About the RoleOur Cloud Engineer will own the infrastructure the entire platform runs on. This is a broad ownership role: cloud infrastructure on Azure, CI/CD pipelines, Kubernetes cluster management, security controls, and cost optimization - all under one remit.
This is not a compliance-first security role. It is a cloud infrastructure role where security is a core engineering discipline built into everything, not layered on at the end. You'll work closely with platform engineering to ensure the environment is reliable, observable, and built to scale - and you'll give the rest of the engineering team the confidence to ship quickly because the foundation they're building on is solid.
You'll be one of the first cloud infrastructure hire, which means greenfield decisions and real ownership from day one.
ResponsibilitiesInfrastructure
- Design, deploy, and manage cloud infrastructure on Azure using Terraform and GitOps practices
- Own the networking layer - VNets, Subnets, private endpoints, and DNS configuration
- Manage Azure resource organization, identity, and access management
- Monitor and optimize cloud spending while maintaining performance and reliability
CI/CD & Developer Experience
- Build and maintain CI/CD pipelines with automated testing, security scanning, and deployment automation
- Primary tooling: Azure DevOps and/or GitHub Actions
- Work with engineering teams to ensure deployment workflows support fast, safe iteration
- Manage environment configuration and secrets (Azure Key Vault)
- Kubernetes & Containers
- Manage AKS (Azure Kubernetes Service) cluster configuration, scaling, and lifecycle
- Implement container security hardening, network policies, and RBAC
- Establish patterns for workload deployment, resource management, and observability
Security & Compliance
- Implement security controls across network, application, and data layers
- Conduct vulnerability scanning and manage remediation
- Threat modelling for platform components
- Support SOC 2 compliance requirements as the company matures
Observability & Incident Response
- Set up and maintain platform monitoring, alerting, and logging infrastructure
- Develop and own incident response procedures
- Ensure SLAs are measurable and maintained
RequirementsExperience
- 5+ years DevOps, SRE, or cloud infrastructure engineering in SaaS environments
- Production infrastructure ownership - not just contributing to an infra team, but owning outcomes
Technical Skills
- Deep Azure expertise (primary cloud) - AKS, Azure DevOps, Azure Networking, Key Vault, Azure Monitor
- Terraform - required; all infrastructure is managed as code
- Kubernetes - cluster management, networking, RBAC, security hardening
- CI/CD pipeline design - GitHub Actions or Azure DevOps
- Container security - image scanning, runtime security, secrets management
- Networking - VNet design, private endpoints, DNS, firewall rules
Practices
- Active user of AI tools for infrastructure and automation tasks
Nice to Have- SOC 2 or PCI-DSS compliance experience
- Azure security certifications (AZ-500, AZ-104) or equivalent (CISSP, CKS)
- Financial services or compliance-sensitive infrastructure background
- Experience with data encryption at scale - Azure Key Vault, envelope encryption, field-level encryption
- AWS familiarity - we're Azure-primary but AWS awareness is useful
- Terraform modules and reusable infrastructure patterns at scale
Why Join Us- Category-defining work - AI-native data integration and transformation for financial services doesn't exist yet. You'll help build it from the ground up.
- Enterprise backing, startup speed - The credibility, domain expertise, and runway of an established enterprise combined with the pace of a startup. This is an unusual opportunity.
- Foundational team - You'll be among the first in-house hires. You'll set architecture, culture, and standards - not inherit them.
Salary RangeMA: $110,00 - $160,000 base salary + annual target bonus
BBH and its affiliates' compensation program includes base salary, discretionary bonuses, and profit-sharing. The anticipated base salary range(s) shown above are only for the indicated location(s) and may differ in other locations due to cost of living and labor considerations. Base salaries may vary based on factors such as skill, experience and qualification for the role. BBH's total rewards package recognizes your contributions with more than just a paycheck-providing you with benefits that enhance your experience at BBH from long-term savings, healthcare, and income protection to professional development opportunities and time off, our programs support your overall well-being.
We value diverse experiences. We value diverse experiences and transferrable skillsets. If your career hasn't followed a traditional path, includes alternative experiences, or doesn't meet every qualification or skill listed in the job description, please do go ahead and apply.