Senior Systems Engineer

Garnaut Global

Washington

On-site

USD 180,000 - 240,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Garnaut Global seeks a senior engineer to own the operational layer of a fast-moving research and technology environment. You will run and harden the platform, reporting to the CTO, with room to develop further.

You will work with software engineers to maintain a modern stack: Linux, macOS endpoints, AWS, Cloudflare, and ZTNA, and you will lead DevSecOps—CI/CD, secrets management, IdAM, and overall security posture.

Qualifications

  • Five+ years of experience building and running production systems.
  • Strong opinions about technologies and tools; self-directed, disciplined, and honest.
  • Proven ability to design, ship, scale and recover complex platforms.

Responsibilities

  • Own the operational layer of a fast-moving research/tech environment.
  • Maintain, harden, and evolve a modern stack (Linux/macOS endpoints, AWS, Cloudflare, ZTNA).
  • Lead DevSecOps: CI/CD, secrets management, IdAM, and security posture.
  • Architect, automate, and operate at scale with minimal click-ops.
  • Ensure resilience with backup, DR, observability, and incident response.

Skills

Linux in prod
macOS
CI/CD pipelines
Terraform
Containers
Python
Shell scripting
Cloudflare Zero Trust
IAM
Entra ID
Intune
Jamf
Aurora
Iceberg
SQL
Data analytics
GitHub Actions
Security automation

Tools

AWS
GitHub Enterprise
Cloudflare
Terraform
ECS/EC2

Job description

We are a global research and advisory firm that focuses on the world’s most consequential geopolitical and strategic matters. Our work informs the decisions of governments, institutions, and enterprises.

We hold ourselves to unusually high standards. Our research is defined by empirical rigour and integrity. Our writing by clarity and authority. Our advisory work by genuine mastery of subject matter.

We are a flat, expert-heavy team. Everyone operates at a high level, takes ownership, and is trusted to exercise judgment.

The Role

You will be responsible for the operational layer of a fast-moving, high-impact research and technology environment. You'll start as the senior engineer who runs and hardens the platform, reporting to the CTO, with the runway to develop further.

You will work closely with our software engineers to maintain, harden, and evolve a modern stack: macOS/iOS user endpoints, Linux servers, AWS infrastructure, Cloudflare for edge services and ZTNA, and a sophisticated data analytics environment including a multi-DB lakehouse. You will operate and continuously improve all aspects of DevSecOps - including CI/CD, secrets management, IdAM, and security posture overall.

You will architect as well as administer, automate as well as operate, and maintain an optimal estate as our team and systems scale — minimising click-ops.

You will not be walking into a confused mess. We already operate a sophisticated and well-designed (but part-built) environment, with clarity on where we are going. E.g. deployments are health-gated with automatic rollback, CI runs on short-lived credentials rather than long-lived cloud keys, dependency and image updates arrive as automated, review-gated pull requests, and backups sit in deletion-locked vaults with cross-region copies.

Your job will be to help us go further. Resilience — backup, DR, recovery, and the observability and incident response around them — is yours to own, and to keep proven.

The environment:
  • Linux-first (AWS Linux/Ubuntu), macOS and iOS end-user devices, AWS, cloud-native — workloads run predominantly as containers and IaC, not hand-tended servers; this includes isolated, segmented environments.
  • Cloudflare: DNS, CDN, and Zero Trust (Access, Tunnels, WARP) end to end.
  • AWS, multi-account: ECS/EC2, IAM, S3, networking, and governance — IaC via Terraform.
  • Identity & endpoints: Entra ID, Intune (note this is not a Windows-centric role), Jamf.
  • Databases: Aurora (OLTP), Iceberg/S3 tables, with numerous other analytical and graph databases and caches.
  • CI/CD: GitHub Enterprise, Actions with security embedded in the pipeline.
  • AI-native engineering: you use AI tools fluently and are comfortable operating alongside AI agents in the delivery loop.

And much more besides.

You

You have at least five years of professional experience in building and running production systems. Ideally a tertiary qualification, but we value demonstrated skill more. You should have strong opinions about technologies and tools.

  • A systems engineer first, an operator always. You have deep, evidenced experience running Linux and macOS environments in production — shown in the things you've actually built and shipped, and that you can walk us through in depth (a public GitHub or similar is welcome).
  • You build the platform, you don't just tend it. You think in infrastructure-as-code and automation by default — Terraform, containers, CI/CD pipelines — and you treat click-ops as debt. You've designed and shipped systems that deploy, scale, and recover without someone standing over you.
  • You automate what you administer. You script fluently in shell (bash/zsh) and Python. You believe the best systems run themselves, and you build toward that.
  • Security is woven through the work, not a layer someone else owns. DevSecOps is how you build, not a separate discipline: e.g. Zero Trust access (Cloudflare Access/Tunnels/WARP), least-privilege IAM, federated identity (Entra/SSO/SCIM), secrets management and rotation, guardrails as code, and pipeline security in GitHub Actions — ephemeral credentials, secret-scanning, artefact integrity.
  • You own resilience, and you prove it. Backup, disaster recovery, observability, and incident response are yours — kept honest by drill, not assumption. You instrument what you run, you know before your users do, and you've been the person in the incident, not just downstream of it.
  • You understand the full stack beneath the application. Networking, DNS, TLS, databases — transactional and analytical. You might not be a DBA, but you speak SQL well enough to diagnose, optimise, and not break things.
  • You work with AI, not around it. You use AI tooling — e.g. Claude Code — to go faster and build better, and you can contribute to the infrastructure that supports AI workloads.
  • You are self-directed and intellectually honest. You find answers. You know when to go deep and when to ask. You're as comfortable presenting your thinking to an executive as you are debugging a misconfigured tunnel at 8pm.
  • You take probity seriously. We work on sensitive topics. Discretion and confidentiality aren't policies to comply with — they're professional standards you hold yourself to.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Engineer II, Platform
Engineer II, Platform

Nightingale Education Sole Mb • Salt Lake City (UT)

On-site
USD 120,000 - 180,000
Senior Software Engineer, Platform (Developer Experience)
Senior Software Engineer, Platform (Developer Experience)

Ecp123 • Chicago (IL), Northern (KY)

Hybrid
USD 140,000 - 210,000
Senior AI Platform Security Engineer - Contract to Hire San Francisco, CA
Senior AI Platform Security Engineer - Contract to Hire San Francisco, CA

FrontApp Inc. • San Francisco (CA), Northern (KY)

Hybrid
USD 180,000 - 260,000
Senior Software Engineer, Infrastructure
Senior Software Engineer, Infrastructure

vsco39 • San Francisco (CA)

On-site
USD 180,000 - 240,000
Senior Platform Engineer
Senior Platform Engineer

Enboarder • United States

On-site
USD 180,000 - 240,000
Senior Software Engineer, Infrastructure
Senior Software Engineer, Infrastructure

Talanto • Northern (KY)

Hybrid
USD 1,786,000 - 2,120,000
Security Engineer
Security Engineer

Sperry Rail, Inc. • Shelton (CT)

Hybrid
USD 110,000 - 170,000
Systems Engineer, Product Platform Tools
Systems Engineer, Product Platform Tools

Cloudflare • Austin (TX)

On-site
USD 140,000 - 190,000
Senior Software Engineer, Platform (Developer Experience)
Senior Software Engineer, Platform (Developer Experience)

ECP • Chicago (IL)

On-site
USD 130,000 - 190,000
Senior Platform Engineer
Senior Platform Engineer

Epsilon ASI • Denver (CO), Northern (KY)

Hybrid
USD 130,000 - 180,000