Full-Time

Lead Systems Engineer

Secrets and Vault Engineering

Deadline 4/30/27
Intercontinental Exchange

Intercontinental Exchange

10,001+ employees

Operates global exchanges, data, and connectivity

Compensation Overview

$149.4k - $180k/yr

+ Incentive Compensation

New York, NY, USA

In Person

Category
DevOps & Infrastructure (1)
Required Skills
Bash
Python
Github Actions
ServiceNow
Jenkins
Terraform
Ansible
REST APIs
Linux/Unix
OAuth
Requirements
  • 7+ years of infrastructure, platform, or systems engineering experience.
  • Production experience with HashiCorp Vault — secret engines, authentication methods, policies, and operational concerns. Architect-level depth is not required, but you should have shipped against it and understand how it fits into a broader platform.
  • Strong proficiency in Python and Shell scripting for automation and tooling.
  • Experience with Ansible for configuration management and orchestration.
  • Solid understanding of identity, authentication, and secure communication protocols (TLS, OAuth, OIDC, x.509).
  • Working knowledge of CI/CD tooling (Jenkins, GitHub Actions, GitLab CI, or similar) and Infrastructure-as-Code (Terraform preferred).
  • Experience designing and consuming RESTful APIs.
  • Strong fundamentals in Linux systems.
  • Demonstrated ability to write production-quality code, communicate design trade-offs clearly, and collaborate across teams.
Responsibilities
  • Design, build, and maintain platform services for secrets management, certificate lifecycle, encryption key management, and policy enforcement.
  • Develop automation and tooling in Python and Ansible to streamline operations, enforce security controls, and reduce manual provisioning effort.
  • Contribute to a self-service model for application teams, including golden-pattern templates, declarative manifests, and approval workflows integrated with enterprise systems such as ServiceNow.
  • Collaborate with cross-functional teams (application, infrastructure, security, compliance) to translate requirements into reliable, well-governed services.
  • Help shape the team's roadmap in emerging areas including workload identity (SPIFFE/SPIRE), policy-as-code, and identity controls for AI and machine-driven workloads.
  • Participate in code reviews, design reviews, and architecture discussions; mentor and coach engineers earlier in their career.
  • Contribute to internal documentation, runbooks, and knowledge-sharing.
  • Participate in a light on-call rotation supporting the team's services.
Desired Qualifications
  • Bachelor's degree in Computer Science, Engineering, or related field.
  • Experience building or contributing to a self-service Vault, secrets, or cryptography platform.
  • Familiarity with SPIFFE/SPIRE or other workload identity frameworks.
  • Familiarity with policy-as-code tooling such as Open Policy Agent (OPA) or HashiCorp Sentinel.
  • Exposure to AI/ML infrastructure or interest in identity controls for AI and agentic workloads.
  • Awareness of post-quantum cryptography standards (NIST PQC, hybrid key exchange) and their operational implications.
  • Experience with cloud platforms (AWS, GCP, or hybrid environments) and cloud-native secrets services such as AWS Secrets Manager or KMS.
  • Exposure to container platforms (Docker, Kubernetes, OpenShift).
  • Understanding of threat modeling, secrets rotation, secret-zero patterns, and zero trust architectures.
  • Experience in fintech, financial services, mortgage technology, or other regulated and security-sensitive domains.
Intercontinental Exchange

Intercontinental Exchange

View

Intercontinental Exchange (ICE) operates a global network of regulated exchanges and clearinghouses, plus market data and connectivity services. Its products include real-time and historical data across equities, fixed income, and commodities, as well as trading, clearing, listings, and connectivity to its venues; it also offers mortgage technology and fixed income execution. ICE differentiates itself through an integrated ecosystem that combines multiple major exchanges, a comprehensive data suite, and specialized services under one umbrella. Its goal is to enable efficient, transparent, and trusted global markets by connecting participants, providing data, and supporting trading and clearing across many asset classes and geographies.

Company Size

10,001+

Company Stage

IPO

Headquarters

Atlanta, Georgia

Founded

2001

Simplify Jobs

Simplify's Take

What believers are saying

  • Energy transition and geopolitical disruptions reinforce ICE benchmark primacy for risk management.
  • Tokenized stock pilot and OKX $200M investment position ICE in emerging blockchain infrastructure.
  • ETF Hub processed $5 trillion notional; Northern Trust partnership signals institutional demand surge.

