Resume and JobRESUME AND JOB
Crusoe logo

High-CTR: Staff Infrastructure Engineer (Vault) Careers at Crusoe - San Francisco, California | Apply Now!

Crusoe

High-CTR: Staff Infrastructure Engineer (Vault) Careers at Crusoe - San Francisco, California | Apply Now!

full-timePosted: Dec 8, 2025

Job Description

Role Overview

Crusoe is seeking a Staff Infrastructure Engineer (Vault) to play a critical role in securing our cloud infrastructure and enabling our Zero Trust security strategy. You will be responsible for architecting, deploying, and managing our HashiCorp Vault platform, the foundation for secrets management and identity architecture across our hybrid, multi-cloud environment. This is a highly strategic position where you will shape our long-term credentials management strategy and ensure engineering teams can securely interact with core infrastructure.

A Day in the Life

Here’s a glimpse into what a typical day might look like for a Staff Infrastructure Engineer (Vault) at Crusoe:

  • Start your day by reviewing monitoring dashboards and alerts for the Vault platform, ensuring its health and performance.
  • Attend a stand-up meeting with the Cloud Engineering team to discuss progress on integrating Vault into new microservices.
  • Work on Terraform code to automate the deployment of Vault clusters in different GCP regions.
  • Collaborate with the DevOps team to troubleshoot a Vault integration issue in the CI/CD pipeline.
  • Design and implement a new Policy as Code rule in Sentinel to restrict access to sensitive secrets based on user roles.
  • Research and evaluate new Vault features and capabilities, such as dynamic secrets and certificate management.
  • Write documentation and create training materials for developers on how to use Vault securely and effectively.
  • Participate in a security review of a new application to identify potential secrets management vulnerabilities.
  • Mentor a junior engineer on best practices for securing Kubernetes secrets with Vault.
  • Finish the day by reviewing audit logs and security reports to identify any suspicious activity.

Why San Francisco?

San Francisco is a global hub for technology and innovation, offering a vibrant ecosystem for professionals in cloud security and infrastructure engineering. Crusoe's location in San Francisco provides access to a diverse talent pool, cutting-edge industry events, and a thriving startup culture. The city's proximity to leading cloud providers and security vendors makes it an ideal place to stay at the forefront of technology trends. Beyond the professional benefits, San Francisco offers a rich cultural scene, world-class dining, and stunning natural beauty.

Career Path

The Staff Infrastructure Engineer (Vault) role offers a strong career path within Crusoe. You can progress into roles such as Principal Security Engineer, Security Architect, or even management positions within the Security or Infrastructure Engineering teams. Crusoe is committed to providing opportunities for professional growth and development, including training programs, certifications, and mentorship opportunities.

Salary & Benefits

Crusoe offers a competitive salary and benefits package commensurate with experience and qualifications. The estimated salary range for this role in San Francisco is $180,000 to $250,000 per year. In addition to base salary, Crusoe provides a comprehensive benefits package, including:

  • Comprehensive health, dental, and vision insurance
  • Generous paid time off and holidays
  • 401(k) retirement plan with company match
  • Professional development opportunities and tuition reimbursement
  • Wellness programs and employee assistance program
  • Flexible work arrangements
  • Commuter benefits
  • Company-sponsored events and team-building activities

Crusoe Culture

At Crusoe, we foster a culture of innovation, collaboration, and impact. We are a team of passionate individuals driven by a shared mission to accelerate the abundance of energy and intelligence. We value intellectual curiosity, a growth mindset, and a commitment to excellence. We believe in empowering our employees to make a meaningful difference and providing them with the resources and support they need to succeed.

How to Apply

If you are a highly motivated and experienced infrastructure security engineer with a passion for secrets management and Zero Trust security, we encourage you to apply. Please submit your resume and cover letter through our online application portal. We look forward to hearing from you!

Frequently Asked Questions

  1. What is Crusoe's mission?

    Crusoe's mission is to accelerate the abundance of energy and intelligence. We’re crafting the engine that powers a world where people can create ambitiously with AI — without sacrificing scale, speed, or sustainability.

