6 months ago
Base Salary
$205k - $233k/yr
Responsibilities
- Design and build a hardened AWS Isolated Recovery Environment with immutable vaults and restricted access.
- Threat model cloud-native attack patterns including IAM privilege escalation, backup deletion, ransomware persistence, and cross-account lateral movement.
- Validate backup configurations and continuously improve data recoverability.
- Lead the transition to organization-wide Terraform-based Infrastructure as Code for infrastructure such as VPCs, IAM roles, and security groups.
- Build automated workflows to tear down compromised environments and bootstrap fresh hardened environments from verified code and clean data.
- Create executable, tested, versioned recovery playbooks containing the API calls and CLI commands required to restore applications.
- Develop Python or Go scripts to smoke test recovered data and validate post-restoration integrity.
- Lead hands-on recovery drills, own after-action processes, and drive improvements.
- Shape high-availability architecture and design reviews while championing Infrastructure as Code and immutable infrastructure practices.
- Partner with Site Reliability Engineering on multi-region deployments and high-availability design.
Requirements
- 8+ years of experience in complex cloud environments, including at least 3 years in AWS.
- Experience with at least one of AWS, GCP, or Azure; EKS/Kubernetes experience is a strong plus.
- Strong Terraform skills, including modularizing complex environment-agnostic infrastructure.
- Hands-on familiarity with the Secure Vault pattern using a separate, highly restricted AWS account with tight network controls.
- Advanced shell scripting and proficiency in either Python or Go.
- Experience with CI/CD tooling such as Scalr, GitHub Actions, or equivalent.
- Proven ability to engineer and automate end-to-end restoration workflows.
- Preferred experience leading technical recovery efforts during an actual cyberattack or destructive incident.
- Preferred experience with chaos engineering tooling and familiarity with NIST SP 800-34 or similar frameworks.
- AWS Security Specialty certification or equivalent demonstrated expertise is preferred.
Benefits
- Competitive benefits package including 401(k) match, medical, dental, and vision insurance.
- Life and disability insurance, generous paid time off, vacation, sick leave, floating and fixed holidays, maternity and bonding leave, EAP, and other wellbeing resources.
- Hybrid work arrangement indicated by #LI-Hybrid.
Tech Stack
Categories
About Xometry
Xometry builds an AI-enabled marketplace that connects engineers and procurement teams with a vetted global network of manufacturers for on-demand CNC machining, 3D printing, sheet metal, and injection molding. The company earns fees by brokering instant-quote RFQs and managing production, logistics, and quality across its supplier base. Founded in 2013, Xometry is a publicly traded company (NASDAQ: XMTR) based in the Washington, DC–Baltimore area and serves buyers from startups to Fortune 1000 firms.
