Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Lead Systems Engineer, Secrets and Vault Engineering

$149.4k - $180k

Intercontinental Exchange

Overview

Job Purpose

The Lead Systems Engineer joins our Secrets and Vault Engineering team within Identity and Access Management. The team is responsible for the platforms and services that protect secrets, certificates, encryption keys, and machine identity across the enterprise - a foundational layer that nearly every application at ICE depends on.

This is a hands-on engineering role with a strong design and architecture component. The ideal candidate has built or operated a HashiCorp Vault platform in production, writes clean automation code in Python and Ansible, and is comfortable working at the intersection of cryptography, identity, and platform engineering. You will help shape how the next generation of our secrets and machine-identity services are built, including emerging areas such as workload identity for AI and agentic workloads, policy-as-code, and proactive non-human identity governance.

We are looking for someone who can move fluidly between writing the code, designing the system, and explaining the trade-offs to stakeholders. You should be the kind of engineer who pushes back on a design when there's a better way, and who can mentor others through the why, not just the how.

What You'll Gain

This role offers direct, hands-on exposure to areas that few enterprise engineering teams are working on in earnest today:

  • Post-quantum cryptography (PQC). You'll be part of the team thinking through how an enterprise cryptography platform evolves to meet PQC readiness, including algorithm migration strategies, key lifecycle implications, and the operational realities of running hybrid classical/post-quantum systems at scale.

  • Agentic and AI workload identity. As AI agents and machine-driven workflows become first-class citizens in the enterprise, the question of how they authenticate, what they're allowed to do, and how that's governed is largely unsolved. You'll help build that foundation from the ground up - workload identity, dynamic credentials, policy enforcement, and proactive anomaly detection for non-human identities.

  • A platform being designed, not just operated. The team is actively shaping its next-generation architecture rather than maintaining a legacy stack. You'll have meaningful influence on design decisions and the chance to shape patterns the rest of the organization will adopt.

Responsibilities

  • Design, build, and maintain platform services for secrets management, certificate lifecycle, encryption key management, and policy enforcement.

  • Develop automation and tooling in Python and Ansible to streamline operations, enforce security controls, and reduce manual provisioning effort.

  • Contribute to a self-service model for application teams, including golden-pattern templates, declarative manifests, and approval workflows integrated with enterprise systems such as ServiceNow.

  • Collaborate with cross-functional teams (application, infrastructure, security, compliance) to translate requirements into reliable, well-governed services.

  • Help shape the team's roadmap in emerging areas including workload identity (SPIFFE/SPIRE), policy-as-code, and identity controls for AI and machine-driven workloads.

  • Participate in code reviews, design reviews, and architecture discussions; mentor and coach engineers earlier in their career.

  • Contribute to internal documentation, runbooks, and knowledge-sharing.

  • Participate in a light on-call rotation supporting the team's services.

Knowledge and Experience

  • 7+ years of infrastructure, platform, or systems engineering experience.

  • Production experience with HashiCorp Vault - secret engines, authentication methods, policies, and operational concerns. Architect-level depth is not required, but you should have shipped against it and understand how it fits into a broader platform.

  • Strong proficiency in Python and Shell scripting for automation and tooling.

  • Experience with Ansible for configuration management and orchestration.

  • Solid understanding of identity, authentication, and secure communication protocols (TLS, OAuth, OIDC, x.509).

  • Working knowledge of CI/CD tooling (Jenkins, GitHub Actions, GitLab CI, or similar) and Infrastructure-as-Code (Terraform preferred).

  • Experience designing and consuming RESTful APIs.

  • Strong fundamentals in Linux systems.

  • Demonstrated ability to write production-quality code, communicate design trade-offs clearly, and collaborate across teams.

Preferred Knowledge and Experience

  • Bachelor's degree in Computer Science, Engineering, or related field.

  • Experience building or contributing to a self-service Vault, secrets, or cryptography platform.

  • Familiarity with SPIFFE/SPIRE or other workload identity frameworks.

  • Familiarity with policy-as-code tooling such as Open Policy Agent (OPA) or HashiCorp Sentinel.

  • Exposure to AI/ML infrastructure or interest in identity controls for AI and agentic workloads.