  2. What is Zero Trust security?

    Zero Trust is a security model that assumes no user or device is trusted by default, regardless of whether they are inside or outside the network perimeter. It requires strict identity verification for every user and device attempting to access resources.

  3. What is HashiCorp Vault?

    HashiCorp Vault is a secrets management tool that securely stores and manages sensitive information, such as passwords, API keys, and certificates. It provides a centralized platform for controlling access to secrets and ensuring their confidentiality and integrity.

  4. What experience is required for this role?

    We require 8+ years of hands-on experience in cloud security, DevOps, or infrastructure engineering, with deep, production-grade experience deploying and operating HashiCorp Vault in enterprise environments.

  5. What programming languages are preferred?

    Fluency in at least one programming language (Go or Python preferred) is required for automation and tooling.

  6. What is Crusoe's approach to work-life balance?

    Crusoe offers flexible work arrangements and a generous paid time off policy to support employees' work-life balance.

  7. What opportunities are there for professional development?

    Crusoe provides professional development opportunities and tuition reimbursement to help employees grow their skills and advance their careers.

  8. What is the company culture like at Crusoe?

    Crusoe fosters a culture of innovation, collaboration, and impact. We are a team of passionate individuals driven by a shared mission.

  9. What are the benefits of working in San Francisco?

    San Francisco is a global hub for technology and innovation, offering access to a diverse talent pool, cutting-edge industry events, and a thriving startup culture.

  10. How does Crusoe contribute to sustainability?

    Crusoe is committed to sustainability by developing technologies that reduce energy waste and promote the use of renewable energy sources.

Locations

  • San Francisco, California, United States

Salary

Estimated Salary Rangemedium confidence

198,000 - 275,000 USD / yearly

Source: ai estimated

* This is an estimated range based on market data and may vary based on experience and qualifications.

Skills Required

  • HashiCorp Vaultintermediate
  • Secrets Managementintermediate
  • Cryptographyintermediate
  • PKI/X.509intermediate
  • Google Cloud Platform (GCP)intermediate
  • Cloud-Native IAMintermediate
  • Infrastructure-as-Code (Terraform)intermediate
  • Kubernetesintermediate
  • Microservices Architectureintermediate
  • Gointermediate
  • Pythonintermediate
  • Network Securityintermediate
  • Segmentationintermediate
  • Firewallsintermediate
  • Routingintermediate
  • Zero Trustintermediate
  • Sentinelintermediate
  • Disaster Recoveryintermediate
  • SDLCintermediate
  • Policy as Codeintermediate
  • Terraformintermediate
  • Oktaintermediate
  • Kubernetes Service Accountsintermediate
  • KV Secrets Engineintermediate
  • Transit Secrets Engineintermediate
  • KMIP Secrets Engineintermediate
  • Performance Replicationintermediate
  • Automated Sealingintermediate
  • Observabilityintermediate
  • Monitoringintermediate
  • Alertingintermediate
  • Audit Loggingintermediate
  • Vault as a Serviceintermediate
  • Linuxintermediate

Required Qualifications

  • 8+ years of hands-on experience in cloud security, DevOps, or infrastructure engineering (experience)
  • Deep, production-grade experience deploying and operating HashiCorp Vault in enterprise environments (Enterprise edition strongly preferred) (experience)
  • Expert knowledge of secrets management, cryptography, PKI/X.509 certificate authorities, and trust systems (experience)
  • Strong experience with Google Cloud Platform (GCP) and cloud-native IAM models (experience)
  • Proven expertise using Infrastructure-as-Code tools (Terraform) to automate security platforms (experience)
  • Hands-on experience with Kubernetes and securely integrating secrets into microservices architectures (experience)
  • Fluency in at least one programming language (Go or Python preferred) for automation and tooling (experience)
  • Strong understanding of network security fundamentals, including segmentation, firewalls, routing, and Zero Trust concepts (experience)
  • Experience building internal “security platforms” or Vault-as-a-Service offerings (Bonus) (experience)
  • Prior ownership of enterprise-wide identity or credential lifecycle programs (Bonus) (experience)
  • Bachelor's degree in Computer Science, Engineering, or a related field (or equivalent experience) (experience)
  • Experience with security compliance frameworks (e.g., SOC 2, ISO 27001, PCI DSS) (experience)

