Conviso Inc. is seeking a Security Implementation Engineer to lead the implementation and rollout of the Keeper Security password/secrets management platform. The role involves assessing current credential management practices, designing target-state architecture, and facilitating integrations across a hybrid environment.
Responsibilities:
- Implementation Planning : Assess current credential management practices across on-prem and AWS environments; design target-state Keeper architecture (vault structure, folder/sharing model, RBAC) aligned to hybrid identity model
- Deployment : Install and configure Keeper Enterprise/Keeper Commander CLI; deploy Keeper Gateway on-prem (if using KeeperPAM) for connecting to internal systems, servers, and databases without exposing them directly to the internet
- Entra ID Integration : Configure SSO via SAML/OIDC with Entra ID; set up SCIM provisioning for automated user/group lifecycle sync; align Conditional Access policies (MFA, device compliance) with Keeper login requirements
- AWS Integration : Implement Keeper Secrets Manager for AWS workloads — EC2, Lambda, ECS/EKS — replacing hardcoded credentials and static IAM keys; integrate with CI/CD pipelines (CodePipeline/GitHub Actions) and infrastructure-as-code (Terraform/CloudFormation)
Requirements:
- Must have active Secret / Tier 5 Secret Security Clearance or higher
- Experience implementing PAM/password management platforms (Keeper, CyberArk, etc.) in hybrid environments
- Hands-on Entra ID experience: SSO (SAML/OIDC), SCIM provisioning, Conditional Access
- On-prem AD/network experience for gateway-based privileged access
- AWS experience: IAM, Secrets Manager equivalents, EC2/Lambda, Terraform/CloudFormation a plus
- Scripting ability (Python, PowerShell, Keeper Commander CLI) for migration/automation
- Security certifications (Security+, CISSP, or Azure/AWS security certs) a plus, especially for federal engagements