DevOps Engineer - Infrastructure & Security
Role details
Job location
Tech stack
Job description
We're looking for a DevOps Engineer who can help lead our infrastructure-as-code and CICD deliverables for the client project and raise the bar on security across the program. You'll design and maintain Terraform modules consumed by multiple teams, build secure CI/CD pipelines, and ensure every provisioned resource follows least-privilege principles. You'll work within HCP Terraform using VCS-driven workflows and help shape how the team adopts AI-assisted development tooling responsibly.
## What You'll Do
-
Design, build, and maintain reusable Terraform modules with clear interfaces, versioning, and documentation so other teams can self-serve infrastructure safely
-
Manage and optimize HCP Terraform workspaces using VCS-driven workflows - including workspace design, variable sets, run triggers, and policy enforcement
-
Provision and manage cloud resources (primarily AWS) following least-privilege access patterns and security best practices
-
Manage secrets and sensitive configuration using HashiCorp Vault and/or AWS Secrets Manager
-
Build and maintain CI/CD pipelines (GitHub Actions) with proper gating, scanning, testing, and promotion workflows that integrate with HCP Terraform's VCS-driven run model
-
Conduct security reviews of infrastructure code and pipeline configurations
Requirements
Applicants must be authorized to work in the US without sponsorship. Please note, this role is not able to offer visa transfer or sponsorship now or in the future., 5+ years of hands-on Terraform experience, including writing modules with proper state management, remote backends, and provider configuration
-
Hands-on Experience with HCP Terraform (Terraform Cloud), specifically VCS-driven workflows - workspace configuration, speculative plans on PRs, run approvals, and managing workspace variables/variable sets
-
Experience with HCP Terraform's private registry for publishing and consuming internal modules
-
Strong understanding of AWS IAM - policies, roles, trust relationships, permission boundaries, and service control policies
-
Hands-on Experience with at least one secrets management platform: HashiCorp Vault or AWS Secrets Manager
-
Solid understanding of OIDC and federated identity - how trust is established, token exchange, and practical application in CI/CD and cloud access
-
Proven experience building and maintaining CI/CD pipelines in GitHub Actions or GitLab CI/CD, including environment promotion, approval gates, and artifact management
-
Security-first mindset - you default to deny, scope permissions tightly, and can articulate why
-
Hands-on Experience using AI coding assistants (Amazon Q, Kiro, GitHub Copilot, or similar) with a clear understanding of when to trust, verify, and override AI-generated output
-
Commitment to human-in-the-loop practices: code review, manual approval gates for production, and treating AI output as a draft - never as the final word
### Nice to Have
-
Experience with Sentinel within HCP Terraform
-
Knowledge of infrastructure testing tools
-
Contributions to internal developer platforms or self-service infrastructure tooling
## How We Work
- Infrastructure changes are driven through VCS - a push or PR triggers speculative plans and runs in HCP Terraform, with peer review required before apply
Benefits & conditions
The annual salary for this position is between $140,000- $155,000 depending on experience and other qualifications of the successful candidate.
This position is also eligible for Cognizant's discretionary annual incentive program, based on performance and subject to the terms of Cognizant's applicable plans.
Benefits: Cognizant offers the following benefits for this position, subject to applicable eligibility requirements:
-
Medical/Dental/Vision/Life Insurance
-
Paid holidays plus Paid Time Off
-
401(k) plan and contributions