Sobre esta vaga de Cloud Infrastructure and Security Engineer na Harris Associates
At Harris, the true value of what makes us successful is found in our people. It is our unique mix of cultures, experiences, beliefs and backgrounds that sets Harris apart from the rest. We constantly strive to cultivate, nurture and amplify an unparalleled environment, where we value intellectual curiosity and uniqueness of thought. Inclusion is embedded in the very fabric of our culture of collaboration and openness.
We understand that a job description only tells one part of a broader story, and Harris is seeking dynamic candidates who can add to our best-in-class environment. We recognize that qualifications can be gained through both traditional and non-traditional paths, and we are committed to considering candidates who possess the potential to be excellent in this role regardless of prior experiences.
Therefore we encourage ALL interested individuals to submit their applications, even if they do not meet every requirement outlined in the job description.
Position Summary
InfraSec builds and secures Harris Associates' cloud foundation on Microsoft Azure. The team runs the estate as code - identities, networks, virtual machines, Kubernetes, and data platforms are defined, reviewed, and deployed through automated pipelines rather than managed by hand. It's a lean, hands-on team that partners closely with DevOps, Data, and Application teams, and holds a high bar for security given the firm's regulated environment.
The Cloud Infrastructure and Security Engineer is a hands-on, individual-contributor role at the center of this infrastructure-as-code operation, working across environments and cloud regions with deep involvement in identity, networking, compute, and data-platform security. We're looking for an experienced infrastructure or security engineer who thinks in systems, is comfortable owning production-grade cloud environments, and wants the scope to shape how a growing platform is built and secured.
Responsibilities may include but are not limited to:
- AI-enabled tooling: Build and manage AI/LLM-based skills and agentic workflows that give the team leverage, governed under the same security review and least-privilege discipline as any other credentialed automation, with human review before anything ships.
- Patching and on-call: Share the team's operational rotations — patch the estate roughly three to four Saturdays a year, and serve as on-call first responder for infrastructure and security issues about one week a month, resolving directly or escalating as needed.
- Infrastructure as code: Author and maintain Terraform across roughly 18 repositories, multiple environments and regions, with Azure Storage state backends — holding the line on version/provider discipline, import safety, and plan-diff review.
- Identity and access management: Provision and govern Microsoft Entra ID — app-role and role-assignable groups, PIM/JIT, Conditional Access, Workload Identity Federation, and Microsoft Graph — designing least-privilege grants and auditing existing ones.
- Cloud networking: Design and operate hub-and-spoke topology, management-group policy and custom roles, NSG/firewall rules, routing, and trusted network locations, and troubleshoot when it breaks.
- Virtual machines and golden images: Provision hardened Azure VMs from a shared module (secure boot, vTPM, encryption at host, Hybrid Benefit), and build/maintain golden Windows Server images with Packer.
- Kubernetes and containers: Support the AKS platform alongside DevOps — workload identity, service-mesh and egress behavior, and connectivity troubleshooting.
- Data and analytics platform access: Govern access and security settings for Databricks, Snowflake, Power BI/Microsoft Fabric, and Purview, and manage platform-level governance.
- Monitoring and incident response: Keep signal high and noise low with Azure Monitor, and lead root-cause investigations across pipelines, capacity, and connectivity.
- CI/CD, review, and automation: Deliver every change through Azure Pipelines and a gated Terraform flow, review pull requests for what CI can't catch, and improve the automation itself.
Qualifications
Required
- 7+ years of hands-on cloud infrastructure engineering experience, with production-grade experience on a major cloud platform (Azure preferred).
- Strong Infrastructure-as-Code skills - Terraform or a comparable tool - including state management, provider discipline, and safely importing existing resources.
- Solid grounding in identity and access fundamentals: RBAC, service principals/managed identities, and least-privilege design.
- Cloud networking expertise: hub-and-spoke or equivalent topologies, firewalls/NSGs, routing, and DNS.
- CI/CD delivery experience with a platform like Azure DevOps, plus scripting in PowerShell and/or Bash.
- A security-first mindset, with comfort working inside change-control and approval gates.
- Clear written communication skills for documenting decisions and processes.
Preferred:
- Kubernetes/AKS operations experience - node pools, workload identity, and service mesh.
- Experience with Packer or golden-image build pipelines.
- Data-platform governance experience (e.g., Databricks, Snowflake, Power BI/Microsoft Fabric).
- Experience in a regulated or financial-services environment.
Special Requirements
This role shares the team's operational rotations: a monthly Saturday patching cycle (roughly three to four Saturdays per year) and a weekly on-call rotation (about one week per month) as first responder for infrastructure and security issues. Occasional early-morning, evening, or weekend work may be required to support patch windows and critical incidents. Flexibility with working hours is key.
We offer a comprehensive benefits package designed to integrate life and work and to support our employees and their families. Benefits include, but are not limited to; medical, prescription drug, dental and vision insurance, paid time off, profit sharing plan, 401k plan, tuition reimbursement, commuter and holistic wellness benefits along with volunteer programs.
Actual annual base salaries may vary based on factors including but not limited to education, training, experience, and other job-related factors. If hired, base pay will be determined on an individualized basis and is only one part of the total compensation package, which, depending on the position, may also include a discretionary performance bonus and other Harris sponsored benefit programs.
Equal Employment Opportunity Policy Statement
Harris Associates L.P. pursues a policy of equal opportunity in all areas of employment including recruitment, hiring, training, compensation, benefits, advancement, and treatment on the job. This means that Harris does not discriminate against employees, or qualified applicants, based on an individual's race, color, religion, creed, sex, age, national origin, physical disability, sexual orientation, trans-gender status, transsexual status, status as a veteran or disabled veteran, genetic information or for any other reason prohibited by law. Harris reserves the right to review publicly available information about applicants (i.e., via social networking sites), to the extent permissible under applicable law.
Reasonable Accommodation Notice
We provide reasonable accommodation for individuals with disabilities and disabled veterans in job application procedures. If you have any difficulty using our online system and you need an accommodation due to a disability, you may use the alternative email address below to contact us about your interest in employment at [email protected] or you can call us at 312-646-3600.
Privacy Statement
The information you send to us is used for employment purposes only. What you send is kept confidential—we will not give your personal information to outside parties without your consent.