Logo for Invicta Solutions Group

Senior HashiCorp Architect and Implementation Consultant

Role overview

Qualifications

  • 8+ years of cybersecurity, identity, cloud security, platform engineering, or secrets-management experience
  • 5+ years of hands-on HashiCorp Vault architecture and implementation experience in enterprise environments
  • Experience integrating Vault with Kubernetes, cloud platforms, enterprise identity providers, applications, databases, and CI/CD systems
  • HashiCorp Certified: Vault Associate certification

Responsibilities

  • Lead the architecture, design, and implementation of HashiCorp Vault Enterprise across cloud, hybrid, containerized, and on-premises environments
  • Define the Vault operating model, including namespaces, authentication methods, secrets engines, policies, identity entities and groups
  • Design highly available and resilient Vault deployments, including integrated storage, clustering, performance replication, disaster recovery replication
  • Implement workload identity patterns for applications, Kubernetes and OpenShift workloads

Key facts

Other skills

  • Presentations
  • Troubleshooting (Problem Solving)
  • Consulting

About the company

Invicta Solutions Group logo

Invicta Solutions Group

IT Services & IT Consulting

We are the tool chest for working CISO’s. Process, platforms, and people that simplify business technology security.Challenges with cyber security operations, cloud security, resource management, or technology selection are resolved with our mix of uniquely qualified staff or through our formal partner network.Our ISO 9001 certified, SDVOSB, HUBZone organization offers strategic and tactical solutions to both commercial enterprises and federal contractors. Invicta Solutions Group provides resource expertise in cloud security, cybersecurity, and emerging technologies. With a mature business model, past performance, and technical certifications we help Prime Contractors achieve small business goals while delivering projects on time and on budget.

Company details

Company typeScaleup
IndustryIT Services & IT Consulting
Company size11 - 50

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

This is a remote position.

Position Summary

We are seeking a Senior HashiCorp Architect and Implementation Consultant to design and implement enterprise-grade HashiCorp Vault solutions supporting secure workload identity, privileged access, dynamic credential delivery, Kubernetes platforms, and AI and agentic application security. This consultant will serve as the HashiCorp technical lead for an integrated Enterprise Trust Operating Model (ETOM) implementation, with particular responsibility for agentic identity, delegated authority, MCP/API enforcement, controlled credential injection, and end-to-end provenance. The role combines architecture leadership, hands-on configuration, systems integration, testing, documentation, knowledge transfer, and operational readiness.

Primary Responsibilities

  • Lead the architecture, design, and implementation of HashiCorp Vault Enterprise across cloud, hybrid, containerized, and on-premises environments.
  • Define the Vault operating model, including namespaces, authentication methods, secrets engines, policies, identity entities and groups, tenancy boundaries, and administrative responsibilities.
  • Design highly available and resilient Vault deployments, including integrated storage, clustering, performance replication, disaster recovery replication, backup, recovery, and upgrade strategies.
  • Implement workload identity patterns for applications, Kubernetes and OpenShift workloads, CI/CD pipelines, service accounts, agents, gateways, and enterprise agent runtimes.
  • Configure dynamic and short-lived credentials for downstream databases, cloud platforms, SaaS services, infrastructure systems, and other protected resources.
  • Design contextual credential-release policies that evaluate workload identity, delegated authority, transaction context, approval state, requested action, target resource, and risk signals.
  • Integrate Vault with enterprise identity providers, IBM Verify or comparable identity platforms, cloud IAM services, Kubernetes, API gateways, MCP gateways, and agentic application platforms.
  • Design agentic identity patterns that establish and preserve the identities of the initiating user, AI agent, delegated subagent, tool, runtime, and target resource across the complete transaction path.
  • Implement delegated-authority and token-exchange patterns that bind user intent, approved scope, transaction context, requested MCP tool or API operation, target resource, and approval state to Vault policy decisions.
  • Architect MCP and API enforcement controls, including request normalization, gateway validation, policy enforcement points, direct-target bypass prevention, rejection of caller-supplied credentials, and fail-closed execution behavior.
  • Secure AI and agentic workloads running on Kubernetes and OpenShift using service accounts, projected tokens, Kubernetes authentication, Vault Agent Injector, Secrets Store CSI Driver, namespaces, network controls, and workload-attested identity.
  • Integrate Vault with enterprise AI platforms, agent runtimes, MCP clients and servers, API gateways, model-serving environments, and custom Python, TypeScript, or LangGraph-based agent frameworks.
  • Implement controlled credential-delivery and injection patterns that prevent credentials from being exposed to users, agents, subagents, application code, logs, or unapproved execution paths.
  • Design and test fail-closed enforcement, lease expiration, token and credential revocation, emergency kill paths, and scoped response procedures.
  • Configure Vault audit devices and integrate audit evidence with SIEM, observability, incident-response, and compliance-reporting platforms.
  • Develop infrastructure-as-code, policy-as-code, automated configuration, testing, and deployment patterns using Terraform and approved DevSecOps tooling.
  • Lead technical workshops, architecture reviews, implementation sprints, troubleshooting sessions, and production-readiness assessments with client stakeholders.
  • Produce architecture diagrams, configuration standards, deployment runbooks, test plans, operational procedures, and administrator and developer guidance.
  • Provide knowledge transfer and mentor client security, platform, cloud, DevOps, application, and operations teams.

