2 days ago
Remote, United StatesStaff+

Responsibilities

  • Build orchestrated patching playbooks with pre- and post-validation for PPDM, Data Domain, Avamar, Rubrik, and NetApp ONTAP.
  • Develop a CVE-to-asset correlation service using live platform inventory.
  • Build scheduled backup posture validation for immutability, retention locks, replication, and anti-ransomware controls.
  • Implement configuration drift detection and automated baselines using ActiveIQ and ONTAP REST APIs.
  • Build automated deprovisioning workflows for backup administrator access tied to HR and IAM events.
  • Integrate vault-based credential rotation for backup automation service accounts.
  • Produce audit-ready documentation and evidence artifacts for each automated control.
  • Collaborate with stakeholders and translate technical automation work into business-facing status updates.

Requirements

  • 7+ years of relevant IT experience, including significant hands-on work with data protection, backup, and storage infrastructure.
  • Hands-on experience administering and engineering solutions on PPDM, Data Domain, ECS, Rubrik, and/or NetApp ONTAP in enterprise environments.
  • Experience building automation and orchestration tooling with scripting, APIs, and playbooks.
  • Working knowledge of vulnerability management, CVE tracking, patch cycles, and asset correlation.
  • Experience integrating REST APIs, particularly NetApp ActiveIQ and/or ONTAP APIs.
  • Experience with credential vaulting and automated secrets or credential rotation, such as CyberArk or HashiCorp Vault.
  • Strong scripting ability with PowerShell, Python, or similar tools.
  • Ability to work independently and deliver production-grade solutions under compressed timelines.
  • Experience producing technical documentation and audit or compliance evidence artifacts.
  • Bachelor’s degree in Information Technology, Computer Science, or a related technical field is preferred.
  • Relevant vendor certifications for Dell PowerProtect, Rubrik, or NetApp platforms are preferred.
  • Experience with security configuration baselining, drift detection, FIPS compliance, encryption-at-rest, and audit logging is preferred.
  • Familiarity with IAM and HR-system integrations, anti-ransomware controls, immutability, retention locks, and replication validation is preferred.
  • Familiarity with CI/CD pipelines or infrastructure-as-code practices applied to automation delivery is preferred.
  • Strong stakeholder communication skills are preferred.

Benefits

  • This is a non-employee contingent worker engagement employed through TIAA’s preferred third-party supplier.
  • The anticipated engagement term is 14 months, from October 19, 2026 through December 31, 2027, with possible extension based on business needs.
  • The role is expected to be onsite, likely in a hybrid capacity, at the posted location.
  • Travel is not required.

Tech Stack

PowerShellPython

Categories

Teachers Insurance and Annuity Association of America (TIAA)

About Teachers Insurance and Annuity Association of America (TIAA)

10,000+ employees

TIAA is a privately held, not-for-profit financial services organization providing retirement plans, annuities, IRAs, mutual funds, life insurance, 529 plans, and brokerage services to employees and institutions in education, healthcare, and the nonprofit sector. Founded in 1918 and headquartered in New York, it also offers investment management through its Nuveen subsidiary. Its revenue comes from fees on asset management, insurance, and brokerage services.

Contact me