IaC Engineer

Toyota Tsusho Systems US, Inc.

Plano (TX)

On-site

USD 120,000 - 170,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Toyota Tsusho Systems US, Inc. is seeking an Infrastructure as Code Security Engineer to design, build, and maintain secure, scalable IaC for AI security workloads.

You will own the IaC layer across our container stack including EKS, Docker, and Helm, ensuring secure, repeatable provisioning and compliance with security best practices. The ideal candidate will embed security into infrastructure automation and collaborate with DevSecOps, AI security engineers, and platform teams to enable rapid,

Qualifications

  • Bachelor's degree preferred or equivalent experience
  • Hands-on experience designing and implementing secure IaC for cloud/container environments
  • Deep production experience managing Kubernetes, including EKS cluster administration
  • Strong experience with Terraform modules and secure provisioning patterns
  • Hands-on experience building and managing Docker images and Helm charts
  • Experience integrating infrastructure automation into CI/CD pipelines with automated validation

Responsibilities

  • Design, implement, and maintain secure IaC solutions for cloud and containerized environments supporting AI security workloads
  • Own and manage EKS clusters, including node group configurations, networking policies, RBAC, and pod security
  • Develop and maintain hardened Terraform modules and reusable infrastructure patterns with built-in security controls
  • Build and manage Docker images and Helm charts with security-first principles and signed artifacts
  • Integrate security guardrails into CI/CD pipelines with automated policy checks (OPA/Gatekeeper, Checkov, tfsec)
  • Automate environment provisioning, scaling, configuration, and release processes with immutable infrastructure
  • Collaborate with AI security engineers, platform teams, and DevSecOps to support threat modeling and incident response
  • Troubleshoot and remediate infrastructure security issues across Kubernetes, Terraform, CI/CD, and container platforms
  • Enforce infrastructure compliance with security policies and regulatory frameworks
  • Document secure infrastructure patterns and runbooks for the AI security team

Skills

Kubernetes
Terraform
Docker
Helm
CI/CD
Security engineering
RBAC
OPA/Gatekeeper

Education

Bachelor's degree preferred

Tools

AWS
Checkov
tfsec
Gatekeeper

Job description

About TTS-US

Founded in 2011, Toyota Tsusho Systems US, Inc. (TTS-US) is a Toyota group company that develops IT solutions wherever global businesses operate. Transforming into a technology and mobility company, TTS-US with its 8 TTS affiliates worldwide is establishing a secure and resilient Toyota global value chain. The creative capacity to forge such limitless business opportunities is one of the strengths of Toyota Tsusho Systems.

Summary

We are seeking an Infrastructure as Code (IaC) Security Engineer to design, build, and maintain secure, scalable, and automated infrastructure solutions that underpin our AI security development platform. This role is responsible for owning the IaC layer across our container and orchestration stack—including EKS, Docker, and Helm—ensuring that all infrastructure is provisioned securely, repeatably, and in compliance with security best practices. The ideal candidate will embed security into every phase of infrastructure automation, from Terraform modules to CI/CD pipelines, enabling the AI security team to deliver rapidly without compromising the integrity of our environments.