  • Awareness of post-quantum cryptography standards (NIST PQC, hybrid key exchange) and their operational implications.

  • Experience with cloud platforms (AWS, GCP, or hybrid environments) and cloud-native secrets services such as AWS Secrets Manager or KMS.

  • Exposure to container platforms (Docker, Kubernetes, OpenShift).

  • Understanding of threat modeling, secrets rotation, secret-zero patterns, and zero trust architectures.

  • Experience in fintech, financial services, mortgage technology, or other regulated and security-sensitive domains.

New York Base Salary Range

The expected base salary for this role, if located in New York, is between $149,400 - 180,000 USD. ?The base salary range does not include Intercontinental Exchange's incentive compensation.? While we provide this range as general guidance, at ICE we compensate employees based on the skillset and experience of the individual. Regular full-time ICE employees are eligible for a suite of competitive employee benefits, including healthcare coverage (medical, dental and vision), a 401(k) plan, life insurance, time off, and paid leave for qualifying circumstances.

#LI-SH3

#LI-ONSITE

Intercontinental Exchange, Inc. is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to legally protected characteristics.

Vacancy posted 9 hours ago
Similar jobs that could be interesting for youBased on the Lead Systems Engineer, Secrets and Vault Engineering in Jacksonville, FL vacancy
  •  ...Qualifications Serco North America seeks a Systems Engineer with hands-on Integration and Testing...  ...teams perform a variety of tasks leading to successful integration, test,...  ...transfer a U.S. Department of War (DoW) Secret security clearance. The Combat Air Force... 
    Suggested
    Full time
    Contract work
    Part time
    For contractors
    Local area
    Immediate start
    Worldwide
    Flexible hours

    Serco

    Jacksonville, FL
    5 days ago
  •  ...Description SAIC is seeking a TACNET CB-ISEA Senior Systems Engineer (Fleet Support) to join our team in Jacksonville, FL . This role...  ...responsibilities. ~ Must be a U.S. Citizen. ~ Must have an Active Secret Clearance to Start. ~ Must be able to obtain a TS/SCI after... 
    Suggested
    Permanent employment
    Work at office
    Local area
    Remote work

    SAIC

    Jacksonville, FL
    2 days ago
  •  ...our team. KPMG is currently seeking a Lead Engineer I, Tech Engineering to join our Ignition...  ...-scale, mission-critical enterprise systems, integrating architecture solutions, and...  ...Azure PaaS services such as Azure SQL, Key Vault, Log Analytics, Storage/Backup, and Application... 
    Suggested
    Local area

    KPMG

    Jacksonville, FL
    5 days ago
  •  ...Combat Systems Port Engineer Job Locations US-FL-Mayport ID 2026-3296 # of...  ...and evaluation. As a CSPE, you will lead a maintenance team and act as the primary...  ...Qualifications Active DoD Secret security clearance is highly desired; however... 
    Suggested
    Work at office

    T-Solutions

    Atlantic Beach, FL
    5 hours ago
  •  ...authorization to proceed. This position is remote and requires an active Secret clearance or higher. Maximus TCS (Technology and Consulting...  ...: - Provides subject matter proficiency supporting system testing activities - Applies analytical skills to support process... 
    Suggested
    Minimum wage
    Full time
    Contract work
    Temporary work
    For contractors
    Work experience placement
    Remote work

    Maximus

    Jacksonville, FL
    5 days ago
  •  ...About Our Client Our client, the leading material handling provider in the Southeast, has helped customers in Florida and Georgia...  ...The company's core business is forklifts and service, while the systems division focuses on full warehouse design and installation with... 
    Work at office
    Local area
    Remote work
    Relocation package
    3 days per week

    Naviga

    Jacksonville, FL
    1 day ago
  • $100k - $130k

     ...Transit Systems Engineer Application Deadline: 31 July 2026 Department: Engineering Employment Type: Full Time Location: MRS -- Jacksonville Compensation: $100,000 - $130,000 / year Description The Systems Engineer provides systemwide design... 
    Full time
    Contract work
    For contractors
    For subcontractor
    Work at office

