About Northern Trust
As a global leader in innovative wealth management, asset servicing, asset management and banking services, Northern Trust (Nasdaq: NTRS) is proud to guide the world's most successful individuals, families, corporations and institutions.
Since 1889, we have aligned our efforts with our three guiding Principles That Endure: Service, Expertise, and Integrity. Together, they reflect the three cornerstones of business conduct which we strive to instill in our employees, whom we call partners, and to provide to our clients and the communities we serve worldwide.
With more than 135years of financial experience and over 24,000 partners, we serve the world's most sophisticated clients using leading technology and exceptional service.
Job Description Role Summary
We're looking for a UNIX Engineering SME who brings traditional platform depth along with modern engineering practices. You'll help lead the design, deployment, and lifecycle of mission‑critical UNIX platforms ( RHEL, AIX, Ubuntu) and services, while contributing to DevOps tooling, Git‑driven workflows, hybrid cloud strategies with an automation and engineering mindset. This is a key role in a high‑trust team that powers secure, compliant infrastructure for a global financial institution. Expect deep technical challenges, high visibility, and opportunities to influence platform direction.
Key Responsibilities
Core UNIX Engineering & Support
- - Design, secure, build, and maintain resilient UNIX environments across AIX 7.x (VIOS, NPIV), Ubuntu, and RHEL 6-10 (on physical, virtual, and hybrid platforms).
- - Own OS lifecycle strategy: patching, upgrades, security baselines, and hardware refresh planning.
- - Maintain HA solutions (Pacemaker, HACMP, RH Cluster Suite) and performance‑tuned enterprise systems.
DevOps, SRE & Automation
- - Embrace an SRE mindset: treat infrastructure as code, prioritize availability and observability, and automate toil.
- - Automate provisioning, compliance checks, and config enforcement using Ansible, AAP, AWX, CFEngine, and scripting (bash/ansible/Python).
- - Use GitHub for source control, peer‑reviewed automation pipelines, change tracking, and documentation versioning.
- - Contribute to CI/CD workflows for infrastructure as code deployments, and integrate with enterprise tools like ServiceNow, Jenkins, or GitHubActions.
Security
- - Ensure UNIX systems are hardened and compliant with security frameworks (e.g., CIS Benchmarks, NIST, FFIEC, ISO 27001).
- - Manage OS‑level security policies including firewall rules, kernel parameters, selinux policies and secure configurations.
- - Integrate host systems with PAM, LDAP, and CyberArk, Conjur for identity and privileged access management.
- - Support audit, forensic, and security event investigations in coordination with InfoSec teams.
- - Regularly review and remediate security vulnerabilities identified by Qualys, Nessus, or other scanning tools.
- - Contribute to incident response planning, patching SLAs, and compliance reporting.
- - Design and maintain logging, audit trails, and syslog/SIEM integrations (Splunk, QRadar, etc.).
Authentication, Authorization, and Directory Services
- - Integrate UNIX systems with enterprise identity management platforms using LDAP, RHDS, Kerberos, PAM, and SSSD.
- - Implement and enforce secure access controls, sudo policies, and RBAC schemes.
- - Collaborate with IAM and InfoSec teams on audit readiness, access provisioning, and PAM integrations.
Monitoring, Reliability & Incident Response
- - Integrate systems with monitoring tools like Dynatrace, vROps, and custom health scripts.
- - Support alerting, auto‑remediation, and telemetry for performance and availability.
- - Participate in on‑call rotations, DR testing, and RCA for high‑impact incidents.
Hybrid Cloud & Platform Modernization
- - Support UNIX workloads running on VMware (vSphere/vSAN/vXrail) and prepare platforms for future cloud integration.
- - Assist with cloud‑readiness assessments, infrastructure modernization efforts, and immutable infrastructure adoption.
- - Collaborate with Cloud, DevOps, and Cybersecurity teams on secure hybrid operating models.
Documentation & Governance
- - Maintain robust documentation in Confluence: HLD, LLD, SOPs, DR plans, build guides, access policies, GitHub repositories, and architectural decisions.
- - Ensure all platforms and automation meet compliance standards (CIS, FFIEC, SOX, ISO 27001).
- - Lead or contribute to engineering design reviews, change boards, and audit remediation efforts.
Required Skills and Experience
Technical Requirements
- - 10 + years in UNIX engineering across AIX, RHEL and Ubuntu, with deep expertise in large enterprise environments.
- - Strong understanding of centralized authentication/authorization using LDAP, Kerberos, PAM, SSSD, RHDS, and Active Directory integration.
- - Proficiency in shell scripting (bash, ksh, sh); strong familiarity with Python, and Ansible.
- - Hands‑on experience with tools like:
- o Red Hat Satellite, CFEngine, PowerVC, LV