United States
Remote
Senior
Full Time
29 days ago
💰$ 90,000 - $ 200,000
Infrastructure SecurityCloud SecurityTerraformGitOpsAWSGCPDeFiWeb3Leadership
Requirements
- •Hands-on experience authoring and deploying production-grade Terraform for cloud security including complex IAM, EKS, and VPC implementations through GitOps pipelines such as Atlantis or ArgoCD
- •Proven success leading and mentoring a small engineering team while maintaining direct ownership of technical project delivery as a player-coach
- •Built foundational infrastructure hardening and IAM standards from the ground up in an organization without an established infrastructure security function
- •Experience designing and implementing secure infrastructure using Infrastructure as Code and GitOps practices in production cloud environments
- •Ability to architect and secure cloud infrastructure while partnering closely with engineering teams to embed security into development workflows
What You'll Do
- •Establish and scale security foundations protecting infrastructure, cloud environments, and decentralized network
- •Lead a small team while being hands-on in architecture, implementation, and delivery
- •Build and standardize secure infrastructure patterns across AWS and GCP
- •Establish unified identity and access management and centralized secrets management
- •Deliver secure Terraform and GitOps workflows for infrastructure deployments
- •Automate infrastructure compliance, logging, and security controls to support SOC 2 Type 2 and banking-grade standards
- •Reduce blast radius of infrastructure compromises by strengthening IAM, platform hardening, and cloud security boundaries
- •Lead evolution of Infrastructure Security into an engineering-enabled capability to accelerate product delivery and improve security posture
Nice to Have
- •Experience adapting financial services or banking security standards to modern, high-velocity infrastructure environments
- •Background designing security architectures and trust boundaries for highly distributed systems or decentralized service topologies
- •Experience securing identity and access management across both AWS and GCP environments
- •Experience working within DeFi or Web3 environments and understanding associated infrastructure threat models
- •Built and enforced policy-as-code controls within CI/CD pipelines using technologies such as OPA, CodeQL, or comparable frameworks
- •Designed or operated advanced secrets management or cryptographic infrastructure using technologies such as HSMs, Vault, MPC, or equivalent beyond standard cloud KMS offerings
