · Burbank, California, United States of America

Cyber Security Manager – Operational Technology (OT)
GE Vernova · Rugby

Regional Project Management Lead, Facilities
JLL · North Charleston, SC

Sr. Manager, Cybersecurity Compliance Analyst (Secret Clearance Required)
Raytheon (RTX) · US-CT-FARMINGTON-0004 ~ 4 Farm Springs Rd ~ 4 FARM SPRINGS
Prudential 소개

Prudential
PublicPrudential Financial, Inc. is an American financial services company whose subsidiaries provide insurance, retirement planning, investment management, and other products and services to both retail and institutional customers throughout the United States and in over 40 other countries.
10,001+
직원 수
Newark
본사 위치
$47B
기업 가치
리뷰
3.5
10개 리뷰
워라밸
4.2
보상
4.0
문화
4.1
커리어
4.0
경영진
3.8
68%
친구에게 추천
장점
Good benefits and comprehensive healthcare coverage
Supportive and collaborative culture
Opportunities for growth and career advancement
단점
Frequent changes in senior leadership and priorities
Ongoing layoffs and job insecurity
Unequal treatment between different employee groups
연봉 정보
1,456개 데이터
Junior/L3
Senior/L5
Junior/L3 · Analyst
121개 리포트
$94,507
총 연봉
기본급
$83,881
주식
-
보너스
$10,626
$61,960
$145,547
면접 경험
5개 면접
난이도
3.0
/ 5
소요 기간
21-35주
면접 과정
1
Application Review
2
HireVue/Video Interview
3
Technical Assessment
4
Final Interview
5
Decision
자주 나오는 질문
Behavioral/STAR
Technical Knowledge
Coding/Algorithm
Past Experience
뉴스 & 버즈
KBC Group NV Buys 76,461 Shares of Prudential Financial, Inc. $PRU - MarketBeat
MarketBeat
News
·
1d ago
AE Wealth Management LLC Buys 13,123 Shares of Prudential Financial, Inc. $PRU - MarketBeat
MarketBeat
News
·
1d ago
Diversity and Inclusion above all else?
Hi, I had my first ever Primary PGCE interview this week at a highly-respected university, and my main takeaway was the manner in which DEI was portrayed to be the nucleus of the entire course. I'm just wondering if this is standard for PGCEs now? Of course, Britain is an increasingly diverse nation, something which I personally like (albeit something I don't attach positive or negative objective value to). I expected diversity and inclusion to be mentioned, but I didn't expect it to be the main
·
2d ago
·
3
·
92
Prudential Regulation Authority Business Plan 2026/27 - Bank of England
Bank of England
News
·
2d ago