Staff Production Engineer- Public Sector
Owns secure cloud infrastructure, IAM, and automation across AWS, Azure, GCP for public sector environments. Requires 8+ years experience, deep cloud expertise, IaC tools like Terraform, and TS/SCI clearance eligibility.
About the job
Responsibilities
Security-Focused Cloud Operations
- Design, automate, and operate the IAM, account/subscription, and project lifecycle across AWS, Azure, and GCP, enforcing least-privilege and standardized access patterns at scale.
- Review, implement, and continuously improve cloud identity and access policies (IAM, Okta, Opal) to align with Databricks security standards and audit requirements.
Production Engineering & Automation
- Build and maintain reliable, observable automation and tooling to apply cloud changes (roles, policies, accounts, networking) safely and repeatedly.
- Treat operational and security issues as software problems: eliminate toil, drive root-cause analysis, and codify fixes into infrastructure and tooling.
Security Data Pipelines & Compliance
- Own and improve security and audit logging data pipelines from cloud providers into our internal systems, ensuring timely, accurate data for detection, investigations, and audits.
- Partner with Security, Compliance, and Audit teams to provide evidence, clarifications, and policy updates that keep our environments aligned with evolving standards.
Regulated & Specialized Environments
- Operate and improve specialized, highly regulated environments (e.g., FedRAMP / GovCloud) including release management, patching cadences, and supporting secure access workflows (e.g., SAW).
- Ensure high availability and resiliency for critical security and access infrastructure across these environments.
On-Call & Incident Response
- Participate in a 24x7 on-call rotation for high-severity incidents impacting cloud accounts, IAM, or security data pipelines.
- Act as a key partner to product engineering, security engineering, and field teams during incidents to restore service and harden systems for the future.
Requirements
Education: BS, MS, or PhD in Computer Science, Engineering, or a related technical field, or equivalent practical experience.
Experience: 8+ years of experience operating and automating large-scale cloud environments, with a track record of driving cross-team infrastructure improvement.
Cloud & Infrastructure Expertise:
- Deep hands-on experience with at least one major cloud provider (AWS, Azure, or GCP) in areas such as IAM, networking, accounts/subscriptions/projects, and audit logging.
- Strong background in Infrastructure-as-Code and automation (e.g., Terraform, CloudFormation, or similar) and CI/CD for infrastructure changes.
Security & Compliance Mindset:
- Proven experience working in or with security-sensitive or regulated environments (e.g., SOC2, FedRAMP, ISO 27001, financial services, public sector) and translating requirements into concrete technical controls.
- Familiarity with access review processes, policy baselines, and audit evidence for cloud environments.
Operational Excellence:
- Demonstrated success running high-availability, security-critical services, including on-call responsibilities and incident management.
- Strong debugging and problem-solving skills across distributed systems, with the ability to navigate ambiguous issues spanning multiple teams and platforms.
Required: Candidates must be eligible for a Top Secret / Sensitive Compartmented Information (TS/SCI) security clearance.
Nice-to-Haves (Bonus)
- Possession of a current polygraph (Counterintelligence or Full Scope).
- Experience with Okta, Opal, or similar identity/access tooling.
- Background operating secure admin workstations (SAW) or comparable hardened access patterns.
- Experience migrating cloud accounts or subscriptions during M&A or large-scale reorganizations.
Skills
AWS, Azure, GCP, IAM, Terraform, CloudFormation, Okta, Opal, CI/CD, Infrastructure As Code
Similar jobs
DevOps / SRE jobsStaff Platform Engineer will build and improve automated delivery pipelines, developer environments, infrastructure, and release systems across the engineering organization. The role requires 6+ years of engineering experience, a bachelor’s degree, and expertise with CI/CD, cloud infrastructure, containers, and infrastructure as code.
Leads site reliability initiatives for trading systems, improving availability, scalability, monitoring, incident response, and infrastructure automation. The role requires 8+ years of DevOps, SRE, or platform engineering experience and strong expertise in Kubernetes, cloud platforms, CI/CD, and infrastructure as code.
Leads the architecture, development, and operation of cloud, Kubernetes, on-premises, and hybrid infrastructure, while building developer platforms and CI/CD automation. Requires at least six years of infrastructure or related engineering experience, deep Kubernetes expertise, strong programming skills, and technical leadership.
Designs, automates, and operates AWS infrastructure, shared development environments, and container platforms. The role requires strong experience with Kubernetes, infrastructure as code, environment lifecycle automation, cloud security, compliance, and cost optimization.
Leads the design and deployment of AI-enabled manufacturing systems, MES, connected-factory infrastructure, and automation for aircraft production. Requires a bachelor’s degree and 8+ years of experience in digital manufacturing, industrial automation, or software-enabled operations.