4 hours ago
Base Salary
$187k - $250k/yr
Responsibilities
- Define and maintain standards, reference architecture, security requirements, review processes, and documentation for internal software.
- Own AWS and Snowflake infrastructure, including compute, networking, data stores, DNS, certificates, environments, observability, and platform cost.
- Implement infrastructure as code, CI/CD pipelines, secure golden paths, reusable modules, base images, libraries, secrets management, and developer self-service.
- Secure infrastructure and the software development lifecycle through configuration hardening, IaC scanning, container and image hygiene, dependency and supply-chain scanning, secret detection, and pipeline hardening.
- Manage vulnerabilities, cloud drift, security monitoring, audit logs, data loss prevention, access boundaries, least privilege, and incident response.
- Support SOC 2, ISO, access audits, incident runbooks, tabletop exercises, RBAC/ABAC, JML automations, and identity governance.
- Operate MCP, Workato, Snowflake, AI client, and data integrations; troubleshoot escalations, manage semantic-layer configuration, and handle upstream API and schema changes.
- Review infrastructure and deployment changes, participate in on-call, write postmortems, and maintain operational runbooks and architecture documentation.
Requirements
- Experience establishing a platform, DevOps, or infrastructure practice where one did not previously exist.
- Deep hands-on production infrastructure experience in a major cloud, including networking, IAM, compute, and failure modes.
- Production-scale infrastructure-as-code experience with Terraform, Pulumi, CloudFormation, or an equivalent, including refactoring inherited modules.
- End-to-end ownership of CI/CD pipelines with testing, scanning, deployment gates, containers, and orchestration.
- Strong Python or Go skills for automation, tooling, and debugging.
- Practical infrastructure security experience covering cloud hardening, secrets management, dependency and vulnerability management, and least-privilege access.
- Strong written communication and ability to document standards and explain risk to technical and non-technical stakeholders.
- Strong SQL experience, including writing queries in Snowflake and other BI tools.
- Hands-on security operations experience with log and audit analysis, alert triage, incident response, and SIEM event review.
- Experience implementing and managing SAML/OIDC SSO and SCIM for internal-built tools and integrating identity providers such as Okta.
- Strong secrets-management experience, including OAuth, API, and JWT service-account integrations.
- Production iPaaS experience, including repairing integrations built by others.
- Experience building an internal developer platform or serving engineers as platform customers is preferred.
- Experience operating LLM or agent infrastructure, MCP servers, RAG pipelines, semantic layers, or enterprise AI tooling is preferred.
- Familiarity with prompt injection, tool-use abuse, model-context data leakage, and related AI security controls is preferred.
- Experience with Workato, Airflow, dbt, MuleSoft, Splunk, Panther, Datadog Security, Snowflake operations, or GTM tools such as Gong, HubSpot, and Outreach is preferred.
Benefits
- Contract-to-hire opportunity.
- Optional office attendance on Tuesdays, Wednesdays, and Thursdays; in-office attendance is not required.
- Opportunity to establish and own a new internal platform and security practice.
- Work alongside GTM Systems, Data, product engineering, Enterprise Security, Legal, and IAM teams.
About Front
Front is the customer operations platform built for B2B complexity, keeping every team, tool, and customer conversation in sync so companies can scale without losing connection. Others handle simple interactions. Front handles the coordination and context behind complex B2B customer relationships. Over 9,000 companies, including Uber Freight, Navan, and Stripe, rely on Front because it's the only one that can run the operational layer that makes customer-facing work actually succeed.