Jobs · Information Technology · Illinois

Staff Infrastructure & Security Engineer

Vouch Insurance · Chicago, IL · 3 days ago
Information Technology$200/hrFull-time

About the role

Serve as the technical DRI for the Infra & Security group: own the architecture, set the standards, and make the technical calls across infrastructure, DevOps, and security engineering.

Own the cloud platform end-to-end: infrastructure reliability, CI/CD and delivery automation, and the infrastructure-as-code beneath them.

Drive a simpler, isolated architecture through shrinking the surface area we defend and maintain: Retire legacy and unused services, consolidate SaaS and vendors, and unwind standing external dependencies.

Own infra & security incident-response: a staffed rotation with no single point of failure, severity-matched response, actionable alerting, and runbooks.

Bring identity and access under a single source of truth: human, service, machine, and agent identity.

Build the Production-agent Infrastructure that lets autonomous agents run and self-verify safely in production.

Drive and maintain our security-compliance and supply-chain scanning programs.

Responsibilities

  • Serve as the technical DRI for the Infra & Security group: own the architecture, set the standards, and make the technical calls across infrastructure, DevOps, and security engineering.
  • Own the cloud platform end-to-end: infrastructure reliability, CI/CD and delivery automation, and the infrastructure-as-code beneath them.
  • Drive a simpler, isolated architecture through shrinking the surface area we defend and maintain: Retire legacy and unused services, consolidate SaaS and vendors, and unwind standing external dependencies.
  • Own infra & security incident-response: a staffed rotation with no single point of failure, severity-matched response, actionable alerting, and runbooks.
  • Bring identity and access under a single source of truth: human, service, machine, and agent identity.
  • Build the Production-agent Infrastructure that lets autonomous agents run and self-verify safely in production.
  • Drive and maintain our security-compliance and supply-chain scanning programs.

Requirements

  • Deep cloud engineering experience, primarily in AWS: designing, building, and operating production infrastructure at scale.
  • Strong in CI/CD and delivery automation (CircleCI, Nomad, or equivalent) and infrastructure-as-code (Terraform), with ownership of a real production system's reliability.
  • Apply security pragmatically: isolation, least-privilege, RBAC, blast-radius containment.
  • A formal background in information security or cybersecurity, including having led a SOC 2 (or similar) compliance audit.
  • Has led at least one enterprise security-breach or data-leak incident response.
  • Comfortable as a hands-on technical lead and DRI: work through architecture, standards, and code review, set technical direction, and raise the bar across a team.
  • Bias toward simplicity and subtraction.
  • AI-forward: build for isolation, safe data, and non-human identity, and the infrastructure behind it.
  • Communicate crisply across engineering, IT/Security, Legal, and Finance.

Qualifications

  • Experience operating Temporal or similar durable-workflow infrastructure in production.
  • Hands-on with supply-chain / dependency vulnerability scanning (Endor Labs, Snyk, or equivalent).
  • Compliance-as-code experience: treating controls and evidence as an engineering artifact.
  • Familiarity with agent / sandbox isolation patterns: dedicated accounts, scoped tokens, ephemeral environments, and data masking.
  • Secrets and credential management at scale (1Password, AWS SSM, or equivalent).
  • Experience in insurance, fintech, or another regulated domain.

Skills

  • Deep cloud engineering experience, primarily in AWS: designing, building, and operating production infrastructure at scale.
  • Strong in CI/CD and delivery automation (CircleCI, Nomad, or equivalent) and infrastructure-as-code (Terraform), with ownership of a real production system's reliability.
  • Apply security pragmatically: isolation, least-privilege, RBAC, blast-radius containment.
  • Experience operating Temporal or similar durable-workflow infrastructure in production.
  • Hands-on with supply-chain / dependency vulnerability scanning (Endor Labs, Snyk, or equivalent).
  • Compliance-as-code experience: treating controls and evidence as an engineering artifact.
  • Familiarity with agent / sandbox isolation patterns: dedicated accounts, scoped tokens, ephemeral environments, and data masking.
  • Secrets and credential management at scale (1Password, AWS SSM, or equivalent).
  • Experience in insurance, fintech, or another regulated domain.

Benefits

  • Competitive compensation and equity packages
  • Health, dental, and vision insurance
  • Baby and caregiver support
  • Technology allowance
  • Company-sponsored personal and professional development
  • Regular performance reviews

Pay

The Pay Range For This Role Is 200,000 - 240,000 USD per year (Chicago, IL (Hybrid))

Schedule

This role is aligned to our Chicago Office. While this role has hybrid work flexibility, we require team members to be in the office at least three days per week (Tuesday, Wednesday and Thursday) to foster close collaboration and team building.

Similar jobs