Principal Software Engineer - Infrastructure Automation
Listed on 2026-09-08
-
IT/Tech
At Early Warning, we’ve powered and protected the U.S. financial system for over thirty years with cutting-edge solutions like Zelle®, Paze℠, and so much more. As a trusted name in payments, we partner with thousands of institutions to increase access to financial services and protect transactions for hundreds of millions of consumers and small businesses.
Positions located in Scottsdale, San Francisco, Chicago, or New York follow a hybrid work model to allow for a more collaborative working environment.
Candidates responding to this posting must independently possess the eligibility to work in the United States, for any employer, at the date of hire. This position is ineligible for employment Visa sponsorship.
Principal Software Engineer- Infrastructure Automation Overall Purpose
The Principal Software Engineer
- Infrastructure Automation is an enterprise technical leader responsible for the architecture, strategy, and engineering direction of the infrastructure-as-code platform used to provision and manage infrastructure across Early Warning. This position owns the technical model for Terraform, Ansible, policy-as-code guardrails, and the shared modules and services consumed by engineering teams.
This is a hands-on software engineering and systems design role that operates with very little guidance. The Principal Engineer proactively identifies material problems and opportunities, frames the solution, resolves ambiguous cross-domain decisions, and drives execution through adoption. The role establishes enterprise standards and governance and delivers secure, maintainable, and well-tested platform capabilities that automate regulatory and operational controls across cloud and on-premises environments.
EssentialFunctions
- Operate with very little guidance to identify enterprise infrastructure automation problems and opportunities, define the target solution and execution path, resolve cross-domain tradeoffs, and drive delivery through measurable adoption and outcomes.
- Set the enterprise technical strategy and reference architecture for infrastructure automation, including architecture decision records, platform boundaries, operating models, and consequential build-versus-buy decisions.
- Establish software engineering standards for infrastructure modules, policy, and tooling, including versioned interfaces, testing, code review, release management, deprecation, and automated regression coverage.
- Own Terraform as the enterprise default for infrastructure provisioning across cloud and on-premises estates, including module taxonomy, ownership, private registry strategy, and adoption standards.
- Define and deliver opinionated Terraform modules for AWS services and common service patterns that provide secure, compliant, observable defaults for encryption, logging, tagging, networking, and IAM.
- Establish the enterprise override and exception model so legitimate deviations remain visible, reviewable, policy-checked, time-bound, and auditable.
- Architect the Terraform module test and release system, including native Terraform tests, Terratest, tflint, static analysis, semantic versioning, signed artifacts, and policy gates on plan output.
- Own the HCP Terraform or Terraform Enterprise operating model, including work spaces, run tasks, policy sets, protected state, drift detection, and plan/apply governance independent of the CI system that initiates a run.
- Own the enterprise Ansible platform architecture, including collections, roles, execution environments, Molecule and lint standards, and Ansible Automation Platform/AWX operating practices.
- Define the configuration-as-code architecture for network infrastructure, including structured configuration as source of truth, safe rollback, virtual topology and reachability validation, post-change verification, compliance, and drift detection.
- Own the enterprise policy-as-code architecture and Rego policy library for Terraform plans, Ansible constraints, and Kubernetes admission; ensure policy is tested, versioned, released, and distributed as a governed product.
- Design programmatic controls for segregation of duties, protected state, change review, and break-glass access with…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).