Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Lead Systems Engineer, Secrets and Vault Engineering

$149.4k - $180k

Intercontinental Exchange

Overview

Job Purpose

The Lead Systems Engineer joins our Secrets and Vault Engineering team within Identity and Access Management. The team is responsible for the platforms and services that protect secrets, certificates, encryption keys, and machine identity across the enterprise - a foundational layer that nearly every application at ICE depends on.

This is a hands-on engineering role with a strong design and architecture component. The ideal candidate has built or operated a HashiCorp Vault platform in production, writes clean automation code in Python and Ansible, and is comfortable working at the intersection of cryptography, identity, and platform engineering. You will help shape how the next generation of our secrets and machine-identity services are built, including emerging areas such as workload identity for AI and agentic workloads, policy-as-code, and proactive non-human identity governance.

We are looking for someone who can move fluidly between writing the code, designing the system, and explaining the trade-offs to stakeholders. You should be the kind of engineer who pushes back on a design when there's a better way, and who can mentor others through the why, not just the how.

What You'll Gain

This role offers direct, hands-on exposure to areas that few enterprise engineering teams are working on in earnest today:

  • Post-quantum cryptography (PQC). You'll be part of the team thinking through how an enterprise cryptography platform evolves to meet PQC readiness, including algorithm migration strategies, key lifecycle implications, and the operational realities of running hybrid classical/post-quantum systems at scale.

  • Agentic and AI workload identity. As AI agents and machine-driven workflows become first-class citizens in the enterprise, the question of how they authenticate, what they're allowed to do, and how that's governed is largely unsolved. You'll help build that foundation from the ground up - workload identity, dynamic credentials, policy enforcement, and proactive anomaly detection for non-human identities.

  • A platform being designed, not just operated. The team is actively shaping its next-generation architecture rather than maintaining a legacy stack. You'll have meaningful influence on design decisions and the chance to shape patterns the rest of the organization will adopt.

Responsibilities

  • Design, build, and maintain platform services for secrets management, certificate lifecycle, encryption key management, and policy enforcement.

  • Develop automation and tooling in Python and Ansible to streamline operations, enforce security controls, and reduce manual provisioning effort.

  • Contribute to a self-service model for application teams, including golden-pattern templates, declarative manifests, and approval workflows integrated with enterprise systems such as ServiceNow.

  • Collaborate with cross-functional teams (application, infrastructure, security, compliance) to translate requirements into reliable, well-governed services.

  • Help shape the team's roadmap in emerging areas including workload identity (SPIFFE/SPIRE), policy-as-code, and identity controls for AI and machine-driven workloads.

  • Participate in code reviews, design reviews, and architecture discussions; mentor and coach engineers earlier in their career.

  • Contribute to internal documentation, runbooks, and knowledge-sharing.

  • Participate in a light on-call rotation supporting the team's services.

Knowledge and Experience

  • 7+ years of infrastructure, platform, or systems engineering experience.

  • Production experience with HashiCorp Vault - secret engines, authentication methods, policies, and operational concerns. Architect-level depth is not required, but you should have shipped against it and understand how it fits into a broader platform.

  • Strong proficiency in Python and Shell scripting for automation and tooling.

  • Experience with Ansible for configuration management and orchestration.

  • Solid understanding of identity, authentication, and secure communication protocols (TLS, OAuth, OIDC, x.509).

  • Working knowledge of CI/CD tooling (Jenkins, GitHub Actions, GitLab CI, or similar) and Infrastructure-as-Code (Terraform preferred).

  • Experience designing and consuming RESTful APIs.

  • Strong fundamentals in Linux systems.

  • Demonstrated ability to write production-quality code, communicate design trade-offs clearly, and collaborate across teams.

Preferred Knowledge and Experience

  • Bachelor's degree in Computer Science, Engineering, or related field.

  • Experience building or contributing to a self-service Vault, secrets, or cryptography platform.

  • Familiarity with SPIFFE/SPIRE or other workload identity frameworks.

  • Familiarity with policy-as-code tooling such as Open Policy Agent (OPA) or HashiCorp Sentinel.

