Principal - Cloud Engineer

Ally

Charlotte (NC)

On-site

USD 110,000 - 180,000

Full time

9 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Annual incentive plan
Relocation assistance
Total rewards program

Job summary

Ally Financial seeks a Principal Cloud Engineer to lead enterprise cloud resiliency efforts in a regulated financial services environment. You will shape multi-region architectures, drive chaos engineering programs, and partner with application teams to validate recovery readiness.

Responsibilities include designing ARC patterns, enforcing least-privilege IAM, and building automation with Terraform and GitLab CI/CD to deliver reliable, auditable recovery capabilities across the business.

Qualifications

  • Bachelor's degree in Computer Science, Information Systems, or related field.
  • 5+ years of hands-on AWS cloud engineering or SRE in a large, regulated environment.
  • Expert knowledge of AWS reliability services (Lambda, ECS, RDS/Aurora, S3, Route 53, etc.).
  • Hands-on experience with ARC, Resilience Hub, and FIS, including chaos experiments.

Responsibilities

  • Lead architecture discovery with stakeholders to define recovery objectives and multi-region needs.
  • Design multi-region AWS architectures (Active/Active, Warm Standby, Backup and Restore).
  • Implement ARC patterns, readiness checks, routing controls, and safe failover processes.
  • Evaluate Resilience Hub findings and drive remediation to measurable outcomes.
  • Create Terraform modules and CI/CD pipelines with GitLab for secure deployments.

Skills

Bachelor's degree in CS/IS
AWS cloud engineering
AWS reliability services
ARC / Resilience Hub / FIS
Multi-region architectures
IAM least-privilege
Terraform + GitLab CI/CD
AWS migration services
Python automation
FinOps basics

Education

Bachelor's degree in CS/IS

Tools

Terraform
GitLab CI/CD
AWS ARC

Job description

Charlotte, NC

Full time

R2600866

Ally and Your Career

Ally Financial only succeeds when its people do - and that’s more than some cliché people put on job postings. We love this stuff! We see our people as, well, people - with interests, families, friends, dreams, and causes that are all important to them. Our focus is on the health and safety of our teammates as well as work-life balance and diversity and inclusion. From generous benefits to a variety of employee resource groups, we strive to build paths that encourage employees to stretch themselves professionally. We want to help you grow, develop, and learn new things. You’re constantly evolving, so shouldn’t your opportunities be, too?

Work Schedule

Ally designates roles as (1) fully on-site, (2) hybrid, or (3) fully remote. Hybrid roles are generally expected to be in the office a certain number of days per week as indicated by your manager. Your hiring manager will discuss this role's specific work requirements with you during the hiring process. All work requirements are subject to change at any time based on leader discretion and/or business need.

The Opportunity

Seeking an innovative, hands‑on Principal Cloud Engineer who excels at the intersection of cloud resilience engineering, infrastructure automation, and technical leadership. In this role, you will define and drive enterprise‑wide cloud reliability strategy — designing multi‑region architectures, leading chaos engineering programs, building recovery tooling, and partnering with application teams to achieve measurable, validated resiliency outcomes in a regulated financial services environment.