Key Responsibilities
  • Design, implement, and maintain secure Infrastructure as Code solutions for cloud and containerized environments supporting AI security workloads
  • Own and manage EKS clusters, including node group configurations, networking policies, RBAC, and pod security standards to support secure AI model development and deployment
  • Develop and maintain hardened Terraform modules, configurations, and reusable infrastructure patterns with built-in security controls (e.g., least‑privilege IAM, encryption‑at‑rest, network segmentation)
  • Build and manage Docker images and Helm charts with security‑first principles—image scanning, minimal base images, secrets management, and signed artifacts
  • Integrate security guardrails into CI/CD pipelines, including automated policy checks (e.g., OPA/Gatekeeper, Checkov, tfsec) for infrastructure deployments
  • Automate environment provisioning, scaling, configuration, and release processes with a focus on immutable infrastructure and drift detection
  • Collaborate with AI security engineers, platform teams, and DevSecOps to ensure infrastructure supports threat modeling, vulnerability management, and incident response requirements
  • Troubleshoot and remediate infrastructure security issues across Kubernetes, Terraform, CI/CD, and container platforms
  • Enforce infrastructure compliance with organizational security policies, regulatory frameworks (e.g., NIST, CIS Benchmarks), and operational best practices
  • Document secure infrastructure patterns, deployment runbooks, and automation workflows for the AI security development team
Requirements
  • Bachelor's degree preferred and/or equivalent relevant experience considered
  • Strong hands‑on experience designing and implementing secure Infrastructure as Code solutions in cloud and containerized environments
  • Deep production experience managing Kubernetes, including EKS cluster administration, networking, RBAC, and workload security
  • Strong experience with Terraform, including development of reusable modules and secure infrastructure provisioning patterns
  • Hands‑on experience building and managing Docker images and Helm charts for containerized deployments
  • Experience integrating infrastructure automation into CI/CD pipelines with automated validation and deployment workflows
  • Strong understanding of infrastructure security best practices, including IAM, encryption, secrets management, and network segmentation
  • Experience troubleshooting and remediating issues across Kubernetes, Terraform, containers, and deployment pipelines
  • Ability to collaborate effectively with engineering, platform, and DevSecOps teams in a fast‑paced environment
Preferred Qualifications
  • Experience supporting AI, ML, or security‑focused platform workloads in Kubernetes‑based environments
  • Experience with AWS and cloud‑native services related to container orchestration, networking, and infrastructure automation
  • Familiarity with infrastructure security and policy enforcement tools such as OPA/Gatekeeper, Checkov, tfsec, or similar solutions
  • Knowledge of compliance and security frameworks such as NIST, CIS Benchmarks, or related infrastructure governance standards
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IaC Engineer
IaC Engineer

Toyota Tsusho Systems Corporation • Plano (TX)

On-site
USD 110,000 - 140,000
Secure IaC Engineer – Kubernetes, Terraform & CI/CD
Secure IaC Engineer – Kubernetes, Terraform & CI/CD

Toyota Tsusho Systems US, Inc. • Plano (TX)

On-site
USD 120,000 - 170,000
Secure IaC Engineer for Cloud, Kubernetes & CI/CD
Secure IaC Engineer for Cloud, Kubernetes & CI/CD

Toyota Tsusho Systems Corporation • Plano (TX)

On-site
USD 110,000 - 140,000
Senior Member of Technical Staff - Infrastructure Security
Senior Member of Technical Staff - Infrastructure Security

Xcede • San Francisco (CA)

On-site
USD 120,000 - 160,000
Significant compensation and equity opportunity
Work across cloud, Kubernetes, GPU infrastructure, CI/CD, and platform engineering
IaC Security Engineer at VirtualVocations Saint Charles, MO
IaC Security Engineer at VirtualVocations Saint Charles, MO

Fairweather, LLC • Saint Charles (MO)

On-site
USD 110,000 - 160,000
AWS Infrastructure Engineer - Senior
AWS Infrastructure Engineer - Senior

Compunnel, Inc. • Columbus (OH)

On-site
USD 100,000 - 130,000
Remote IaC Security Engineer: Secure Cloud & EKS Automation
Remote IaC Security Engineer: Secure Cloud & EKS Automation

Fairweather, LLC • Saint Charles (MO)

On-site
USD 110,000 - 160,000
Senior Security Infrastructure Engineer — Private AI Cloud
Senior Security Infrastructure Engineer — Private AI Cloud

Aionia Group • Reston (VA)

On-site
USD 110,000 - 150,000
Cloud Infrastructure Architect, Okta Federal
Cloud Infrastructure Architect, Okta Federal

United States Digital Space LLC • Washington

On-site
USD 180,000 - 240,000
Senior Software Engineer – Infrastructure as Code, IaC
Senior Software Engineer – Infrastructure as Code, IaC

Jobtailor • Kentucky

On-site
USD 90,000 - 120,000