Infrastructure as Code (IaC) Security Engineer (EKS/Terraform/CI-CD Guardrails)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+4 more
Job description
- Design and maintain secure Infrastructure as Code solutions for cloud and containerized environments supporting AI security workloads
- Own EKS cluster security, including node group configuration, networking policies, RBAC, and pod security standards
- Develop hardened, reusable Terraform modules with built-in security controls (least-privilege IAM, encryption-at-rest, segmentation)
- Build and manage Docker images and Helm charts using security-first practices (image scanning, minimal bases, secrets management, signed artifacts)
- Integrate security policy checks into CI/CD pipelines (e.g., OPA/Gatekeeper, Checkov, tfsec)
- Automate provisioning/scaling using immutable infrastructure principles and drift detection
- Troubleshoot and remediate infrastructure security issues across Kubernetes, Terraform, CI/CD, and containers
- Enforce compliance with organizational policies and frameworks such as NIST and CIS Benchmarks
- Document secure patterns, deployment runbooks, and automation workflows for the AI security team
Requirements
Do you have experience in Terraform?, * A security mindset and a track record of making automation inherently safer
- Production experience securing Kubernetes environments and IaC pipelines
- Strong collaboration with DevSecOps, platform, and engineering teams in fast-paced delivery, * Hands-on secure IaC experience (Terraform, cloud + containerized environments)
- Deep production experience with Kubernetes on EKS (networking, RBAC, workload security)
- Strong Terraform development skills (reusable modules and secure provisioning patterns)
- Experience building Docker images and Helm charts securely
- CI/CD integration with automated validation and deployment workflows
- Solid understanding of IAM, encryption, secrets management, and network segmentation
- Troubleshooting across Kubernetes, Terraform, containers, and pipeline deployments
Other Skills:
- Working knowledge of security policy enforcement tools (OPA/Gatekeeper, Checkov, tfsec or similar)
- Familiarity with NIST/CIS infrastructure governance frameworks
- Experience supporting AI/ML or security-focused Kubernetes workloads
Important Notes:
- This role focuses on embedding security controls into automated infrastructure delivery (IaC, Kubernetes, containers, and CI/CD guardrails).
- Prioritize security-first patterns: repeatability, immutability, drift detection, and compliance enforcement.
Benefits & conditions
3.63.6 out of 5 stars Plano, TX 75074 $68 - $72 an hour
About the company
Our Client: A leading provider of AI security and infrastructure automation solutions department in the Automotive industry is seeking an Infrastructure as Code (IaC) Security Engineer. This role offers the chance to embed security into automated cloud and Kubernetes infrastructure, powering secure, repeatable delivery for an innovation-focused AI security platform., Calance is a global IT company with operations in the United States, Canada, and India. Over the years, Calance has grown organically and has acquired numerous successful IT Services firms along the way. As a result, the company today is a mix of diverse cultures, talents, and expertise that collaborate globally to bring our best capabilities and thinking to clients. Calance also offers benefits which includes Medical, Dental, Vision care, and 401K.
Calance - the place to grow. www.calance.com
You must create an Indeed account before continuing to the company website to apply
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence
Learning Kubernetes made easy with KubeCampus
Now is the time for industrialized software development
Dev Digest 121 - AI goes offline