Jobs · Engineering · Illinois

Staff Software Engineer - Infrastructure Automation

Early Warning · Chicago, IL · 3 days ago
Engineering$145k–$186k/yrFull-time

About the role

The Staff Software Engineer - Infrastructure Automation is a senior hands-on technical contributor responsible for designing, building, and improving the infrastructure-as-code capabilities used to provision and manage infrastructure across Early Warning. This role applies strong software engineering and systems design practices to shared Terraform and Ansible tooling, reusable infrastructure modules, policy-as-code guardrails, and developer enablement capabilities.

Responsibilities

  • Apply software engineering discipline to infrastructure automation by treating modules, policies, and tooling as versioned, tested, reviewed products with clear interfaces, lifecycle practices, and automated regression coverage.
  • Execute complex infrastructure automation assignments with general direction; break work into deliverable components, identify practical implementation solutions, raise risks and dependencies, and seek guidance when decisions extend beyond established architecture or standards.
  • Contribute to the design and evolution of reference architectures for infrastructure-as-code capabilities; maintain architecture decision records and evaluate significant design and build-versus-buy tradeoffs with appropriate technical guidance.
  • Drive adoption of Terraform as a preferred path for infrastructure provisioning across supported cloud and on-premises environments; contribute to module taxonomy, ownership practices, and private registry standards.
  • Develop clear override and exception patterns that address legitimate use cases while keeping deviations visible, reviewable, auditable, and subject to policy controls.
  • Develop configuration-as-code capabilities for network infrastructure, including structured configuration generation, controlled changes and rollback, pre-change validation, post-change verification, compliance checks, and drift detection.
  • Develop programmatic controls supporting segregation of duties, protected infrastructure state, change review, exception handling, and break-glass processes with appropriate evidence capture and expiration.
  • Implement secure authentication and credential patterns, including OIDC-federated and short-lived IAM roles and dynamic secrets for cloud, database, and infrastructure credentials.
  • Partner with Security, Risk, and Compliance teams to map infrastructure automation controls to applicable requirements, including PCI DSS, SOX ITGC, NYDFS Part 500, and FFIEC expectations, and automate evidence collection where practical.
  • Develop engineering standards, technical documentation, self-service tooling, APIs, and compliance visibility that improve the infrastructure developer experience.
  • Prototype and de-risk complex infrastructure automation and policy problems; mentor engineers and improve design, implementation, testing, and code-review practices across the organization.
  • Partner with CI/CD, AIOps, and observability teams to integrate infrastructure modules, policy controls, telemetry, and control signals into shared engineering workflows.
  • Define and monitor measures of platform effectiveness, including module adoption, policy compliance, plan/apply reliability, and time to remediate infrastructure drift or compliance violations.

Requirements

This position is ineligible for employment Visa sponsorship. Candidates responding to this posting must independently possess the eligibility to work in the United States at the date of hire.

Qualifications

  • Education and/or experience typically obtained through a bachelor's degree in computer science, engineering, or a related technical field.
  • Eight or more years of related experience in software engineering, cloud engineering, platform engineering, infrastructure engineering, DevOps, or a related technical discipline.
  • Demonstrated strength in software engineering and systems design, including the ability to turn ambiguous technical problems into maintainable, testable solutions and reason about interfaces, state, failure modes, idempotency, and change impact.
  • Demonstrated ability to execute complex technical work with general direction, independently make implementation decisions within established architecture and standards, and recognize when guidance or escalation is needed for novel or enterprise-wide decisions.
  • Strong production programming experience in Python, Go, or a comparable general-purpose language used to build infrastructure tooling, services, controllers, or automation.
  • Experience with Terraform, including reusable module development, composition, automated testing, registry publishing, versioning, state management, and infrastructure change workflows.
  • Experience with Ansible beyond basic playbooks, such as reusable roles or collections, execution environments, automated testing, linting, or Ansible Automation Platform/AWX.
  • Experience implementing policy-as-code or infrastructure policy controls using OPA/Rego or comparable technologies.
  • Strong knowledge of AWS infrastructure and security concepts, including IAM, networking, encryption, credential management, and secure configuration.
  • Experience implementing security, compliance, or change-management controls through infrastructure automation in a regulated or similarly controlled environment.
  • Strong hands-on experience with Kubernetes and containerized infrastructure sufficient to implement infrastructure and admission-control requirements.
  • Experience automating network infrastructure configuration, validation, compliance, or change-management workflows.
  • Experience implementing federated identity, OIDC-based workload authentication, dynamic secrets management, or short-lived infrastructure credentials.
  • Experience mapping automated infrastructure controls to regulatory or control frameworks such as PCI DSS, SOX ITGC, NYDFS Part 500, or FFIEC guidance.
  • Experience in FinTech, banking, payments, or another highly regulated industry.
  • Current AWS, Terraform, Kubernetes, or other relevant technical certification.

Similar jobs