Cloud Infrastructure and Security Engineer

Harris Associates

Chicago (IL)

On-site

USD 190,000 - 210,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical insurance
Dental and vision insurance
Paid time off
Profit sharing
401k plan
Tuition reimbursement
Commuter benefits
Wellness programs
Volunteer programs

Job summary

Harris Associates is seeking a Cloud Infrastructure and Security Engineer in Chicago. You will own production-grade cloud environments, secure identities and networks, and automate infrastructure across Azure, Terraform, and AKS.

The role requires a security-first mindset, strong IaC skills, and close collaboration with DevOps and data teams to keep a regulated environment safe and scalable. Expect a high-impact, hands-on position with on-call rotations and monthly patch windows, contributing to

Qualifications

  • 7+ years of hands-on cloud infrastructure engineering experience.
  • Terraform or a comparable IaC tool with state management and safe imports.
  • RBAC and least-privilege design fundamentals.
  • Hub-and-spoke networking, firewalls/NSGs, DNS.
  • CI/CD with Azure DevOps; scripting in PowerShell and/or Bash.
  • A security-first mindset with comfort in change-control environments.
  • Clear written communication skills for documenting decisions.

Responsibilities

  • Build and manage AI/LLM-based workflows with security review and least-privilege discipline.
  • Patch estate and serve as on-call first responder for infra and security issues.
  • Author and maintain Terraform across multiple repositories and regions.
  • Provision and govern Microsoft Entra ID with least-privilege grants.
  • Design and operate hub-and-spoke cloud networking and policy.
  • Provision hardened Azure VMs and golden images; manage Packer pipelines.
  • Support AKS and DevOps platform with workload identity and service mesh.
  • Govern Databricks, Snowflake, Power BI/Microsoft Fabric access and security.
  • Monitor with Azure Monitor; lead RCAs across pipelines and capacity.
  • Deliver changes via Azure Pipelines with gated Terraform flow.

Skills

Cloud infrastructure
Terraform
Azure DevOps
PowerShell
Bash
Identity management
Networking
Kubernetes
Security mindset

Tools

Packer
Databricks
Snowflake
Power BI
Microsoft Fabric

Job description

Cloud Infrastructure and Security Engineer

At Harris, the true value of what makes us successful is found in our people. It is our unique mix of cultures, experiences, beliefs and backgrounds that sets Harris apart from the rest. We constantly strive to cultivate, nurture and amplify an unparalleled environment, where we value intellectual curiosity and uniqueness of thought. Inclusion is embedded in the very fabric of our culture of collaboration and openness.

We understand that a job description only tells one part of a broader story, and Harris is seeking dynamic candidates who can add to our best-in-class environment. We recognize that qualifications can be gained through both traditional and non-traditional paths, and we are committed to considering candidates who possess the potential to be excellent in this role regardless of prior experiences.

Therefore we encourage ALL interested individuals to submit their applications, even if they do not meet every requirement outlined in the job description.

Position Summary

InfraSec builds and secures Harris Associates' cloud foundation on Microsoft Azure. The team runs the estate as code - identities, networks, virtual machines, Kubernetes, and data platforms are defined, reviewed, and deployed through automated pipelines rather than managed by hand. It's a lean, hands‑on team that partners closely with DevOps, Data, and Application teams, and holds a high bar for security given the firm's regulated environment.

The Cloud Infrastructure and Security Engineer is a hands‑on, individual‑contributor role at the center of this infrastructure-as-code operation, working across environments and cloud regions with deep involvement in identity, networking, compute, and data‑platform security. We're looking for an experienced infrastructure or security engineer who thinks in systems, is comfortable owning production‑grade cloud environments, and wants the scope to shape how a growing platform is built and secured.