Responsibilities

  • Architecting a highly available, disaster-resilient, multi-cluster secrets management platform as the foundation of our Zero Trust strategy
  • Driving Vault from PoC to enterprise-grade production, establishing standards, reliability, and scalability
  • Leading cross-functional alignment with Cloud Engineering, DevOps, and SRE teams on secure secret management workflows embedded into the SDLC
  • Designing and enforcing governance controls to meet internal policies and external compliance requirements (e.g., SOX, ISO 27001)
  • Implementing Policy as Code using Sentinel to automate guardrails and access decisions
  • Engineering Vault infrastructure using Terraform with fully automated, reproducible, and version-controlled deployments
  • Architecting integrations between Vault, identity providers (e.g., Okta), and workload identities (e.g., Kubernetes Service Accounts)
  • Configuring and tuning core Vault secrets engines (KV, Transit, KMIP) and Enterprise features such as performance replication and automated sealing
  • Operationalizing “Vault as a Service” through paved-road onboarding, self-service workflows, and clear developer documentation
  • Building observability across the platform, including monitoring, alerting, audit logging, and usage insights
  • Developing and maintaining security documentation, including architectural diagrams, standard operating procedures, and security policies
  • Participating in security incident response and vulnerability management activities
  • Staying up-to-date with the latest security threats, vulnerabilities, and industry best practices
  • Mentoring junior engineers and providing technical guidance on security topics

Benefits

  • general: Competitive salary and equity package
  • general: Comprehensive health, dental, and vision insurance
  • general: Generous paid time off and holidays
  • general: 401(k) retirement plan with company match
  • general: Professional development opportunities and tuition reimbursement
  • general: Wellness programs and employee assistance program
  • general: Flexible work arrangements
  • general: Commuter benefits
  • general: Company-sponsored events and team-building activities
  • general: Opportunity to work on cutting-edge technology and solve challenging problems
  • general: Collaborative and supportive work environment
  • general: Making a tangible impact on the future of energy and intelligence
  • general: Stock options
  • general: Life insurance
  • general: Disability insurance
  • general: Parental leave
  • general: Relocation assistance (if applicable)
  • general: Pet Insurance

Target Your Resume for "High-CTR: Staff Infrastructure Engineer (Vault) Careers at Crusoe - San Francisco, California | Apply Now!" , Crusoe

Get personalized recommendations to optimize your resume specifically for High-CTR: Staff Infrastructure Engineer (Vault) Careers at Crusoe - San Francisco, California | Apply Now!. Takes only 15 seconds!

AI-powered keyword optimization
Skills matching & gap analysis
Experience alignment suggestions

Check Your ATS Score for "High-CTR: Staff Infrastructure Engineer (Vault) Careers at Crusoe - San Francisco, California | Apply Now!" , Crusoe

Find out how well your resume matches this job's requirements. Get comprehensive analysis including ATS compatibility, keyword matching, skill gaps, and personalized recommendations.

ATS compatibility check
Keyword optimization analysis
Skill matching & gap identification
Format & readability score

Tags & Categories

InfrastructureSecurityVaultDevOpsCloudCrusoeStaff Infrastructure EngineerHashiCorp VaultSecrets ManagementCloud SecurityInfrastructure EngineeringZero Trust SecurityGCPGoogle Cloud PlatformTerraformKubernetesSan FranciscoCaliforniaTechnology JobsSecurity EngineerIdentity ManagementPKICryptographyAutomationSentinelPolicy as CodeCloud InfrastructureIAMOktaDisaster RecoveryHigh AvailabilityComplianceSOXISO 27001Green TechAI InfrastructureCloudEngineering

Answer 10 quick questions to check your fit for High-CTR: Staff Infrastructure Engineer (Vault) Careers at Crusoe - San Francisco, California | Apply Now! @ Crusoe.

Quiz Challenge
10 Questions
~2 Minutes
Instant Score

Related Books and Jobs

No related jobs found at the moment.

