Cloud DevOps Engineer
Role details
Job location
Tech stack
Job description
The Senior Cloud DevOps Engineer leads design, implementation, and monitoring of Azure cloud solutions while ensuring compliance with FedRAMP standards and automating infrastructure deployments., * Lead the design, continuous monitoring, implementation, and security operations of Azure cloud solutions, ensuring they meet industry best practices and comply with FedRAMP High, IL4 requirements.
- Lead team in developing modular Infrastructure-as-Code utilizing Terraform, PowerShell, ARM, Bicep, and YAML languages.
- Lead projects of moderate complexity to completion.
- Sustain a high level of reliability for key automated systems.
- Leads teams to define, estimate, and implement requirements for new automations or services of moderate complexity needing development.
- Stay up to date with the latest Azure and FedRAMP regulatory changes and industry trends, advising teams on potential impacts and necessary adjustments.
- Update technical documentation, workflows, and knowledge base articles.
- Provide feedback in pull requests and peer coding reviews.
- Solid knowledge in focused areas of OneStream Software.
- Participate in on-call rotation to support production systems.
- Assist in efforts to debug the problems which arise in production.
- Ability to mentor others in several technical areas.
- Understanding practical use of FedRAMP/SOC controls to assist Compliance and Security teams.
Requirements
- BS/BA in computer science, engineering, or technology-related field (or equivalent work experience).
- 8+ years of cloud infrastructure experience.
- 2+ years of compliance programs and security control sets such as NIST SP 800-53, FedRAMP High, IL4, as applied to cloud SaaS, PaaS, and IaaS environments.
- Expert knowledge of:
- VNets/vWAN, subnets, UDRs, routing, peering.
- ExpressRoute, VPN Gateway, Private Link/Endpoint.
- Azure Firewall, NSG/ASG, WAF, Application Gateway, Web Application Firewalls.
- Hands-on experience implementing network design and firewall configurations, as it pertains to connecting to government networks (BCAP) utilizing Azure Firewall and/or Palo Alto.
- Hands on experience implementing IPv6 routing and strict egress filtering strategies.
- Ability to translate DISA STIGs and NIST controls into enforceable network guardrails and evidence artifacts.
- Advanced understanding of Infrastructure-As-Code concepts and tooling (Terraform, CloudFormation templates, Bicep or ARM templates) on Microsoft Azure, Amazon Web Services (AWS), or Google Cloud Platform (GCP).
- Deep knowledge of Configuration Management/Orchestration utilities such as Ansible, PowerShell DSC, Chef, and Puppet.
- Advanced understanding of cloud concepts including elasticity, security, and identity management.
- Well versed familiarity with Agile Development methodologies utilizing Jira or Azure DevOps Boards.
- Strong understanding of Azure Kubernetes Services (AKS) with container-based deployment skills or other platforms such as OpenShift, GKS, EKS.
- Proficient knowledge in Software Development Lifecycles.
- 8+ years of hands-on experience with the following technologies, tools, and concepts:
- Automating processes using PowerShell, Bash, CLI, REST APIs, python, ARM Templates or other scripting languages.
- Comfortable leveraging source control tools such as Git, BitBucket, or GitHub.
- Microsoft Azure, Amazon Web Services (AWS) or Google Cloud (GCP).
- Microsoft Windows 11, Windows Server, IIS, Microsoft SQL Server, Active Directory., * Experience working for a cloud service provider (CSP), managed service provider (MSP), or SaaS provider.
- 8+ years of relevant Azure experience deploying and managing leveraging Infrastructure-as-Code (IAC) concepts.
- Microsoft Windows Server 2016-2022, IIS, Microsoft SQL Server, Azure Active Directory.
- Debian, Ubuntu, or other flavors of the Linux operating systems.
- Any certifications such as Microsoft Certified: Azure Administrator Associate (AZ-103, AZ-104), Azure Solutions Architect Expert (AZ-300, AZ-301), CCNP, CCIE, CISSP, Azure DevOps Engineer Expert (AZ-400), Certified Kubernetes Administrator (CKE), CISSP, Information Technology Infrastructure Library (ITIL) Foundation, Microsoft Certified Professional (MCP), CompTIA Security+/Network+ is a plus.
Knowledge, Skills, and Abilities
- Deal well with ambiguous/undefined problems.
- Ability to self-motivate and work independently.
- Strong organizational and prioritization skills.
- Ability to find and apply effective solutions to emerging problems and challenges.
- Strong attention to detail.
- Ability to estimate your efforts.
- Ability to get up to speed quickly with modern technologies and services.
- Work well in a fast-paced environment.
- Ability to multitask on a variety of projects.
- Comfortable communicating with all levels of management.
- Experience with OneStream Software not required.
Travel (remove if not applicable)
- No travel is required.
Benefits & conditions
Compensation: $140,000.00 - $160,000.00 (Range applies to US candidates only) + Benefits/Variable Comp/Equity - Range may vary based on experience.
Benefits Offered: Vision, Medical, Life, Dental, 401K, * Transparency around corporate structure, salary, and benefits.
- Core value of customer success.
- Variety of project work (not industry-specific).
- Strong culture and camaraderie.
- Multiple training opportunities.
Benefits at OneStream OneStream employees are passionate, hardworking individuals who go above and beyond to keep our customers happy and follow through on our mission statement. They consistently deliver the best and in turn, we make every effort to keep them cared for and happy. A sample of the benefits we provide are:
- Excellent Medical Plan.
- Dental & Vision Insurance.
- Life Insurance.
- Short & Long Term Disability.
- Vacation Time.
- Paid Holidays.
- Professional Development.
- Retirement Plan.
All candidates must be legally authorized to work for any company in the country where this position is located without sponsorship.
OneStream is an Equal Opportunity Employer.