Position SummaryInfraSec builds and secures Harris Associates' cloud foundation on Microsoft Azure. The team runs the estate as code - identities, networks, virtual machines, Kubernetes, and data platforms are defined, reviewed, and deployed through automated pipelines rather than managed by hand. It's a lean, hands-on team that partners closely with DevOps, Data, and Application teams, and holds a high bar for security given the firm's regulated environment.
The Cloud Infrastructure and Security Engineer is a hands-on, individual-contributor role at the center of this infrastructure-as-code operation, working across environments and cloud regions with deep involvement in identity, networking, compute, and data-platform security. We're looking for an experienced infrastructure or security engineer who thinks in systems, is comfortable owning production-grade cloud environments, and wants the scope to shape how a growing platform is built and secured.
Responsibilities may include but are not limited to:- AI-enabled tooling: Build and manage AI/LLM-based skills and agentic workflows that give the team leverage, governed under the same security review and least-privilege discipline as any other credentialed automation, with human review before anything ships.
- Patching and on-call: Share the team's operational rotations - patch the estate roughly three to four Saturdays a year, and serve as on-call first responder for infrastructure and security issues about one week a month, resolving directly or escalating as needed.
- Infrastructure as code: Author and maintain Terraform across roughly 18 repositories, multiple environments and regions, with Azure Storage state backends - holding the line on version/provider discipline, import safety, and plan-diff review.
- Identity and access management: Provision and govern Microsoft Entra ID - app-role and role-assignable groups, PIM/JIT, Conditional Access, Workload Identity Federation, and Microsoft Graph - designing least-privilege grants and auditing existing ones.
- Cloud networking: Design and operate hub-and-spoke topology, management-group policy and custom roles, NSG/firewall rules, routing, and trusted network locations, and troubleshoot when it breaks.
- Virtual machines and golden images: Provision hardened Azure VMs from a shared module (secure boot, vTPM, encryption at host, Hybrid Benefit), and build/maintain golden Windows Server images with Packer.
- Kubernetes and containers: Support the AKS platform alongside DevOps - workload identity, service-mesh and egress behavior, and connectivity troubleshooting.
- Data and analytics platform access: Govern access and security settings for Databricks, Snowflake, Power BI/Microsoft Fabric, and Purview, and manage platform-level governance.
- Monitoring and incident response: Keep signal high and noise low with Azure Monitor, and lead root-cause investigations across pipelines, capacity, and connectivity.
- CI/CD, review, and automation: Deliver every change through Azure Pipelines and a gated Terraform flow, review pull requests for what CI can't catch, and improve the automation itself.
QualificationsRequired- 7+ years of hands-on cloud infrastructure engineering experience, with production-grade experience on a major cloud platform (Azure preferred).
- Strong Infrastructure-as-Code skills - Terraform or a comparable tool - including state management, provider discipline, and safely importing existing resources.
- Solid grounding in identity and access fundamentals: RBAC, service principals/managed identities, and least-privilege design.
- Cloud networking expertise: hub-and-spoke or equivalent topologies, firewalls/NSGs, routing, and DNS.
- CI/CD delivery experience with a platform like Azure DevOps, plus scripting in PowerShell and/or Bash.
- A security-first mindset, with comfort working inside change-control and approval gates.
- Clear written communication skills for documenting decisions and processes.
Preferred:- Kubernetes/AKS operations experience - node pools, workload identity, and service mesh.
- Experience with Packer or golden-image build pipelines.
- Data-platform governance experience (e.g., Databricks, Snowflake, Power BI/Microsoft Fabric).
- Experience in a regulated or financial-services environment.
Special RequirementsThis role shares the team's operational rotations: a monthly Saturday patching cycle (roughly three to four Saturdays per year) and a weekly on-call rotation (about one week per month) as first responder for infrastructure and security issues. Occasional early-morning, evening, or weekend work may be required to support patch windows and critical incidents. Flexibility with working hours is key.
We offer a comprehensive benefits package designed to integrate life and work and to support our employees and their families. Benefits include, but are not limited to; medical, prescription drug, dental and vision insurance, paid time off, profit sharing plan, 401k plan, tuition reimbursement, commuter and holistic wellness benefits along with volunteer programs.
Actual annual base salaries may vary based on factors including but not limited to education, training, experience, and other job-related factors. If hired, base pay will be determined on an individualized basis and is only one part of the total compensation package, which, depending on the position, may also include a discretionary performance bonus and other Harris sponsored benefit programs.
Expected range for this Chicago-based role
$190,000-$210,000 USD