Crusoe logo

High-CTR: Staff Infrastructure Engineer (Vault) Careers at Crusoe - San Francisco, California | Apply Now!

Crusoe

High-CTR: Staff Infrastructure Engineer (Vault) Careers at Crusoe - San Francisco, California | Apply Now!

full-timePosted: Dec 8, 2025

Job Description

Role Overview

Crusoe is seeking a Staff Infrastructure Engineer (Vault) to play a critical role in securing our cloud infrastructure and enabling our Zero Trust security strategy. You will be responsible for architecting, deploying, and managing our HashiCorp Vault platform, the foundation for secrets management and identity architecture across our hybrid, multi-cloud environment. This is a highly strategic position where you will shape our long-term credentials management strategy and ensure engineering teams can securely interact with core infrastructure.

A Day in the Life

Here’s a glimpse into what a typical day might look like for a Staff Infrastructure Engineer (Vault) at Crusoe:

  • Start your day by reviewing monitoring dashboards and alerts for the Vault platform, ensuring its health and performance.
  • Attend a stand-up meeting with the Cloud Engineering team to discuss progress on integrating Vault into new microservices.
  • Work on Terraform code to automate the deployment of Vault clusters in different GCP regions.
  • Collaborate with the DevOps team to troubleshoot a Vault integration issue in the CI/CD pipeline.
  • Design and implement a new Policy as Code rule in Sentinel to restrict access to sensitive secrets based on user roles.
  • Research and evaluate new Vault features and capabilities, such as dynamic secrets and certificate management.
  • Write documentation and create training materials for developers on how to use Vault securely and effectively.
  • Participate in a security review of a new application to identify potential secrets management vulnerabilities.
  • Mentor a junior engineer on best practices for securing Kubernetes secrets with Vault.
  • Finish the day by reviewing audit logs and security reports to identify any suspicious activity.

Why San Francisco?

San Francisco is a global hub for technology and innovation, offering a vibrant ecosystem for professionals in cloud security and infrastructure engineering. Crusoe's location in San Francisco provides access to a diverse talent pool, cutting-edge industry events, and a thriving startup culture. The city's proximity to leading cloud providers and security vendors makes it an ideal place to stay at the forefront of technology trends. Beyond the professional benefits, San Francisco offers a rich cultural scene, world-class dining, and stunning natural beauty.

Career Path

The Staff Infrastructure Engineer (Vault) role offers a strong career path within Crusoe. You can progress into roles such as Principal Security Engineer, Security Architect, or even management positions within the Security or Infrastructure Engineering teams. Crusoe is committed to providing opportunities for professional growth and development, including training programs, certifications, and mentorship opportunities.

Salary & Benefits

Crusoe offers a competitive salary and benefits package commensurate with experience and qualifications. The estimated salary range for this role in San Francisco is $180,000 to $250,000 per year. In addition to base salary, Crusoe provides a comprehensive benefits package, including:

  • Comprehensive health, dental, and vision insurance
  • Generous paid time off and holidays
  • 401(k) retirement plan with company match
  • Professional development opportunities and tuition reimbursement
  • Wellness programs and employee assistance program
  • Flexible work arrangements
  • Commuter benefits
  • Company-sponsored events and team-building activities

Crusoe Culture

At Crusoe, we foster a culture of innovation, collaboration, and impact. We are a team of passionate individuals driven by a shared mission to accelerate the abundance of energy and intelligence. We value intellectual curiosity, a growth mindset, and a commitment to excellence. We believe in empowering our employees to make a meaningful difference and providing them with the resources and support they need to succeed.

How to Apply

If you are a highly motivated and experienced infrastructure security engineer with a passion for secrets management and Zero Trust security, we encourage you to apply. Please submit your resume and cover letter through our online application portal. We look forward to hearing from you!

Frequently Asked Questions

  1. What is Crusoe's mission?

    Crusoe's mission is to accelerate the abundance of energy and intelligence. We’re crafting the engine that powers a world where people can create ambitiously with AI — without sacrificing scale, speed, or sustainability.

