Cloud Infrastructure and Security Engineer
Chicago, IL - USA
Job Summary
At Harris the true value of what makes us successful is found in our people. It is our unique mix of cultures experiences beliefs and backgrounds that sets Harris apart from the rest. We constantly strive to cultivate nurture and amplify an unparalleled environment where we value intellectual curiosity and uniqueness of thought. Inclusion is embedded in the very fabric of our culture of collaboration and openness.
We understand that a job description only tells one part of a broader story and Harris is seeking dynamic candidates who can add to our best-in-class environment. We recognize that qualifications can be gained through both traditional and non-traditional paths and we are committed to considering candidates who possess the potential to be excellent in this role regardless of prior experiences.
Therefore we encourage ALL interested individuals to submit their applications even if they do not meet every requirement outlined in the job description.
Position Summary
InfraSec builds and secures Harris Associates cloud foundation on Microsoft Azure. The team runs the estate as code - identities networks virtual machines Kubernetes and data platforms are defined reviewed and deployed through automated pipelines rather than managed by hand. Its a lean hands-on team that partners closely with DevOps Data and Application teams and holds a high bar for security given the firms regulated environment.
The Cloud Infrastructure and Security Engineer is a hands-on individual-contributor role at the center of this infrastructure-as-code operation working across environments and cloud regions with deep involvement in identity networking compute and data-platform security. Were looking for an experienced infrastructure or security engineer who thinks in systems is comfortable owning production-grade cloud environments and wants the scope to shape how a growing platform is built and secured.
Responsibilities may include but are not limited to:
- AI-enabled tooling: Build and manage AI/LLM-based skills and agentic workflows that give the team leverage governed under the same security review and least-privilege discipline as any other credentialed automation with human review before anything ships.
- Patching and on-call: Share the teams operational rotations patch the estate roughly three to four Saturdays a year and serve as on-call first responder for infrastructure and security issues about one week a month resolving directly or escalating as needed.
- Infrastructure as code: Author and maintain Terraform across roughly 18 repositories multiple environments and regions with Azure Storage state backends holding the line on version/provider discipline import safety and plan-diff review.
- Identity and access management: Provision and govern Microsoft Entra ID app-role and role-assignable groups PIM/JIT Conditional Access Workload Identity Federation and Microsoft Graph designing least-privilege grants and auditing existing ones.
- Cloud networking: Design and operate hub-and-spoke topology management-group policy and custom roles NSG/firewall rules routing and trusted network locations and troubleshoot when it breaks.
- Virtual machines and golden images: Provision hardened Azure VMs from a shared module (secure boot vTPM encryption at host Hybrid Benefit) and build/maintain golden Windows Server images with Packer.
- Kubernetes and containers: Support the AKS platform alongside DevOps workload identity service-mesh and egress behavior and connectivity troubleshooting.
- Data and analytics platform access: Govern access and security settings for Databricks Snowflake Power BI/Microsoft Fabric and Purview and manage platform-level governance.
- Monitoring and incident response: Keep signal high and noise low with Azure Monitor and lead root-cause investigations across pipelines capacity and connectivity.
- CI/CD review and automation: Deliver every change through Azure Pipelines and a gated Terraform flow review pull requests for what CI cant catch and improve the automation itself.
Qualifications
Required
- 7 years of hands-on cloud infrastructure engineering experience with production-grade experience on a major cloud platform (Azure preferred).
- Strong Infrastructure-as-Code skills - Terraform or a comparable tool - including state management provider discipline and safely importing existing resources.
- Solid grounding in identity and access fundamentals: RBAC service principals/managed identities and least-privilege design.
- Cloud networking expertise: hub-and-spoke or equivalent topologies firewalls/NSGs routing and DNS.
- CI/CD delivery experience with a platform like Azure DevOps plus scripting in PowerShell and/or Bash.
- A security-first mindset with comfort working inside change-control and approval gates.
- Clear written communication skills for documenting decisions and processes.
Preferred:
- Kubernetes/AKS operations experience - node pools workload identity and service mesh.
- Experience with Packer or golden-image build pipelines.
- Data-platform governance experience (e.g. Databricks Snowflake Power BI/Microsoft Fabric).
- Experience in a regulated or financial-services environment.
Special Requirements
This role shares the teams operational rotations: a monthly Saturday patching cycle (roughly three to four Saturdays per year) and a weekly on-call rotation (about one week per month) as first responder for infrastructure and security issues. Occasional early-morning evening or weekend work may be required to support patch windows and critical incidents. Flexibility with working hours is key.
We offer a comprehensive benefits package designed to integrate life and work and to support our employees and their families. Benefits include but are not limited to; medical prescription drug dental and vision insurance paid time off profit sharing plan 401k plan tuition reimbursement commuter and holistic wellness benefits along with volunteer programs.
Actual annual base salaries may vary based on factors including but not limited to education training experience and other job-related factors. If hired base pay will be determined on an individualized basis and is only one part of the total compensation package which depending on the position may also include a discretionary performance bonus and other Harris sponsored benefit programs.
Expected range for this Chicago-based role
$190000 - $210000 USD
Equal Employment Opportunity Policy Statement
Harris Associates L.P. pursues a policy of equal opportunity in all areas of employment including recruitment hiring training compensation benefits advancement and treatment on the job. This means that Harris does not discriminate against employees or qualified applicants based on an individuals race color religion creed sex age national origin physical disability sexual orientation trans-gender status transsexual status status as a veteran or disabled veteran genetic information or for any other reason prohibited by law. Harris reserves the right to review publicly available information about applicants (i.e. via social networking sites) to the extent permissible under applicable law.
Reasonable Accommodation Notice
We provide reasonable accommodation for individuals with disabilities and disabled veterans in job application procedures. If you have any difficulty using our online system and you need an accommodation due to a disability you may use the alternative email address below to contact us about your interest in employment at or you can call us at .
Privacy Statement
The information you send to us is used for employment purposes only. What you send is kept confidentialwe will not give your personal information to outside parties without your consent.
Required Experience:
IC
About Company
Since 1976, Harris Associates has managed money for individuals, institutions, and private equity clients with consistent investment philosophies and disciplined research processes.