The Work Itself
  • Lead architecture discovery sessions with application, infrastructure, security, and business stakeholders to define recovery objectives, dependency maps, and multi-region requirements
  • Design multi-region AWS architectures — Active/Active, Warm Standby, Pilot Light, and Backup and Restore — aligned to application criticality, RTO/RPO targets, and compliance requirements
  • Design and implement AWS Application Recovery Controller (ARC) patterns — readiness checks, routing controls, safety rules, and zonal shift — to enable deliberate, auditable traffic management and verify recovery environments are prepared before any failover event
  • Evaluate AWS Resilience Hub to identify resilience gaps, map recovery policies, and drive remediation to measurable objectives
  • Define traffic management and failover strategies using Amazon Route 53, CloudFront, load balancers, API Gateway, and health checks
  • Design backup and recovery patterns using AWS Backup, S3, RDS/Aurora cross‑region capabilities, encryption, and restore validation procedures
  • Produce architecture decision records documenting service selection, alternatives considered, constraints, and expected outcomes
  • Define secure AWS landing‑zone controls and design IAM roles, permission boundaries, federation, and least‑privilege access models for applications, automation, and platform services
  • Establish infrastructure and application‑performance monitoring using Amazon CloudWatch, Dynatrace, and distributed tracing; build log forwarding to enterprise analytics platforms including Splunk; design operational dashboards connecting infrastructure health, security findings, and recovery readiness indicators
  • Develop FinOps operating models covering account ownership, tagging, chargeback, budgets, and anomaly detection; forecast cloud consumption and build cost‑optimization business cases covering rightsizing, Savings Plans, and Reserved Instances
  • Evaluate migration strategy patterns and design migration approaches using EC2, VPC, S3, RDS, CloudFormation, containers, and serverless services aligned to business criticality and RTO/RPO targets
  • Use AWS Migration Hub, Application Migration Service, and Database Migration Service to coordinate and execute migrations; define data migration, validation, reconciliation, rollback, and synchronization procedures aligned to RTO/RPO requirements with tested cutover plans
  • Validate migrated workloads through functional, performance, backup, restore, and disaster‑recovery testing
  • Create reusable Terraform modules for VPC, IAM, ECS, RDS, S3, and monitoring; design GitLab CI/CD pipelines with validation, security scanning, plan review, approval controls, and drift detection
  • Implement blue‑green, canary, rolling, and controlled failover deployment patterns; build deployment safety controls including pre‑deployment validation, health gates, blast‑radius reduction, and automated rollback procedures
  • Integrate cost‑estimation tooling into pipelines and automate account and regional deployment workflows while preserving isolation, least privilege, and clear ownership
  • Design and run controlled chaos engineering experiments using AWS Fault Injection Service (FIS) targeting compute, database, network, and dependency layers with defined hypotheses, abort criteria, and observability instrumentation
  • Create game days and disaster recovery exercises involving application owners, infrastructure, cybersecurity, and business stakeholders; develop recovery runbooks for AZ impairment, regional degradation, database failure, and capacity exhaustion; establish a recovery‑testing calendar covering backup restoration, failover, and failback
  • Define resilience engineering standards covering dependency mapping and failure‑domain analysis; use experiment results to surface single points of failure and drive remediation with risk owners; coach application teams on resilience patterns and operational ownership
  • Create executive‑ready reporting summarizing recovery readiness, experiment coverage, open resilience risks, and reliability trends for leadership
The Qualifications We’re Looking For
  • Bachelor's degree in Computer Science, Information System, or other relevant field of study preferred
  • 5+ years of hands‑on experience in AWS cloud engineering or site reliability engineering in a large‑scale, regulated environment
  • Expert knowledge of AWS reliability services: Lambda, ECS, RDS/Aurora, DynamoDB, S3, SQS, EventBridge, CloudWatch, Route 53, CloudFront, API Gateway, and VPC networking
  • Hands‑on experience with AWS Application Recovery Controller (ARC), AWS Resilience Hub, and AWS Fault Injection Service (FIS) — including readiness checks, routing controls, resiliency scoring, and chaos experiment design across compute, database, and network layers
  • Experience designing multi‑region architectures across Active/Active, Warm Standby, Pilot Light, and Backup and Restore patterns
  • Expert‑level AWS IAM knowledge including least‑privilege design, permission boundaries, federation, and Service Control Policies (SCPs)
  • Proficiency in Terraform for infrastructure as code and strong CI/CD experience with GitLab including pipeline design, OIDC authentication, and deployment safety controls
  • Experience with AWS migration services: Migration Hub, Application Migration Service, Database Migration Service, and Application Discovery Service
  • Proficiency in Python for automation and scripting; experience with Amazon CloudWatch, Dynatrace, Splunk, and distributed tracing
  • Experience with FinOps practices including cost allocation, tagging, rightsizing, Savings Plans, and consumption forecasting
  • Ability to lead resilience reviews, production readiness assessments, and architecture decisions; strong communication skills to translate technical recovery risks into executive‑ready reporting and business outcomes
  • Comfortable operating as both a principal individual contributor and a technical leader for distributed engineering teams
  • Preferred Certifications: AWS Certified Solutions Architect – Professional, AWS Certified DevOps Engineer – Professional, or equivalent advanced AWS certifications
How We’ll Have Your Back

Ally's compensation program offers market‑competitive base pay and pay‑for‑performance incentives (bonuses) based on achieving personal and company goals. Our Total Rewards program includes industry‑leading compensation and benefits plus additional incentives that are designed to meet your needs and those of your family so you can get the most out of your career and your life, including:

Time Away

Program starts at 20 paid time off days in addition to 11 paid holidays and 8 hours of volunteer time off yearly (time off days are prorated based on start date and program varies based on full or part‑time status and management level).

Planning for the Future

plan for the near and long term with an industry‑leading 401K retirement savings plan with matching and company contributions, student loan pay downs and 529 educational save up assistance programs, tuition reimbursement, employee stock purchase plan, and financial learning center and financial coach access.