  2. What is Zero Trust security?

    Zero Trust is a security model that assumes no user or device is trusted by default, regardless of whether they are inside or outside the network perimeter. It requires strict identity verification for every user and device attempting to access resources.

  3. What is HashiCorp Vault?

    HashiCorp Vault is a secrets management tool that securely stores and manages sensitive information, such as passwords, API keys, and certificates. It provides a centralized platform for controlling access to secrets and ensuring their confidentiality and integrity.

  4. What experience is required for this role?

    We require 8+ years of hands-on experience in cloud security, DevOps, or infrastructure engineering, with deep, production-grade experience deploying and operating HashiCorp Vault in enterprise environments.

  5. What programming languages are preferred?

    Fluency in at least one programming language (Go or Python preferred) is required for automation and tooling.

  6. What is Crusoe's approach to work-life balance?

    Crusoe offers flexible work arrangements and a generous paid time off policy to support employees' work-life balance.

  7. What opportunities are there for professional development?

    Crusoe provides professional development opportunities and tuition reimbursement to help employees grow their skills and advance their careers.

  8. What is the company culture like at Crusoe?

    Crusoe fosters a culture of innovation, collaboration, and impact. We are a team of passionate individuals driven by a shared mission.

  9. What are the benefits of working in San Francisco?

    San Francisco is a global hub for technology and innovation, offering access to a diverse talent pool, cutting-edge industry events, and a thriving startup culture.

  10. How does Crusoe contribute to sustainability?

    Crusoe is committed to sustainability by developing technologies that reduce energy waste and promote the use of renewable energy sources.

Locations

  • San Francisco, California, United States

Salary

Estimated Salary Rangemedium confidence

198,000 - 275,000 USD / yearly

Source: ai estimated

* This is an estimated range based on market data and may vary based on experience and qualifications.

Skills Required

  • HashiCorp Vaultintermediate
  • Secrets Managementintermediate
  • Cryptographyintermediate
  • PKI/X.509intermediate
  • Google Cloud Platform (GCP)intermediate
  • Cloud-Native IAMintermediate
  • Infrastructure-as-Code (Terraform)intermediate
  • Kubernetesintermediate
  • Microservices Architectureintermediate
  • Gointermediate
  • Pythonintermediate
  • Network Securityintermediate
  • Segmentationintermediate
  • Firewallsintermediate
  • Routingintermediate
  • Zero Trustintermediate
  • Sentinelintermediate
  • Disaster Recoveryintermediate
  • SDLCintermediate
  • Policy as Codeintermediate
  • Terraformintermediate
  • Oktaintermediate
  • Kubernetes Service Accountsintermediate
  • KV Secrets Engineintermediate
  • Transit Secrets Engineintermediate
  • KMIP Secrets Engineintermediate
  • Performance Replicationintermediate
  • Automated Sealingintermediate
  • Observabilityintermediate
  • Monitoringintermediate
  • Alertingintermediate
  • Audit Loggingintermediate
  • Vault as a Serviceintermediate
  • Linuxintermediate

Required Qualifications

  • 8+ years of hands-on experience in cloud security, DevOps, or infrastructure engineering (experience)
  • Deep, production-grade experience deploying and operating HashiCorp Vault in enterprise environments (Enterprise edition strongly preferred) (experience)
  • Expert knowledge of secrets management, cryptography, PKI/X.509 certificate authorities, and trust systems (experience)
  • Strong experience with Google Cloud Platform (GCP) and cloud-native IAM models (experience)
  • Proven expertise using Infrastructure-as-Code tools (Terraform) to automate security platforms (experience)
  • Hands-on experience with Kubernetes and securely integrating secrets into microservices architectures (experience)
  • Fluency in at least one programming language (Go or Python preferred) for automation and tooling (experience)
  • Strong understanding of network security fundamentals, including segmentation, firewalls, routing, and Zero Trust concepts (experience)
  • Experience building internal “security platforms” or Vault-as-a-Service offerings (Bonus) (experience)
  • Prior ownership of enterprise-wide identity or credential lifecycle programs (Bonus) (experience)
  • Bachelor's degree in Computer Science, Engineering, or a related field (or equivalent experience) (experience)
  • Experience with security compliance frameworks (e.g., SOC 2, ISO 27001, PCI DSS) (experience)

