ForgeApply · Job listing
Principal Software Engineer - Infrastructure Automation
Earlywarning
See all 77 open roles at Earlywarning →
Tailor your resume for this Earlywarning job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Earlywarning's site. Free trial, no card required.
About this role
At Early Warning, we’ve powered and protected the U.S. financial system for over thirty years with cutting-edge solutions like Zelle®, Paze℠, and so much more. As a trusted name in payments, we partner with thousands of institutions to increase access to financial services and protect transactions for hundreds of millions of consumers and small businesses.
Positions located in Scottsdale, San Francisco, Chicago, or New York follow a hybrid work model to allow for a more collaborative working environment.
Candidates responding to this posting must independently possess the eligibility to work in the United States, for any employer, at the date of hire. This position is ineligible for employment Visa sponsorship.
Principal Software Engineer - Infrastructure Automation
Overall Purpose The Principal Software Engineer - Infrastructure Automation is an enterprise technical leader responsible for the architecture, strategy, and engineering direction of the infrastructure-as-code platform used to provision and manage infrastructure across Early Warning. This position owns the technical model for Terraform, Ansible, policy-as-code guardrails, and the shared modules and services consumed by engineering teams. This is a hands-on software engineering and systems design role that operates with very little guidance. The Principal Engineer proactively identifies material problems and opportunities, frames the solution, resolves ambiguous cross-domain decisions, and drives execution through adoption. The role establishes enterprise standards and governance and delivers secure, maintainable, and well-tested platform capabilities that automate regulatory and operational controls across cloud and on-premises environments.
Essential Functions • Operate with very little guidance to identify enterprise infrastructure automation problems and opportunities, define the target solution and execution path, resolve cross-domain tradeoffs, and drive delivery through measurable adoption and outcomes. • Set the enterprise technical strategy and reference architecture for infrastructure automation, including architecture decision records, platform boundaries, operating models, and consequential build-versus-buy decisions. • Establish software engineering standards for infrastructure modules, policy, and tooling, including versioned interfaces, testing, code review, release management, deprecation, and automated regression coverage. • Own Terraform as the enterprise default for infrastructure provisioning across cloud and on-premises estates, including module taxonomy, ownership, private registry strategy, and adoption standards. • Define and deliver opinionated Terraform modules for AWS services and common service patterns that provide secure, compliant, observable defaults for encryption, logging, tagging, networking, and IAM. • Establish the enterprise override and exception model so legitimate deviations remain visible, reviewable, policy-checked, time-bound, and auditable. • Architect the Terraform module test and release system, including native Terraform tests, Terratest, tflint, static analysis, semantic versioning, signed artifacts, and policy gates on plan output. • Own the HCP Terraform or Terraform Enterprise operating model, including workspaces, run tasks, policy sets, protected state, drift detection, and plan/apply governance independent of the CI system that initiates a run. • Own the enterprise Ansible platform architecture, including collections, roles, execution environments, Molecule and lint standards, and Ansible Automation Platform/AWX operating practices. • Define the configuration-as-code architecture for network infrastructure, including structured configuration as source of truth, safe rollback, virtual topology and reachability validation, post-change verification, compliance, and drift detection. • Own the enterprise policy-as-code architecture and Rego policy library for Terraform plans, Ansible constraints, and Kubernetes admission; ensure policy is tested, versioned, released, and distributed as a governed product. • Design programmatic controls for segregation of duties, protected state, change review, and break-glass access with automatic evidence capture and time-boxed expiration. • Eliminate static credentials from infrastructure change workflows through OIDC-federated, short-lived IAM roles and dynamic secrets for cloud, database, and network credentials. • Define the infrastructure automation control framework and map enforcement points to PCI DSS, SOX ITGC, NYDFS Part 500, FFIEC, and other applicable requirements; convert manual controls into continuously evidenced automated controls. • Serve as the technical authority for infrastructure-as-code controls in internal audits, external audits, and regulatory examinations, and author enterprise engineering standards and control narratives. • Architect self-service capabilities for module discovery, scaffolding, exception workflows, compliance dashboards, and APIs that expose module, policy, and compliance state to internal platforms. • Prototype and de-risk the most complex infrastructure automation and guardrail problems; mentor senior engineers and raise the architecture, design, and code-review bar across engineering. • Partner with CI/CD, Security, Network Engineering, AIOps, and observability leaders to integrate infrastructure modules, controls, telemetry, and governance across shared engineering platforms. • Define and report enterprise measures of platform effectiveness, including module adoption, policy pass rate, plan/apply success, control coverage, and time to remediate drift and compliance violations. • Support the company's commitment to risk management and protecting the integrity and confidentiality of systems and data.
Minimum Qualifications • Education and/or experience typically obtained through a bachelor's degree in computer science, engineering, or a related technical field. • Typically ten or more years of
Salary insight
The midpoint of this range ($202k) is about 55% above the median disclosed salary for Chicago roles listed on ForgeApply ($130k across 2,704 jobs).
See full Software Engineer salary data for Chicago →
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this Earlywarning role before you apply.
Tailor my resume for this jobSimilar jobs
- Software Engineer-Infrastructure Automation — Wells Fargo · ISELIN, NJ | IRVING, TX | CHARLOTTE, NC
- Staff Software Engineer - Infrastructure Automation — Earlywarning · Scottsdale | Chicago
- Senior Software Engineer - Infrastructure — Arcesiumllc · New York
- Senior Software Engineer - Infrastructure — Confluent · Remote
- Senior Software Engineer - Infrastructure — Afterquery · San Francisco
- Senior Software Engineer, Infrastructure Engineering — Coreweave · New York, NY
- Senior Software Engineer, Infrastructure — Artemis · New York City
- Senior Software Engineer, Infrastructure — Sandbar · New York City
More like this: Software Engineer Jobs · Software Engineer Jobs in Chicago · Browse all jobs
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)