Senior Cloud Engineer
Overland Park, Johnson County, Kansas, 66213, USA
Listed on 2026-06-22
-
IT/Tech
Cloud Computing: Infrastructure & Operations, AWS
Job Description
We're Looking for an experienced Senior Cloud Engineer!
Security Benefit is a PLACE where we promise to help our customers To and Through Retirement.
We’re proud to have been recognized as one of the best in the business:
- Named to Ward’s 50 list of top-performing life-health insurance companies
- Recognized on list of Ingram’s Top 100 Private Companies in the Kansas City area in 2024
As a Senior Cloud Engineer you will build the reusable, team-agnostic Git Lab CI/CD platform that the rest of the organization adopts. You are the engineering engine that turns Security Benefit’s Dev Sec Ops maturity roadmap into working, audit‑compliant pipelines — then partner directly with each team’s tech leads to onboard their workloads and hand day‑to‑day release ownership back to those teams.
This role is best suited for a builder who takes pride in engineering excellence within a clear strategic direction, going deep on one team at a time and leaving every engagement with a reusable contribution to the shared platform.
This role reports to the Manager, AWS Platform Engineering, and is based out of our Overland Park, Kansas office with a hybrid work schedule offering flexibility between on‑site and remote work.
- Design, build, and maintain enterprise‑standard Git Lab CI/CD templates, shared libraries, and include components that teams adopt with minimal friction — ensuring every engagement leaves a reusable artifact back in the shared platform
- Own Git Lab runner fleet management and performance, including Windows runners required for private‑network access to SQL Server environments across DEV, QA, and PROD
- Implement Terraform‑based Infrastructure as Code for AWS workloads (ECS Fargate, EC2, Lambda, RDS/Aurora) across environment‑segregated accounts
- Build database and data‑engineering CI/CD: migration‑based deployment for SQL Server and Snowflake, SSIS/.ispac packaging, and ETL/DML/DDL pipelines
- Build SAST, DAST, SCA, and secret‑detection as reusable shared CI components, and embed segregation of duties, dual approval, JSM/CAB integration, and automated audit‑evidence generation into the pipeline standard
- Partner with each team’s tech lead to onboard their workload onto the standard pipeline, define a clear handoff‑readiness bar, and ensure tech leads can independently own releases end to end
- Produce documentation, runbooks, and quick‑reference guides as first‑class deliverables alongside the code; provide ongoing consulting and escalation support to teams operating autonomously
- Manage versioned, immutable artifacts via Git Lab Package Registry with semantic versioning, SHA
256 verification, and audit‑compliant retention; implement environment promotion (DEV → QA → PROD) and rollback procedures - Enforce secrets‑management best practices across all pipelines using Git Lab CI variables and AWS Secrets Manager
- Provide technical mentorship and guidance to junior engineers on the team, building internal capability alongside the platform itself
- 5–8+ years hands‑on in Dev Ops, Dev Sec Ops , platform, or release engineering, including a track record of building reusable CI/CD adopted by more than one team
- Deep Git Lab CI/CD expertise: pipeline templates and components, Compliance Module, runner fleet management, group and repository administration, access controls, branch protection, and merge request policies
- Strong Terraform/IaC skills and solid AWS experience across ECS, EC2, Lambda, RDS/Aurora, S3, IAM, and Secrets Manager
- Scripting proficiency across stacks:
Power Shell (critical for Windows runners and SQL Server automation), Python, Bash, and YAML - Experience implementing security scanning (SAST, DAST, SCA, secret detection) inside CI/CD pipelines
- Demonstrated ability to design automation that satisfies audit and compliance requirements — approval gates, evidence generation, and change traceability — ideally in a regulated industry
- Working knowledge of containerization (Docker)
- Builds for reuse, not for the moment: leaves every team more capable and self‑sufficient, thrives going deep single‑threaded, and treats documentation as part of the job
- Database and data‑engineering CI/CD:…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).