  • Exposure to AI/ML infrastructure or interest in identity controls for AI and agentic workloads.

  • Awareness of post-quantum cryptography standards (NIST PQC, hybrid key exchange) and their operational implications.

  • Experience with cloud platforms (AWS, GCP, or hybrid environments) and cloud-native secrets services such as AWS Secrets Manager or KMS.

  • Exposure to container platforms (Docker, Kubernetes, OpenShift).

  • Understanding of threat modeling, secrets rotation, secret-zero patterns, and zero trust architectures.

  • Experience in fintech, financial services, mortgage technology, or other regulated and security-sensitive domains.

New York Base Salary Range

The expected base salary for this role, if located in New York, is between $149,400 - 180,000 USD. ?The base salary range does not include Intercontinental Exchange's incentive compensation.? While we provide this range as general guidance, at ICE we compensate employees based on the skillset and experience of the individual. Regular full-time ICE employees are eligible for a suite of competitive employee benefits, including healthcare coverage (medical, dental and vision), a 401(k) plan, life insurance, time off, and paid leave for qualifying circumstances.

#LI-SH3

#LI-ONSITE

Intercontinental Exchange, Inc. is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to legally protected characteristics.

Vacancy posted 20 hours ago
Similar jobs that could be interesting for youBased on the Lead Systems Engineer, Secrets and Vault Engineering in New York, NY vacancy
  • $149.4k - $180k

     ...Lead Systems Engineer The Lead Systems Engineer joins our Secrets and Vault Engineering team within Identity and Access Management. The team is responsible for the platforms and services that protect secrets, certificates, encryption keys, and machine identity across... 
    Suggested
    Full time
    Immediate start

    Intercontinental Exchange Holdings, Inc.

    New York, NY
    4 days ago
  • $149.4k - $180k

    Intercontinental Exchange Holdings, Inc. is hiring a Lead Systems Engineer for their New York office. This hands-...  ...robust security systems that manage secrets, certificates, and machine identities....  ...technologies such as HashiCorp Vault, post-quantum cryptography, and AI... 
    Suggested
    Work at office

    Intercontinental Exchange Holdings, Inc.

    New York, NY
    3 days ago
  • Precision Solutions, Inc. is hiring a Systems Engineer to work onsite at Tinker AFB, Oklahoma. The role involves leading engineering projects to enhance U.S. Air Force missions...  ...and a relevant Bachelor's degree. An Active Secret security clearance is required. Join us to... 
    Suggested

    Precision Solutions, Inc.

    Brooklyn, NY
    4 days ago
  • A leading defense support organization seeks skilled engineers to enhance submarine shipbuilding processes and support NAVSEA programs. Candidates should have extensive...  ...with a BS/BA degree in a technical field and a secret security clearance. This role involves design,... 
    Suggested

    International Executive Service Corps

    New York, NY
    3 days ago
  •  ...solutions provider is seeking a C-UAS Engineer to lead test and evaluation projects for a DHS...  ...management, engineering support for C-UAS systems, and collaboration with federal...  ...requires U.S. citizenship and the ability to obtain a Secret clearance. #J-18808-Ljbffr LMI
    Suggested

    LMI

    New York, NY
    4 days ago
  •  ...Responsibilities & Qualifications We are seeking a Software Systems Engineer. Required Qualifications 5+ years relevant experience Certifications...  ...from a nationally recognized technical authority Clearance Secret IT II Responsibilities Formulates/defines specifications for... 
    Contract work
    Temporary work
    Remote work
    Monday to Friday
    Weekend work
    Day shift
    Afternoon shift

    TekSynap

    New York, NY
    2 days ago
  • $115.1k - $175k

     ...This Opportunity WSP is currently initiating a search for a Lead Technology Systems Engineer, with the potential to work out of any WSP office, which includes Dallas, TX; Virginia Beach, VA; New York City, NY; Arlington, VA; Denver, CO; Chicago, IL; San Diego, CA... 
    Work at office
    Local area
    Flexible hours