Responsibilities may include but are not limited to:
  • AI-enabled tooling: Build and manage AI/LLM-based skills and agentic workflows that give the team leverage, governed under the same security review and least‑privilege discipline as any other credentialed automation, with human review before anything ships.
  • Patching and on‑call: Share the team's operational rotations — patch the estate roughly three to four Saturdays a year, and serve as on‑call first responder for infrastructure and security issues about one week a month, resolving directly or escalating as needed.
  • Infrastructure as code: Author and maintain Terraform across roughly 18 repositories, multiple environments and regions, with Azure Storage state backends — holding the line on version/provider discipline, import safety, and plan‑diff review.
  • Identity and access management: Provision and govern Microsoft Entra ID — app‑role and role‑assignable groups, PIM/JIT, Conditional Access, Workload Identity Federation, and Microsoft Graph — designing least‑privilege grants and auditing existing ones.
  • Cloud networking: Design and operate hub‑and‑spoke topology, management‑group policy and custom roles, NSG/firewall rules, routing, and trusted network locations, and troubleshoot when it breaks.
  • Virtual machines and golden images: Provision hardened Azure VMs from a shared module (secure boot, vTPM, encryption at host, Hybrid Benefit), and build/maintain golden Windows Server images with Packer.
  • Kubernetes and containers: Support the AKS platform alongside DevOps — workload identity, service‑mesh and egress behavior, and connectivity troubleshooting.
  • Data and analytics platform access: Govern access and security settings for Databricks, Snowflake, Power BI/Microsoft Fabric, and Purview, and manage platform‑level governance.
  • Monitoring and incident response: Keep signal high and noise low with Azure Monitor, and lead root‑cause investigations across pipelines, capacity, and connectivity.
  • CI/CD, review, and automation: Deliver every change through Azure Pipelines and a gated Terraform flow, review pull requests for what CI can’t catch, and improve the automation itself.
Qualifications
Required
  • 7+ years of hands‑on cloud infrastructure engineering experience, with production‑grade experience on a major cloud platform (Azure preferred).
  • Strong Infrastructure-as-Code skills - Terraform or a comparable tool - including state management, provider discipline, and safely importing existing resources.
  • Solid grounding in identity and access fundamentals: RBAC, service principals/managed identities, and least‑privilege design.
  • Cloud networking expertise: hub‑and‑spoke or equivalent topologies, firewalls/NSGs, routing, and DNS.
  • CI/CD delivery experience with a platform like Azure DevOps, plus scripting in PowerShell and/or Bash.
  • A security‑first mindset, with comfort working inside change‑control and approval gates.
  • Clear written communication skills for documenting decisions and processes.
Preferred
  • Kubernetes/AKS operations experience - node pools, workload identity, and service mesh.
  • Experience with Packer or golden‑image build pipelines.
  • Data‑platform governance experience (e.g., Databricks, Snowflake, Power BI/Microsoft Fabric).
  • Experience in a regulated or financial‑services environment.
Special Requirements

This role shares the team's operational rotations: a monthly Saturday patching cycle (roughly three to four Saturdays per year) and a weekly on‑call rotation (about one week per month) as first responder for infrastructure and security issues. Occasional early‑morning, evening, or weekend work may be required to support patch windows and critical incidents. Flexibility with working hours is key.

We offer a comprehensive benefits package designed to integrate life and work and to support our employees and their families. Benefits include, but are not limited to; medical, prescription drug, dental and vision insurance, paid time off, profit sharing plan, 401k plan, tuition reimbursement, commuter and holistic wellness benefits along with volunteer programs.

Actual annual base salaries may vary based on factors including but not limited to education, training, experience, and other job‑related factors. If hired, base pay will be determined on an individualized basis and is only one part of the total compensation package, which, depending on the position, may also include a discretionary performance bonus and other Harris sponsored benefit programs.

Expected range for this Chicago‑based role

$190,000 - $210,000 USD

Equal Employment Opportunity Policy Statement

Harris Associates L.P. pursues a policy of equal opportunity in all areas of employment including recruitment, hiring, training, compensation, benefits, advancement, and treatment on the job. This means that Harris does not discriminate against employees, or qualified applicants, based on an individual's race, color, religion, creed, sex, age, national origin, physical disability, sexual orientation, trans‑gender status, transsexual status, status as a veteran or disabled veteran, genetic information or for any other reason prohibited by law. Harris reserves the right to review publicly available information about applicants (i.e., via social networking sites), to the extent permissible under applicable law.

