Cloud Engineer
About Us
We are on a mission to rebuild how financial services firms create, manage, and execute their data integrations and transformations. Today that process stretches across multiple teams, tools, and handoffs—slow to build, expensive to maintain, and nearly impossible to change. We collapse it into a single AI-native platform that business users can operate without writing a ticket, while engineering teams retain the governance and security controls they require. We're growing our founding team now.
BBH is a premier global financial services firm, known for premium service, specialist expertise, technology solutions, and a partnership approach to client management. Across Investor Services and Capital Partners, we work with sophisticated clients who make BBH their first call when tackling their hardest challenges. We believe stability is a competitive advantage and invest in relationships, technologies, and development for the long-term interests of our clients and people.
About The Role
Our Cloud Engineer will own the infrastructure the entire platform runs on. This is a broad ownership role: cloud infrastructure on Azure, CI/CD pipelines, Kubernetes cluster management, security controls, and cost optimization—all under one remit. This is not a compliance-first security role; it is a cloud infrastructure role where security is a core engineering discipline built into everything. You'll work closely with platform engineering to ensure the environment is reliable, observable, and built to scale, giving the rest of the engineering team the confidence to ship quickly. As one of the first cloud infrastructure hires, you'll make greenfield decisions and have real ownership from day one.
Responsibilities
- Infrastructure:
- Design, deploy, and manage cloud infrastructure on Azure using Terraform and GitOps practices
- Own the networking layer—VNets, Subnets, private endpoints, and DNS configuration
- Manage Azure resource organization, identity, and access management
- Monitor and optimize cloud spending while maintaining performance and reliability
- CI/CD & Developer Experience:
- Build and maintain CI/CD pipelines with automated testing, security scanning, and deployment automation (primary tooling: Azure DevOps and/or GitHub Actions)
- Work with engineering teams to ensure deployment workflows support fast, safe iteration
- Manage environment configuration and secrets (Azure Key Vault)
- Kubernetes & Containers:
- Manage AKS (Azure Kubernetes Service) cluster configuration, scaling, and lifecycle
- Implement container security hardening, network policies, and RBAC
- Establish patterns for workload deployment, resource management, and observability
- Security & Compliance:
- Implement security controls across network, application, and data layers
- Conduct vulnerability scanning and manage remediation
- Threat modeling for platform components
- Support SOC 2 compliance requirements as the company matures
- Observability & Incident Response:
- Set up and maintain platform monitoring, alerting, and logging infrastructure
- Develop and own incident response procedures
- Ensure SLAs are measurable and maintained
Requirements
- Experience:
- 5+ years in DevOps, SRE, or cloud infrastructure engineering in SaaS environments
- Production infrastructure ownership—not just contributing to an infra team, but owning outcomes
- Technical Skills:
- Deep Azure expertise (primary cloud)—AKS, Azure DevOps, Azure Networking, Key Vault, Azure Monitor
- Terraform—required; all infrastructure is managed as code
- Kubernetes—cluster management, networking, RBAC, security hardening
- CI/CD pipeline design—GitHub Actions or Azure DevOps
- Container security—image scanning, runtime security, secrets management
- Networking—VNet design, private endpoints, DNS, firewall rules
- Practices:
- Active user of AI tools for infrastructure and automation tasks
Nice to Have
- SOC 2 or PCI-DSS compliance experience
- Azure security certifications (AZ-500, AZ-104) or equivalent (CISSP, CKS)
- Financial services or compliance-sensitive infrastructure background
- Experience with data encryption at scale—Azure Key Vault, envelope encryption, field-level encryption
- AWS familiarity—we're Azure-primary but AWS awareness is useful
- Terraform modules and reusable infrastructure patterns at scale
Why Join Us
- Category-defining work: AI-native data integration and transformation for financial services doesn't exist yet. You'll help build it from the ground up.
- Enterprise backing, startup speed: The credibility, domain expertise, and runway of an established enterprise combined with the pace of a startup. This is an unusual opportunity.
- Foundational team: You'll be among the first in-house hires. You'll set architecture, culture, and standards—not inherit them.
Pay
MA: $110,000 - $160,000 base salary + annual target bonus. BBH and its affiliates' compensation program includes base salary, discretionary bonuses, and profit-sharing.
Benefits
BBH's total rewards package recognizes your contributions with more than just a paycheck—providing benefits that enhance your experience from long-term savings, healthcare, and income protection to professional development opportunities and time off.