Arctiq
Sr. Vault Specialist (HashiCorp)
Montreal, Quebec · Senior · Full-time
Sponsorship not specifiedDetected 45 days ago
Code ReviewGitAWSGCPAzureTerraformCI/CDGitHub ActionsCybersecurityIncident ResponseAgileCadenceVPNMentoring
About the role
- Consumers raise a ticket in ServiceNow that triggers a GitHub Actions pipeline.
- Migrating consumer teams from static to dynamic is not in this role's scope; that work sits with the domain teams themselves.
- Ship changes through the team's GitHub Actions pipeline; almost never through the Vault UI.
Responsibilities
- Keep the self-service endpoint healthy as more consumer teams onboard, refactoring so each new team is a configuration change rather than a custom build.
- Mentor and pair with junior engineers in a way that can be shadowed: explain the reasoning, document the patterns, and make decisions deliberately so the next engineer can replicate the approach instead of guessing.
- Drive assigned goals to completion, aligning execution with the product and domain architects above and translating that alignment into the work the team actually ships.
Requirements
- If French is primary, English at CEFR C1 (advanced) is required.
- If English is primary, native-level or C1+ English is required.
- Must be able to read dense HashiCorp Vault, Terraform, CI/CD pipeline, and cloud-provider documentation
- Both are required.
- Production HashiCorp Vault experience at senior level: hands-on ownership of secret engines, policies, and auth methods on a platform other teams depend on.
- Direct experience with the static-to-dynamic secrets shift: dynamic-secret engines (databases, cloud IAM, PKI, or similar) in production, not just in a lab.
- Required:
- Fluent reading Vault audit logs and acting on them.
- Strong Terraform practitioner, configuring Vault and adjacent platforms through IaC
- reviewing other engineers' Terraform with an eye for safety and drift.
- CI/CD-driven workflow experience (GitHub Actions, GitLab CI, or equivalent)
- can debug a pipeline failure end-to-end.
- Incident handling on a critical platform after tier-1 and tier-2 triage, with the judgment to decide what gets fixed now, what gets hardened later, and what gets documented for the next responder.
- Mentoring junior engineers in a way that can be shadowed: explaining reasoning, documenting patterns, and making deliberate decisions others can replicate.
- Drives assigned goals to completion in agile/scrum and aligns execution with product and domain architects, without needing strategy set at the task level.
- Language profile matching the header: primary working language in Quebec French, International French, or English
Nice to have
- HashiCorp Vault Associate or Operations Professional certification, or equivalent demonstrable depth (talks, contributions, internal write-ups).
- Adjacent HashiCorp tools, in particular Boundary (access) and Consul (service identity).
- Cloud IAM and secret-management at one or more major clouds (AWS, Azure, GCP).
Skills
- Working environment: French-speaking, with English as a second language for most colleagues.
- French preferred, English required.
- [to confirm: Boundary, Consul, Terraform Cloud or Enterprise]
- Enterprise Security, Modern Infrastructure, and Platform Engineering.
- Primarily Azure and AWS, with very little GCP.
Visa & Work Authorization
- Security clearance or background check: [to confirm: regulated-sector clients sometimes require one]
This listing is sourced directly from Arctiq's careers page and normalized into a canonical job model.