Location Designation: Hybrid - 3 days per quarter
Role OverviewThis role supports the development and ongoing operation of the Open DEX platform, including building and maintaining internal tooling, enterprise API integrations, and AI-assisted automation across the firm's cloud, endpoint management, and service-management environment.
The role owns delivery end-to-end, from design and implementation through testing, debugging, performance tuning, and production incident support. The engineer will also establish reusable patterns, standards, and tooling that can be adopted by other engineering teams across the organization.
What You'll Do- Develop and operate the Open DEX platform: Design, build, test, debug, optimize, and support production applications, services, and internal tools using Python, Bash, PowerShell, APIs, container technologies, cloud services, and modern software engineering practices. Diagnose live production incidents across application, database, network, and platform layers and implement durable solutions that address root causes.
- Build enterprise integrations and automation: Develop, maintain, and troubleshoot REST API integrations across Microsoft 365, Azure AD / Entra ID, Microsoft Intune, Active Directory, ServiceNow, PagerDuty, Rundeck, and other business applications. Build automated operational and incident workflows while addressing authentication, authorization, token handling, pagination, retries, error handling, rate limiting, credential synchronization, network restrictions, and identity or role configuration issues.
- Advance AI-assisted engineering: Use modern AI-assisted development tools and LLMs to accelerate development, debugging, documentation, code review, and automation. Build agentic AI applications and LLM tooling, including tool interfaces and integrations using Model Context Protocol (MCP) or comparable frameworks, while applying appropriate controls for prompt injection, destructive operations, credential access, least privilege, and per-user audit logging.
- Build secure, scalable engineering foundations: Deliver containerized applications using Docker, Kubernetes, and Helm and develop CI/CD and infrastructure-as-code capabilities using technologies such as GitHub Actions, Terraform, Ansible, GitOps, and Argo CD. Support AWS services including EKS, IAM/IRSA, VPC, S3, Secrets Manager, RDS PostgreSQL, Route 53, and KMS, along with observability and production support through Datadog, Grafana, CloudTrail, and PagerDuty. Support artifact and package management in restricted-egress environments using JFrog Artifactory or equivalent technologies.
- Own technical direction and reusable standards: Operate as the sole or primary engineer on workstreams as needed, setting technical direction and making implementation decisions independently. Partner across engineering, security, identity, and infrastructure teams to establish reusable components, development patterns, and standards that reduce duplicated effort. Identify and drive opportunities beyond assigned scope, including solutions addressing compliance or operational risk, and communicate technical concepts, operational impact, and business value to stakeholders.
What You'll BringRequired Skills- Strong proficiency in Python with production experience designing, building, testing, debugging, performance-tuning, and supporting applications and services in a live enterprise environment; proficiency with Bash and PowerShell for cross-platform automation.
- Strong understanding of HTTP/HTTPS, REST APIs, JSON, modern service architecture, Git version control, and authentication and authorization technologies including API keys, OAuth 2.0, OIDC, JWT, SAML, service principals, and workload identity federation. Experience securely managing credentials through enterprise secret stores such as AWS Secrets Manager, External Secrets Operator, KMS, or equivalent using least-privilege and auditable access.
- Experience building and troubleshooting enterprise API integrations and automated workflows across platforms such as Microsoft 365, Azure AD / Entra ID, Microsoft Intune, Active Directory, ServiceNow, PagerDuty, and Rundeck, including diagnosing issues across network, identity, and application layers.
- Experience delivering containerized applications using Docker, Kubernetes, and Helm; developing CI/CD pipelines and infrastructure as code using GitHub Actions, Terraform, Ansible, GitOps, or Argo CD; and working with AWS services including EKS, IAM/IRSA, VPC, S3, Secrets Manager, RDS PostgreSQL, Route 53, and KMS.
- Proficiency with modern AI-assisted development tools and LLMs, including prompt engineering and AI-powered engineering workflows. Experience building agentic AI applications and production LLM tooling using MCP or comparable frameworks, with an understanding of security considerations for AI systems with write access.
- Strong analytical, problem-solving, communication, and collaboration skills, with the ability to independently own technical workstreams, diagnose production incidents to root cause, establish reusable engineering standards and tooling, collaborate across engineering, security, identity, and infrastructure teams, and translate technical work into business and operational value.
Preferred Skills- Experience with enterprise IT management and automation platforms, including endpoint management at scale using Microsoft Intune Automated Device Enrollment, Autopilot, or JamF, as well as identity lifecycle automation and Microsoft 365 integrations.
- Experience building scalable, secure, and maintainable enterprise applications, custom integrations, internal tools, or automation solutions leveraging enterprise APIs.
- Experience supporting regulatory and compliance requirements in a financial services environment, including SEC and GDPR requirements, through automation and controls.
- Experience with workflow orchestration platforms such as Kestra, Dagster, or Argo Workflows and with multi-cluster Kubernetes platform operations.
Job Level: LEVELPF5Pay TransparencySalary Range: $168,801 - $210,800
Overtime eligible: Exempt
Discretionary bonus eligible: Yes
Sales bonus eligible: No
Actual base salary will be determined based on several factors but not limited to individual's experience, skills, qualifications, and job location. Additionally, employees are eligible for an annual discretionary bonus. In addition to base salary, employees may also be eligible to participate in an incentive program.
Our BenefitsWe provide a full package of benefits for employees - and have unique offerings for a modern workforce, including leave programs, adoption assistance, and student loan repayment programs. Based on feedback from our employees, we continue to refine and add benefits to our offering, so that you can flourish both inside and outside of work.Click hereto discover more about our comprehensive benefit options or visit our NYL Benefits Site.
Job Requisition ID: 94808