Supporting your Health & Well‑being

flexible health and insurance options including medical, dental and vision, employee, spouse and child life insurance, short‑and long‑term disability, pre‑tax Health Savings Account with employer contributions, Healthcare FSA, critical illness, accident & hospital indemnity insurance, and a total well‑being program that helps you and your family stay on track physically, socially, emotionally, and financially.

Building a Family

adoption, surrogacy and fertility assistance as well as paid parental and caregiver leave, Dependent Day Care FSA back‑up child and adult/elder care days and childcare discounts.

Work‑Life Integration

other benefits including Mentally Fit Employee Assistance Program, subsidized and discounted Weight Watchers program and other employee discount programs.

Other Compensations

depending on the role for which you are considered, you may be eligible for travel allowances, relocation assistance, a signing bonus and/or equity.

To view more detailed information about Ally’s Total Rewards, please visit this link: https://www.ally.com/content/dam/pdf/corporate/ally-total-rewards-snapshot.pdf

Who We Are

Ally Financial is a customer‑centric, leading digital financial services company with passionate customer service and innovative financial solutions. We are relentlessly focused on "Doing it Right" and being a trusted financial‑services provider to our consumer, commercial, and corporate customers. For more information, visit www.ally.com .

Ally is an equal opportunity employer committed to diversity and inclusion in the workplace. All qualified applicants will receive consideration for employment without regard to age, race, color, sex, religion, national origin, disability, sexual orientation, gender identity or expression, pregnancy status, marital status, military or veteran status, genetic disposition or any other reason protected by law.

In accordance with the Americans with Disabilities Act, if after review of the position expectations, you believe that you may need a medical accommodation to fulfill the duties of this role, please email hrpolicy@ally.com with details of your accommodation request.

Base Pay Range

$110,000.00 - $180,000.00

An individual's position in the range is determined by the specific role, the scope and responsibilities of the role, work experience, education, certification(s), training, and additional qualifications. We review internal pay, the competitive market, and business environment prior to extending an offer.

Incentive Compensation

This position is eligible to participate in our annual incentive plan.

We all work better as allies. Join a team that thrives on doing it right — whether we're helping people live their best financial lives or helping each other grow in our careers.

We're a leading financial services company serving over 11M customers through banking, auto financing, insurance and investment services. Our team's approach of celebrating differences and lifting each other up is consistently recognized on Fortune's 100 Best Companies to Work For list. Here, you'll find people who care about doing work that matters and making an impact in the communities we serve. Good enough is never enough for us — we're always looking for ways to be better, together.

CCPA Notice (https://www.ally.com/content/dam/pdf/corporate/ally_careers_ccpa_disclosures_ca_residents.pdf)

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Principal - Cloud Engineer
Principal - Cloud Engineer

1611 Ally Bank • Charlotte (NC)

Hybrid
USD 110,000 - 180,000
Time Off
401K retirement plan
Health benefits
+1
Principal - Software Engineer
Principal - Software Engineer

1611 Ally Bank • Charlotte (NC)

Hybrid
USD 110,000 - 180,000
Principal - Cloud Engineer
Principal - Cloud Engineer

Ally Bank • Charlotte (NC)

Hybrid
USD 110,000 - 180,000
Time Off
401K with matching
Health insurance
+1
Senior Software Engineer
Senior Software Engineer

Ally • Charlotte (NC)

Hybrid
USD 85,000 - 150,000
Time away
401K with match
Tuition reimbursement
+2
Director - Digital Platforms
Director - Digital Platforms

Ally • Charlotte (NC)

Hybrid
USD 125,000 - 190,000
Principal - Data Engineering
Principal - Data Engineering

4001 Motors Insurance Corp. • New York (NY)

Hybrid
USD 120,000 - 180,000
Senior Software Engineer
Senior Software Engineer

1611 Ally Bank • Charlotte (NC)

On-site
USD 85,000 - 150,000
Health insurance
401K matching
Bonuses and equity
+1
Cloud Security Principal Engineer
Cloud Security Principal Engineer

Ally-Financial • Charlotte (NC)

On-site
USD 110,000 - 180,000
Time Away including paid holidays
401K retirement plan
Health, dental, vision coverage
+1
Senior Analyst, Advanced Business Analytics
Senior Analyst, Advanced Business Analytics

1611 Ally Bank • United States

Hybrid
USD 90,000 - 150,000
Time off & holidays
401(k) plan
Annual incentive
Principal Database Security
Principal Database Security

Ally • Charlotte (NC)

Hybrid
USD 110,000 - 180,000
Time off + holidays
401(k) retirement plan
Employee stock purchase plan