    Stacy Witbeck

    Jacksonville, FL
    2 days ago
  •  ...RailPros is the premier provider of engineering and diversified safety services to America...  ...of railroad signaling and communications systems. This role works under the supervision of...  ...managers and other technical discipline leads. External Relationships ~ General... 
    Full time
    Temporary work
    For contractors
    For subcontractor
    Work at office
    Flexible hours

    Railpros

    Jacksonville, FL
    5 days ago
  • $70.24 per hour

     ...Senior Mac Systems Engineer responsible for the design, build, and lifecycle management of Microsoft 365 endpoint clients on macOS. This role...  ...TEKsystems and TEKsystems Global Services We're a leading provider of business and technology services. We accelerate business... 
    Contract work
    Temporary work

    TEKsystems

    Jacksonville, FL
    2 days ago
  •  ...System Engineer The System Engineer defines the specification, the architecture, and the interfaces of the product to satisfy customer requirements. They are responsible for performance/technical requirements of the product and their implementation into sub-systems.... 

    Pinnacle Professional Services

    Jacksonville, FL
    5 days ago
  • $60k - $85k

    Description Senior Systems Engineer Base Salary: $60,000.00 to $85,000.00 depending on experience. Position will include commission opportunity. Toshiba America Business Solutions, a leader in digital technology, is seeking a Senior Systems Engineer working remotely... 
    Remote work

    Toshiba America Business Solutions

    Jacksonville, FL
    9 hours ago
  • $70.2 per hour

     ...We are seeking a Mac Systems Engineer with 5+ years of experience managing macOS in secure, enterprise environments. This role focuses on building, maintaining, and optimizing large-scale Mac ecosystems with an emphasis on security, automation, and performance. The ideal... 
    Remote work

    Insight Global

    Jacksonville, FL
    4 days ago
  •  ...RailPros is the premier provider of engineering and diversified safety services to America...  ...journey! Job Summary The Rail Systems Engineer III performs advanced...  ..., and interface control documents. Lead development of test procedures for factory... 
    Temporary work
    For contractors
    For subcontractor
    Work at office
    Flexible hours

    Railpros

    Jacksonville, FL
    8 hours ago
  •  ...Systems Engineer Power the future of Space at Star Catcher Star Catcher is powering the future of space by building the world's first...  ...Network, its orbital power grid. This role will be responsible for leading and overseeing the development, integration, and testing of... 
    Permanent employment

    Star Catcher

    Jacksonville, FL
    9 hours ago
  •  ...As a leading financial services and healthcare technology company based on revenue, SS&C is headquartered in Windsor, Connecticut...  ...scale, and technology. Job Description Job Title: CPQ Systems Engineer Location : Jacksonville, FL | Hybrid Get To Know Us:... 
    Ongoing contract
    Casual work
    Flexible hours

    SS&C Technologies

    Jacksonville, FL
    4 days ago
  •  ...Hybrid Jacksonville, FL Schedule: Monday-Friday 8-5 What work will you perform? You will be part of a team of Sr. Systems Engineers that supports and monitors mission critical infrastructure and web/mobile applications based on prem and in the cloud. Providing... 
    Local area
    Monday to Friday

    Landstar

    Jacksonville, FL
    4 days ago
  •  ...Jconnect INC . Below is the requirement with my client. Please let me know if you are available for this role. Title: Middleware Engineer / System Engineer Location : Jacksonville, FL Duration: Fulltime JOB DESCRIPTION : Middleware Engineer... 
    Full time
    Immediate start
    Relocation

    3B Staffing LLC

    Jacksonville, FL
    5 days ago
  •  ...Middleware Engineer / System Engineer Middleware Engineer / System Engineer Location: Jacksonville, FL Duration: Fulltime Job Description: Middleware Engineer / System Engineer Experience with deployment tools such as BladeLogic, Ansible, Terraform, Puppet... 
    Full time
    Immediate start
    Relocation

    JConnect Infotech

    Jacksonville, FL
    1 day ago
  • $155k - $410k

     ...At PwC, our people in data and analytics engineering focus on leveraging advanced...  ...and optimising algorithms, models, and systems to enable intelligent decision-making and...  ...knowledge, and experiences you need to lead and deliver value at this level include... 
    Full time
    Temporary work
    H1b