Reasonable Accommodation Notice

We provide reasonable accommodation for individuals with disabilities and disabled veterans in job application procedures. If you have any difficulty using our online system and you need an accommodation due to a disability, you may use the alternative email address below to contact us about your interest in employment at HR@harrisassoc.com or you can call us at 312‑646‑3600.

Privacy Statement

The information you send to us is used for employment purposes only. What you send is kept confidential—we will not give your personal information to outside parties without your consent.

Confidential Self-ID Questions

Harris Associates is committed to providing equal employment opportunity to applicants and employees regardless of race, color, religion, gender, sexual orientation, pregnancy, gender identity, national origin, age, disability (including association with a person with a disability), genetic information, veteran status, military status, marital status, order of protection status, unfavorable military discharge, arrest record (or criminal history record ordered expunged, sealed, or impounded), and conviction record (subject to applicable legal exceptions), or any other characteristic protected by applicable law.

To enable us to evaluate the effectiveness of our equal employment opportunity policy and diversity, equity, and inclusion initiatives, we ask you to complete the self‑identification survey below. This information will be treated as confidential and in accordance with the Firm’s Privacy Policy. Data collected will be used on a no‑name basis for monitoring and reporting requirement purposes only.

DISABILITY STATUS: You are considered to have a disability if you have a physical or mental impairment or medical condition that substantially limits a major life activity, or if you have a history or record of such an impairment or medical condition.

Disabilities include, but are not limited to: Autism, Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, or HIV/AIDS. Blind or low vision, Cancer, Cardiovascular or heart disease, Celiac disease, Cerebral palsy, Deaf or hard of hearing, Depression or anxiety, Diabetes, Epilepsy, Gastrointestinal disorders, for example, Crohn's Disease, or irritable bowel syndrome, Intellectual disability, Missing limbs or partially missing limbs. Nervous system condition for example, migraine headaches, Parkinson’s disease, or Multiple sclerosis. Psychiatric conditions, for example, bipolar disorder, schizophrenia, PTSD, or major depression.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Portfolio Implementation Specialist
Senior Portfolio Implementation Specialist

Harris Associates • Chicago (IL)

On-site
USD 95,000 - 110,000
Medical insurance
401k plan
Tuition reimbursement
+2
Senior GRC Manager
Senior GRC Manager

MediSolution • North Carolina

Hybrid
USD 130,000 - 150,000
Full benefits package
Vacation + personal days
Employee stock ownership
+1
Data Analyst, Data Ops
Data Analyst, Data Ops

Harris Associates • Chicago (IL)

Hybrid
USD 80,000 - 100,000
Medical and dental insurance
401(k) plan
Tuition reimbursement
+1
Senior Performance Analyst
Senior Performance Analyst

Harris Associates • Chicago (IL)

Hybrid
USD 95,000 - 110,000
Medical, dental and vision insurance
401k plan
Tuition reimbursement
+2
Cloud Security Engineer (Job 1445)
Cloud Security Engineer (Job 1445)

DLH Corp • Bethesda (MD)

On-site
USD 150,000 - 158,000
Director of People Analytics Chicago, Illinois, United States
Director of People Analytics Chicago, Illinois, United States

Harrisassoc • Chicago (IL)

On-site
USD 170,000 - 200,000
Data Analyst, Data Ops
Data Analyst, Data Ops

Harris | Oakmark • Chicago (IL)

On-site
USD 95,000 - 110,000
Medical, prescription drug, dental, and vision insurance
Paid time off
401(k) plan
+1
Information Security Specialist (Remote)
Information Security Specialist (Remote)

Harris Computer • North Dakota

On-site
USD 80,000 - 110,000
Competitive compensation package
Health Insurance (medical, dental, vision)
Paid Vacation
+1
Senior GRC Manager
Senior GRC Manager

MediSolution • Northern (KY)

Hybrid
USD 135,000 - 165,000
Full benefits package (medical, dental
Flexible work arrangements
3 weeks vacation + 5 personal days
+2
Support Analyst
Support Analyst

MediSolution • Maine

Hybrid
USD 50,000 - 55,000