    WSP

    New York, NY
    19 hours ago
  •  ...TekSynap is seeking a Software Systems Engineer to develop and maintain complex operating software applications. The position is primarily...  ...experience and possess certifications such as IAT Level I and Secret IT II clearance. Benefits include health, dental, vision, 401... 
    Remote work

    TekSynap

    New York, NY
    2 days ago
  • $175k - $200k

     ...Trexquant is looking for a senior technologist to lead the design and evolution of our core...  ...and building scalable, low-latency systems in Linux environments, collaborating closely with quantitative researchers & engineers, and driving next-generation simulation and... 
    Casual work

    Trexquant Investment

    New York, NY
    2 days ago
  •  ...onsite Tuesdays, Wednesdays and a third day unique to each team or employee). The Impact you will have in this role: The Lead System Engineer (Windows OS Operations, Private Cloud) is a critical role responsible for the stability, security, and long-term evolution... 
    Remote work
    Flexible hours

    Dtcc

    Jersey City, NJ
    2 days ago
  • Penn State University is seeking a Principal Electro-Optic and Infrared (EO/IR) Systems Engineer in Freeport, PA. This role involves leading research for DoD acquisitions, developing performance models, and managing projects related to imaging systems. The ideal candidate... 

    Penn State University

    New York, NY
    3 days ago
  • ATS+Partners is looking for a seasoned manager to oversee Mainframe Systems in New York. This leadership role involves managing the daily...  ...should have substantial experience in IT infrastructure engineering, excellent communication skills, and a proactive problem-solving... 

    ATS+Partners

    New York, NY
    13 hours ago
  • $174k - $215k

    Why Hover wants you Hover's GTM Systems team owns the full technical stack powering how our Sales, Marketing, and CX organizations operate...  ...— and we're growing it. This is a net new role for a senior engineer who wants breadth and ownership in equal measure: someone who... 
    Full time
    Work at office
    Local area
    Flexible hours

    HOVER

    New York, NY
    1 day ago
  • $120k - $150k

    A technology solutions company in New Jersey seeks an experienced Engineering Manager to lead and mentor a team, manage multimillion dollar integration projects, and ensure client satisfaction. Required qualifications include 10+ years in A/V with strong leadership and... 

    AVI-SPL, Inc.

    New York, NY
    3 days ago
  • AVI-SPL, Inc. is seeking a professional to oversee the final testing and commissioning of complex audio-visual systems. The role requires working closely with the Project Manager and includes troubleshooting, system testing, and client interaction. Candidates must have... 

    AVI-SPL, Inc.

    New York, NY
    2 days ago
  • $144.2k - $288.4k

     ...this platform sits at the core of our ability to serve patients, members, and customers reliably and securely. The Lead Director - Mainframe Systems Engineer is a senior leadership position, not a hands‑on engineering role. In this Executive role, you will set strategic... 
    Hourly pay
    Full time
    Contract work
    Temporary work
    For contractors
    Local area

    Hispanic Alliance for Career Enhancement

    New York, NY
    3 days ago
  • $156.5k - $181k

     ...OVERVIEW The Company U.S. Financial Technology (U.S. FinTech) is seeking an experienced Lead Cloud Systems Engineer (Microsoft 365, AWS, Collaboration Tools) to join our team of talented professionals. This is a full-time remote opportunity. U.S. FinTech built and operates... 
    Full time
    H1b
    Work at office
    Local area
    Remote work

    U.S. Financial Technology

    New York, NY
    2 days ago
  •  ...Lead Systems Engineer (Rust) - AI Platform About the Role What if your deep Rust expertise could directly shape the infrastructure powering the next generation of AI? We're looking for a Senior Rust Full-Stack Engineer to build and optimize the high-performance... 
    Hourly pay
    Ongoing contract
    Contract work
    Remote work

    Alignerr

    New York, NY
    2 days ago
  •  ...quality technology on new and legacy DoD systems. This includes avionics, mission LRU's, flight...  ...System level and LRU Architectures. Lead the development of CONOPS, develop requirements, allocate requirements to engineering teams, and test LRU/Systems. Guide multi-... 

