At Early Warning, we’ve powered and protected the U.S. financial system for over thirty years with cutting-edge solutions like Zelle®, Paze℠, and so much more. As a trusted name in payments, we partner with thousands of institutions to increase access to financial services and protect transactions for hundreds of millions of consumers and small businesses.
Positions located in Scottsdale, San Francisco, Chicago, or New York follow a hybrid work model to allow for a more collaborative working environment.
Candidates responding to this posting must independently possess the eligibility to work in the United States, for any employer, at the date of hire. This position is ineligible for employment Visa sponsorship.
Overall Purpose
The Staff Software Engineer - Infrastructure Automation is a senior hands-on technical contributor responsible for designing, building, and improving the infrastructure-as-code capabilities used to provision and manage infrastructure across Early Warning. This role applies strong software engineering and systems design practices to shared Terraform and Ansible tooling, reusable infrastructure modules, policy-as-code guardrails, and developer enablement capabilities.
This position executes complex technical work with general direction, independently makes implementation decisions within established architecture and standards, and may seek guidance for novel, highly ambiguous, or cross-enterprise decisions. The Staff Engineer partners across Cloud Engineering, Platform Engineering, Security, Risk and Compliance, Network Engineering, CI/CD, and other engineering teams to enable secure, reliable, and controlled infrastructure change across cloud and on-premises environments.
Essential Functions
- Apply software engineering discipline to infrastructure automation by treating modules, policies, and tooling as versioned, tested, reviewed products with clear interfaces, lifecycle practices, and automated regression coverage.
- Execute complex infrastructure automation assignments with general direction; break work into deliverable components, identify practical implementation solutions, raise risks and dependencies, and seek guidance when decisions extend beyond established architecture or standards.
- Contribute to the design and evolution of reference architectures for infrastructure-as-code capabilities; maintain architecture decision records and evaluate significant design and build-versus-buy tradeoffs with appropriate technical guidance.
- Drive adoption of Terraform as a preferred path for infrastructure provisioning across supported cloud and on-premises environments; contribute to module taxonomy, ownership practices, and private registry standards.
- Design and develop opinionated Terraform modules for AWS services and common service patterns that incorporate security, compliance, observability, encryption, logging, tagging, network placement, and IAM controls by default.
- Develop clear override and exception patterns that address legitimate use cases while keeping deviations visible, reviewable, auditable, and subject to policy controls.
- Author composable, semantically versioned Terraform modules and develop automated validation using native Terraform testing, Terratest, tflint, static analysis, and policy evaluation of Terraform plans.
- Lead engineering and operating practices for HCP Terraform or Terraform Enterprise, including workspaces, run tasks, policy sets, state governance, drift detection, and plan/apply controls.
- Develop and improve shared Ansible capabilities, including collections, roles, execution environments, automated testing, Molecule, linting, and related engineering standards.
- Develop configuration-as-code capabilities for network infrastructure, including structured configuration generation, controlled changes and rollback, pre-change validation, post-change verification, compliance checks, and drift detection.
- Author, test, version, and maintain policy-as-code used to evaluate Terraform plans, Ansible configuration and execution, and Kubernetes admission controls.
- Build programmatic controls supporting segregation of duties, protected infrastructure state, change review, exception handling, and break-glass processes with appropriate evidence capture and expiration.
- Implement secure authentication and credential patterns, including OIDC-federated and short-lived IAM roles and dynamic secrets for cloud, database, and infrastructure credentials.
- Partner with Security, Risk, and Compliance teams to map infrastructure automation controls to applicable requirements, including PCI DSS, SOX ITGC, NYDFS Part 500, and FFIEC expectations, and automate evidence collection where practical.
- Develop engineering standards, technical documentation, self-service tooling, APIs, and compliance visibility that improve the infrastructure developer experience.
- Prototype and de-risk complex infrastructure automation and policy problems; mentor engineers and improve design, implementation, testing, and code-review practices across the organization.
- Partner with CI/CD, AIOps, and observability teams to integrate infrastructure modules, policy controls, telemetry, and control signals into shared engineering workflows.
- Define and monitor measures of platform effectiveness, including module adoption, policy compliance, plan/apply reliability, and time to remediate infrastructure drift or compliance violations.
- Support the company's commitment to risk management and protecting the integrity and confidentiality of systems and data.
Minimum Qualifications
- Education and/or experience typically obtained through a bachelor's degree in computer science, engineering, or a related technical field.
- Typically eight or more years of related experience in software engineering, cloud engineering, platform engineering, infrastructure engineering, DevOps, or a related technical discipline.
- Demonstrated strength in software engineering and systems design, including the ability to turn ambiguous technical problems into maintainable, testable solutions and reason about interfaces, state, failure modes, idempotency, and change impact.
- Demonstrated ability to execute complex technical work with general direction, independently make implementation decisions within established architecture and standards, and recognize when guidance or escalation is needed for novel or enterprise-wide decisions.
- Demonstrated customer-first approach, balancing internal customer and developer needs with security, reliability, and control requirements.
- Ability to respectfully challenge assumptions with data and technical reasoning, then disagree and commit by supporting and executing the final decision.
- Strong production programming experience in Python, Go, or a comparable general-purpose language used to build infrastructure tooling, services, controllers, or automation.
