- Company Name
- Seneca Resources Company, LLC
- Job Title
- Sr. Technical Analyst 16638
- Job Description
-
Job Title: Senior Technical Analyst – Secrets Management
Role Summary:
Subject‑matter expert responsible for enterprise‑wide secrets discovery, governance, and remediation. Works cross‑functionally with security, infrastructure, and application teams to identify exposed credentials, enforce IAM and NHI policies, implement automated rotation, and drive continuous improvement of secret‑management processes.
Expectations:
* Own the end‑to‑end lifecycle of credential security, from detection to resolution.
* Deliver measurable impact on MTTD, MTTR, and credential exposure trends.
* Act as trusted advisor to stakeholders, translating technical findings into business‑ready insights.
* Maintain compliance with regulatory and internal security standards across multi‑cloud environments.
Key Responsibilities:
1. Discover, validate, and triage alerts from secret‑scanning tools.
2. Analyze risk of credential leaks, hard‑coded secrets, and misconfigurations.
3. Coordinate remediation activities, ensuring secure storage and handling of secrets.
4. Govern Non‑Human Identities—service accounts, system accounts, API credentials—aligning with IAM policies.
5. Collaborate with IAM teams to enforce access controls and identity governance frameworks.
6. Monitor and enforce secret‑rotation policies; build automated rotation workflows with application and infrastructure teams.
7. Investigate exposure incidents with security, incident response, and engineering partners; conduct root‑cause analysis and track resolution.
8. Develop security dashboards (MTTD, MTTR, exposure trends) and communicate actionable insights.
9. Enhance discovery pipelines, accuracy, and remediation processes; author runbooks, SOPs, and documentation.
10. Drive process improvement, automation, and operational efficiency in secret‑management operations.
Required Skills:
* 10+ years in cybersecurity, IAM or security operations.
* Hands‑on expertise with secrets‑management/credential‑discovery tools; experience with secret‑scanning platforms.
* Deep knowledge of IAM, NHI (service accounts), AAA, Zero Trust principles, and cloud identity.
* Proficiency with AWS, Azure, OCI environments; familiarity with DevSecOps and cloud‑native security practices.
* Strong analytical, problem‑solving, and communication skills; ability to convert technical findings to business insights.
* Detail‑oriented, security‑first mindset with proactive ownership.
Required Education & Certifications:
* Bachelor’s degree in Information Technology, Cybersecurity, or related field (or equivalent experience).
* Professional certifications preferred: CISSP, CISM, or relevant IAM/Secrets‑management credentials (e.g., CySA+, CompTIA Security+).
---