What critics are saying

  • CFTC April 2026 event contract caps force Polymarket delisting, slashing volumes 70-80%.
  • SEC May 2026 tokenized asset rules mandate full-reserve custody, blocking NYSE pilot.
  • EU MiFIR 3.0 June 2026 enforcement cuts ICE Endex volumes 40%, favoring EEX.

What makes Intercontinental Exchange unique

  • Record H1 2025 volumes of 1.2 billion contracts with 24% YoY growth demonstrate market-leading liquidity.
  • ICE Private Credit Intelligence standardizes $40 trillion market with Apollo anchor partner validation.
  • AI Aurora framework powers mortgage servicing agents handling thousands simultaneous interactions with compliance.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Life Insurance

Remote Work Options

401(k) Retirement Plan

Company News

Bloomberg L.P.
Mar 31st, 2026
NYSE owner ICE invests $200M in crypto exchange OKX at $25B valuation

OKX, a cryptocurrency exchange operator, has received a $200 million investment from Intercontinental Exchange, valuing the company at $25 billion. ICE, which owns the New York Stock Exchange, will gain a board seat as part of the deal. Haider Rafique, OKX's global managing partner, discussed the investment on Bloomberg Crypto. The companies announced the partnership on Thursday but did not disclose financial terms publicly. The deal marks a significant endorsement of OKX by a major traditional financial institution, as ICE brings its regulatory expertise and market credibility to the cryptocurrency exchange.

RootData
Mar 27th, 2026
ICE invests $600M in prediction market Polymarket

Intercontinental Exchange, the parent company of the New York Stock Exchange, has invested $600 million in Polymarket, according to market reports.

Business Wire
Mar 17th, 2026
ICE launches AI voice and chat agents for mortgage servicing at X26 conference

Intercontinental Exchange has unveiled AI voice and chat agents for mortgage servicing at its ICE Experience 2026 conference. Currently in beta testing, the agents help homeowners answer loan questions and execute management actions whilst maintaining compliance requirements. The ICE Customer Service voice agent, integrated with MSP servicing system, handles common homeowner queries about escrow, insurance and payments whilst managing thousands of simultaneous interactions. The ICE Servicing Digital chat agent assists homeowners through a portal chatbot, explaining mortgage details and performing tasks like payment management. ICE also launched 16 exception-based automation agents within ICE Business Intelligence, including disaster-tracking updates and HELOC credit score-based line adjustments. The solutions are powered by ICE Aurora, the company's enterprise AI framework designed to embed responsible AI into complex workflows.

The Associated Press
Mar 17th, 2026
ICE launches Private Credit Intelligence with Apollo to bring transparency to $40T market

Intercontinental Exchange has launched ICE Private Credit Intelligence, a data infrastructure platform aimed at bringing greater transparency to the $40 trillion private credit market. Apollo is supporting the launch as anchor partner, with additional originators and asset managers expected to join in coming months. The platform provides secure, permissioned data sharing using standardised reference data, enabling deal-level information flow between authorised counterparties. It leverages ICE's technology to ingest deal documents, extract key terms and distribute consistent information at scale. Future capabilities will include performance analytics and pricing insights. Apollo, which facilitated nearly $10 billion in secondary trading volume last year, is transitioning to more frequent pricing reporting across its credit business as private credit increasingly serves as a core fixed income allocation replacement.

Business Wire
Mar 11th, 2026
Northern Trust selects ICE ETF Hub for US institutional ETF servicing launch

Northern Trust has partnered with Intercontinental Exchange to use ICE ETF Hub as the order-taking platform for its new US exchange-traded funds servicing capability for institutional investors. The integration marks a significant step in Northern Trust's strategic entry into the US institutional investor ETF servicing market. ICE ETF Hub provides secure, scalable technology infrastructure that streamlines ETF primary market workflows and connects with authorised participants, market makers and distributors. The platform will integrate with Northern Trust's automated ETF servicing application. Since inception, ICE ETF Hub has processed over $5 trillion in order notional. The partnership comes as institutional demand for ETFs continues to surge, driven by strong inflows and innovation across passive and active strategies. Northern Trust had $18.7 trillion in assets under custody as of 31 December 2025.