- Demonstrated experience developing and operating software, infrastructure tooling, or platform capabilities relied upon by other engineers, including testing, code review, versioning, and operational ownership.
- Strong hands-on experience with Terraform, including reusable module development, composition, automated testing, registry publishing, versioning, state management, and infrastructure change workflows.
- Experience with Ansible beyond basic playbooks, such as reusable roles or collections, execution environments, automated testing, linting, or Ansible Automation Platform/AWX.
- Experience implementing policy-as-code or infrastructure policy controls using OPA/Rego or comparable technologies.
- Strong knowledge of AWS infrastructure and security concepts, including IAM, networking, encryption, credential management, and secure configuration.
- Working knowledge of Kubernetes and containerized infrastructure sufficient to implement infrastructure and admission-control requirements.
- Experience implementing security, compliance, or change-management controls through infrastructure automation in a regulated or similarly controlled environment.
- Demonstrated ability to lead complex technical work, collaborate across engineering disciplines, and influence implementation decisions without direct authority.
- Strong written and verbal communication skills, including technical documentation, architecture decision records, implementation standards, and control documentation.
- Background and drug screen.
Preferred Qualifications
- Experience with HCP Terraform or Terraform Enterprise, including workspaces, run tasks, policy integration, state governance, and drift management.
- Experience developing internal developer platforms, infrastructure self-service tooling, or developer portals.
- Experience leading a complex infrastructure automation capability from design through production implementation with periodic architectural or stakeholder guidance.
- Experience building web-based internal engineering tools using React, Next.js, Angular, or a similar framework and backend/API technologies such as TypeScript, Python, or Go.
- Experience automating network infrastructure configuration, validation, compliance, or change-management workflows.
- Experience implementing federated identity, OIDC-based workload authentication, dynamic secrets management, or short-lived infrastructure credentials.
- Experience mapping automated infrastructure controls to regulatory or control frameworks such as PCI DSS, SOX ITGC, NYDFS Part 500, or FFIEC guidance.
- Experience in FinTech, banking, payments, or another highly regulated industry.
- Current AWS, Terraform, Kubernetes, or other relevant technical certification.
The above job description is not intended to be an all-inclusive list of duties and standards of the position. Incumbents will follow instructions and perform other related duties as assigned by their supervisor.
Physical Requirements
Working conditions consist of a normal office environment. Work is primarily sedentary and requires extensive use of a computer and involves sitting for periods of approximately four hours. Work may require occasional standing, walking, kneeling, and reaching. Must be able to lift 10 pounds occasionally and/or a negligible amount of force frequently. Requires visual acuity and dexterity to view, prepare, and manipulate documents and office equipment, including personal computers. Requires the ability to communicate with internal and/or external customers.
Employee must be able to perform essential functions and physical requirements of the position with or without reasonable accommodation.
Candidates responding to this posting must independently possess the eligibility to work in the United States at the date of hire.
The base pay scale for this position in:
Phoenix, AZ/ Chicago, IL per year is: $145,000 - $186,000.
Additionally, candidates are eligible for a discretionary incentive plan and benefits.
This pay scale is subject to change and is not necessarily reflective of actual compensation that may be earned, nor a promise of any specific pay for any specific candidate, which is always dependent on legitimate factors considered at the time of job offer. Early Warning Services takes into consideration a variety of factors when determining a competitive salary offer, including, but not limited to, the job scope, market rates and geographic location of a position, candidate’s education, experience, training, and specialized skills or certification(s) in relation to the job requirements and compared with internal equity (peers). The business actively supports and reviews wage equity to ensure that pay decisions are not based on gender, race, national origin, or any other protected classes.
Some of the Ways We Prioritize Your Health and Happiness
Healthcare Coverage – Competitive medical (PPO/HDHP), dental, and vision plans as well as company contributions to your Health Savings Account (HSA) or pre-tax savings through flexible spending accounts (FSA) for commuting, health & dependent care expenses.
401(k) Retirement Plan – Featuring a 100% Company Safe Harbor Match on your first 6% deferral immediately upon eligibility.
Paid Time Off – Flexible Time Off for Exempt (salaried) employees, as well as generous PTO for Non-Exempt (hourly) employees, plus 11 paid company holidays and a paid volunteer day.
12 weeks of Paid Parental Leave
Maven Family Planning – provides support through your Parenting journey including egg freezing, fertility, adoption, surrogacy, pregnancy, postpartum, early pediatrics, and returning to work.
And SO much more! We continue to enhance our program, so be sure to check our Benefits page here for the latest. Our team can share more during the interview process!
Early Warning Services, LLC (“Early Warning”) considers for employment, hires, retains and promotes qualified candidates on the basis of ability, potential, and valid qualifications without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote equal employment opportunity and affirmative action, in accordance with all applicable federal, state, and municipal laws. The company also prohibits discrimination on other bases such as medical condition, marital status or any other factor that is irrelevant to the performance of our employees.
Early Warning Services LLC is a proud participant in E-Verify, a federal program to help ensure a legal and authorized workforce. As part of our hiring process, we electronically verify the employment eligibility of all new hires through E-Verify. For more information on your rights and responsibilities under E-Verify please visit Home | E-Verify.