Required Technical Skills

  • HashiCorp Vault Enterprise architecture, implementation, administration, and troubleshooting
  • Vault authentication methods, identity system, tokens, leases, policies, namespaces, and secrets engines
  • Dynamic database and cloud credentials, PKI, transit encryption, key management, and credential brokering
  • Vault Agent, Agent Injector, Secrets Store CSI Driver, Kubernetes authentication, and workload identity
  • Integrated Storage, high availability, performance replication, disaster recovery replication, backup, and recovery
  • Terraform, HCL, REST APIs, CLI automation, and policy-as-code
  • Kubernetes and OpenShift security and platform integration
  • Cloud IAM and secrets-management integration across AWS, Microsoft Azure, and Google Cloud
  • Enterprise identity federation using OIDC, OAuth 2.0, JWT, SAML, LDAP, and related identity standards
  • API gateways, service-to-service security, MCP or agent-tool enforcement, and controlled credential injection
  • AI and agentic security architecture, including agent identity, subagent delegation, human-in-the-loop approval, tool authorization, decision lineage, and secure runtime integration
  • MCP clients, servers, gateways, routers, registries, tool catalogs, request normalization, policy enforcement, and secure tool-execution patterns
  • API security and enforcement using OAuth 2.0, OIDC, JWT, token exchange, mTLS, workload identity, fine-grained authorization, gateway policy, and service-mesh controls
  • Kubernetes security architecture, including service accounts, projected service-account tokens, RBAC, admission controls, network policies, sidecar and CSI injection patterns, and multi-cluster workload identity
  • AI platform integration across enterprise agent runtimes, model gateways, orchestration frameworks, and custom agent applications
  • Audit logging, SIEM integration, observability, incident response, and compliance evidence
  • Linux administration, networking, TLS, certificates, load balancing, and enterprise infrastructure architecture

Required Experience

  • 8+ years of cybersecurity, identity, cloud security, platform engineering, or secrets-management experience.
  • 5+ years of hands-on HashiCorp Vault architecture and implementation experience in enterprise environments.
  • Demonstrated experience leading at least two production Vault implementations or major enterprise expansions.
  • Experience designing highly available, multi-environment, and disaster-recovery Vault architectures.
  • Experience integrating Vault with Kubernetes, cloud platforms, enterprise identity providers, applications, databases, and CI/CD systems.
  • Hands-on experience securing AI or agentic systems, including agent identity, delegated authority, MCP tool use, API enforcement, and controlled access to downstream credentials.
  • Experience implementing Vault in Kubernetes or OpenShift using Kubernetes authentication, Vault Agent Injector, Secrets Store CSI Driver, service accounts, Helm, operators, and infrastructure-as-code.
  • Experience integrating Vault with MCP gateways, API gateways, service meshes, agent runtimes, or custom AI orchestration frameworks is strongly preferred.
  • Experience implementing dynamic credentials, workload identity, least-privilege access, credential rotation, and revocation.
  • Experience developing Terraform automation, reusable deployment patterns, test plans, and operational runbooks.
  • Ability to facilitate executive and technical workshops and translate security requirements into implementable architecture.
  • Excellent documentation, presentation, troubleshooting, and client-facing consulting skills.

Preferred Qualifications

  • HashiCorp Certified: Vault Associate certification; advanced HashiCorp or Terraform credentials are preferred.
  • Experience with IBM Verify, enterprise privileged-access management, certificate lifecycle management, HSMs, or external key-management systems.
  • Experience securing agentic AI platforms, MCP clients and servers, agent gateways, or automated tool-execution environments.
  • Experience with regulated or high-assurance environments such as financial services, healthcare, government, or critical infrastructure.
  • Familiarity with Zero Trust Architecture, NIST guidance, identity threat modeling, and secure software delivery practices.

Ideal Candidate Profile

The ideal consultant combines deep HashiCorp Vault expertise with strong enterprise architecture, implementation, Kubernetes, API security, and AI security capabilities. They can move confidently from whiteboard design to production configuration, explain complex human-to-agent-to-subagent identity and credential flows to both executives and engineers, and implement enforceable controls across Vault, Kubernetes, MCP gateways, API gateways, and agent runtimes. They understand how to preserve actor lineage and delegated authority, bind approval and intent to credential release, prevent bypass and caller-supplied credentials, and provide end-to-end evidence and scoped revocation. Success in this role requires disciplined security engineering, transparent documentation of assumptions and dependencies, a strong focus on least privilege and fail-closed behavior, and the ability to deliver a supportable solution that client teams can operate after transition.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Consultant Related jobs

Other jobs at Invicta Solutions Group

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.