    Southwest Research Institute

    Brooklyn, NY
    1 day ago
  •  ...other passionate professionals who share your drive and commitment to making a difference through technology. The Lead Unix/Linux Systems Engineer will provide technical support and administration of Unix, Linux, and AIX servers across various New York City agencies... 
    Permanent employment
    Full time
    Work at office
    Shift work
    Night shift
    Weekend work
    Afternoon shift

    CITY OF NEW YORK INC

    Brooklyn, NY
    5 days ago
  •  ...Lead Unix/Linux Systems Engineer The Office of Technology and Innovation (OTI) leverages technology to drive opportunity, improve public safety, and help government run better across New York City. From delivering affordable broadband to protecting against cybersecurity... 
    Work at office

    New York City | Jobs

    Brooklyn, NY
    1 day ago
  •  ...seeking a Technical Project Leader in New York to lead the development and scale-up of complex...  ...ideal candidate will have a strong background in engineering with at least 8 years of experience in process or systems engineering. Key responsibilities include leading... 

    Corning Inc.

    New York, NY
    13 hours ago
  • Portfolio BI, Inc. is looking for a seasoned Sr. System Engineer to provide onsite technical leadership for a high-profile client in financial services. You will be the trusted advisor on technology, ensuring the reliability and security of their infrastructure while driving... 
    Full time

    Portfolio BI, Inc.

    New York, NY
    13 hours ago
  • $119.9k - $199.8k

    Sr Platform Engineer page is loaded## Sr Platform Engineerlocations...  ...scalable, performant systems across Google Cloud...  ...reduce toil.* Standardize IaC: Lead the development, versioning...  ...Secure the Platform: Integrate secrets management (HashiCorp Vault or cloud-native managers)... 
    Worldwide

    CME Group Inc.

    New York, NY
    2 days ago
  • $157k - $200k

     ...employees - and aim to leave a positive mark on culture. Overview As a Lead Software Engineer, you will be tasked with key areas of Paramount Streaming's content management systems. You will design systems and collaborate closely with your peers, product managers... 
    Contract work

    Paramount

    New York, NY
    4 days ago
  •  ...A leading government contractor is seeking a qualified Principal Software Developer to support Army analytics work in Fairfield, CA....  ...proficiency in languages like Java and Python, and an active DOD Secret clearance. Responsibilities include designing high-quality code... 
    For contractors

    ASRC Federal Holding Company

    New York, NY
    2 days ago
  •  ...HR1Systems is seeking a Software Engineer Supervisor to lead a team in developing scalable software solutions utilizing machine learning and AI. The ideal candidate will have over 5 years of software development experience and strong leadership skills. Responsibilities... 
    Remote work

    Kids For The Future

    New York, NY
    2 days ago
  • $229.9k - $262.4k

     ...Senior Lead Software Engineer, Distributed Systems (Golang + Python on Kubernetes) Do you love building and pioneering in the technology space? Do you enjoy solving complex business problems in a fast-paced, collaborative, inclusive, and iterative delivery environment... 
    Full time
    Part time
    Internship
    Local area

    Capital One

    New York, NY
    13 hours ago
  •  ...Lead Software Engineer Be an integral part of an agile team that's constantly pushing the envelope to enhance, build, and deliver top-notch...  ...overall operational stability of software applications and systems Leads evaluation sessions with external vendors,... 

    Chase

    Jersey City, NJ
    2 days ago
  • $114k - $165.3k

     ...employment visa at this time, including CPT/OPT.*** What you will do Lead cross-functional reliability initiatives across multiple value...  ...pipeline-as-code and progressive delivery at scale. Lead chaos engineering, game days, and systematic reliability testing initiatives.... 
    16 hours
    Contract work
    Temporary work
    Work experience placement
    Casual work
    Work at office
    Local area
    Remote work
    Work from home
    Work visa
    Flexible hours

    Hispanic Alliance for Career Enhancement

    New York, NY
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Lead Systems Engineer, Secrets and Vault Engineering. Be the first to apply!