    PwC

    Jacksonville, FL
    1 day ago
  •  ...Foth is a 100% member-owned science and engineering consulting firm headquartered in Wisconsin, with over 85 years of success. Our 750 members...  ..., and forward-thinkers. We're currently on the lookout for a Lead Coastal Engineer who's not only passionate about coastal and... 
    Contract work
    Remote work
    Flexible hours

    Foth

    Jacksonville, FL
    4 days ago
  •  ...company, is a highly innovative surveying and engineering company with over 60 years of industry...  ...team. About The Role: As a Lead Engineer, you will provide leadership and...  ...extra high-voltage (EHV) overhead utility systems. Some of the main responsibilities... 
    Temporary work
    For subcontractor
    Flexible hours

    ESP Associates

    Jacksonville, FL
    4 days ago
  • $124k - $280k

     ...At PwC, our people in data and analytics engineering focus on leveraging advanced...  ...and optimising algorithms, models, and systems to enable intelligent decision-making and...  ...knowledge, and experiences you need to lead and deliver value at this level include... 
    Full time
    H1b

    PwC

    Jacksonville, FL
    5 days ago
  •  ...looking for a Development Manager / Technical Lead to join our IT team. As part of the IT...  ...a row, Moffatt & Nichol is Ranked #1 in Engineering News-Record for Marine & Port Facilities...  ..., Software Engineering, Information Systems, or a related field, or an equivalent combination... 
    For contractors
    Worldwide

    Moffatt & Nichol

    Jacksonville, FL
    3 days ago
  • $90 - $105 per hour

     ...Sr TechOps & SRE Lead Engineer (AWS Cloud) Department: Technology / Engineering Role...  ...architectures, improving automation, ensuring system reliability, and leading the TechOps...  ...-privilege access controls. # Manage secrets and key management (AWS KMS, Secrets Manager... 
    Full time
    Remote work

    Simple Solutions

    Jacksonville, FL
    a month ago
  •  ...Linux System Engineer Immediate need for a talented Linux System Engineer. This is a 12 Months Contract opportunity with long-term potential...  ...and written communication skills Our client is a leading Banking and Financial Industry and we are currently interviewing... 
    Contract work
    Local area
    Immediate start
    Flexible hours
    Weekend work

    Pyramid Consulting

    Jacksonville, FL
    2 days ago
  • Description Wunderlich-Malec Engineering (WM) is a 100% employee-owned ESOP and one of the largest and most well-established...  ...News Record) Top 500 firm ~ Rated as a top System Integrator Giant We have a Lead Commissioning Engineer opportunity available in Jacksonville... 
    Full time
    Temporary work
    Remote work
    Worldwide
    Flexible hours

    Wunderlich-Malec Engineering

    Jacksonville, FL
    2 days ago
  • $101.9k - $150k

     ...that help learners achieve their goals and lead a choice-filled life. Our culture...  ...What you'll do here: As the Software Engineering Manager, you will lead a team dedicated...  ...or monolithic architectures, migrating systems to modular, cloud-native platforms, and... 
    Work experience placement
    Live in
    Local area
    Remote work
    Worldwide

    Cengage Group

    Jacksonville, FL
    9 hours ago
  • $124k - $280k

     ...At PwC, our people in data and analytics engineering focus on leveraging advanced...  ...and optimising algorithms, models, and systems to enable intelligent decision-making and...  ...knowledge, and experiences you need to lead and deliver value at this level include... 
    Full time
    H1b

    PwC

    Jacksonville, FL
    2 days ago
  •  ...Software Systems Engineer III We are seeking an experienced Software Systems Engineer III to join our cloud data engineering team. This senior...  ...data solutions using modern cloud technologies. You will lead the hands-on design and development of complex data pipelines,... 

    ECA Staffing Solutions, Inc.

    Jacksonville, FL
    4 days ago
  • A leading aerospace company is seeking a Lead Technical Program Manager in Jacksonville, Florida. This role requires at least 8 years in technical program management, focusing on product development in a collaborative environment. The ideal candidate will demonstrate strong... 
    Remote work

    Otto Aviation

    Jacksonville, FL
    22 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Lead Systems Engineer, Secrets and Vault Engineering. Be the first to apply!