Responsibilities

  • Architecting a highly available, disaster-resilient, multi-cluster secrets management platform as the foundation of our Zero Trust strategy
  • Driving Vault from PoC to enterprise-grade production, establishing standards, reliability, and scalability
  • Leading cross-functional alignment with Cloud Engineering, DevOps, and SRE teams on secure secret management workflows embedded into the SDLC
  • Designing and enforcing governance controls to meet internal policies and external compliance requirements (e.g., SOX, ISO 27001)
  • Implementing Policy as Code using Sentinel to automate guardrails and access decisions
  • Engineering Vault infrastructure using Terraform with fully automated, reproducible, and version-controlled deployments
  • Architecting integrations between Vault, identity providers (e.g., Okta), and workload identities (e.g., Kubernetes Service Accounts)
  • Configuring and tuning core Vault secrets engines (KV, Transit, KMIP) and Enterprise features such as performance replication and automated sealing
  • Operationalizing “Vault as a Service” through paved-road onboarding, self-service workflows, and clear developer documentation
  • Building observability across the platform, including monitoring, alerting, audit logging, and usage insights
  • Developing and maintaining security documentation, including architectural diagrams, standard operating procedures, and security policies
  • Participating in security incident response and vulnerability management activities
  • Staying up-to-date with the latest security threats, vulnerabilities, and industry best practices
  • Mentoring junior engineers and providing technical guidance on security topics

Benefits

  • general: Competitive salary and equity package
  • general: Comprehensive health, dental, and vision insurance
  • general: Generous paid time off and holidays
  • general: 401(k) retirement plan with company match
  • general: Professional development opportunities and tuition reimbursement
  • general: Wellness programs and employee assistance program
  • general: Flexible work arrangements
  • general: Commuter benefits
  • general: Company-sponsored events and team-building activities
  • general: Opportunity to work on cutting-edge technology and solve challenging problems
  • general: Collaborative and supportive work environment
  • general: Making a tangible impact on the future of energy and intelligence
  • general: Stock options
  • general: Life insurance
  • general: Disability insurance
  • general: Parental leave
  • general: Relocation assistance (if applicable)
  • general: Pet Insurance

Target Your Resume for "High-CTR: Staff Infrastructure Engineer (Vault) Careers at Crusoe - San Francisco, California | Apply Now!" , Crusoe

Get personalized recommendations to optimize your resume specifically for High-CTR: Staff Infrastructure Engineer (Vault) Careers at Crusoe - San Francisco, California | Apply Now!. Takes only 15 seconds!

AI-powered keyword optimization
Skills matching & gap analysis
Experience alignment suggestions

Check Your ATS Score for "High-CTR: Staff Infrastructure Engineer (Vault) Careers at Crusoe - San Francisco, California | Apply Now!" , Crusoe

Find out how well your resume matches this job's requirements. Get comprehensive analysis including ATS compatibility, keyword matching, skill gaps, and personalized recommendations.

ATS compatibility check
Keyword optimization analysis
Skill matching & gap identification
Format & readability score

Tags & Categories

InfrastructureSecurityVaultDevOpsCloudCrusoeStaff Infrastructure EngineerHashiCorp VaultSecrets ManagementCloud SecurityInfrastructure EngineeringZero Trust SecurityGCPGoogle Cloud PlatformTerraformKubernetesSan FranciscoCaliforniaTechnology JobsSecurity EngineerIdentity ManagementPKICryptographyAutomationSentinelPolicy as CodeCloud InfrastructureIAMOktaDisaster RecoveryHigh AvailabilityComplianceSOXISO 27001Green TechAI InfrastructureCloudEngineering

Answer 10 quick questions to check your fit for High-CTR: Staff Infrastructure Engineer (Vault) Careers at Crusoe - San Francisco, California | Apply Now! @ Crusoe.

Quiz Challenge
10 Questions
~2 Minutes
Instant Score

Related Books and Jobs

No related jobs found at the moment.