Job Closed
This listing is no longer active.
Deepening the Science of Security
IT Operations Engineer
Location
United States
Posted
88 days ago
Salary
0
Seniority
Mid Level
Job Description
IT Operations Engineer
Trail of Bits
Trail of Bits is a cybersecurity firm of ~100 people across 14+ countries, fully remote since our founding in 2012. We conduct security audits, build research tools, and set standards the industry adopts. Our clients include the largest tech companies, financial institutions, and government agencies. The Role Trail of Bits seeks an IT Operations Engineer to own and evolve our internal IT infrastructure, security compliance, and employee technology experience. Here's what makes this different from IT at most companies: our workforce is security researchers and engineers. They audit the cryptographic protocols that protect financial infrastructure, build open-source security tools used across the industry, and assess the security of systems trusted by millions of users. They have strong, specific opinions about how corporate IT should be configured -- and they're usually right. Your job is to listen to that expertise, implement it reliably, and build the automation and tooling that keeps our systems in a state that matches the standards we set for our clients. You'll take technical direction from people who deeply understand the threat landscape, and you'll exercise your own initiative to build, improve, and automate everything you touch. Our IT infrastructure has scaled with the company over 14 years, and like any growing organization, it needs someone who can assess what's in place, strengthen the foundations, and build from there. Your first priority will be understanding the environment end-to-end -- auditing what's deployed against what's documented, establishing operational discipline across our toolchain, and closing gaps. Once the foundation is solid, you'll build the automation and self-service tooling that takes our operations to the next level. This is a builder role with high accountability. You'll write production-quality code -- not just scripts that work, but tools that scale. You'll automate repetitive tasks, build self-service tooling, and promote consistent, seamless experiences for a fully remote and globally distributed team. You'll also be responsible for endpoint management, SaaS administration, security compliance, and cloud infrastructure. The ideal candidate possesses a "no task too small, no task too big" attitude, proactively owns and solves problems, and thrives working autonomously as the primary IT person for a deeply technical team. You should be comfortable balancing initiative -- you see the gap and close it -- with the discipline to take direction, document transparently, and never cut corners on process. This role is open to candidates authorized to work in the United States. What You'll Achieve Endpoint Device Management - Test, deploy, and maintain MDM solutions (Jamf Pro) and endpoint security tools (CrowdStrike Falcon, iVerify) - Our fleet is primarily macOS (~100 devices), with additional Windows and Linux endpoints driven by the diversity of our client and research work. Expert-level macOS management is the foundation; candidates with multi-OS experience will thrive given the breadth of our engagements. - Maintain strict parity between the configuration repository and what is deployed across the fleet. The repo is the source of truth -- drift between documented and deployed state is unacceptable. - Manage Apple Business Manager, device lifecycle (ordering, provisioning, recovery), and automated onboarding/offboarding workflows - Enforce macOS update policies and patch management across the fleet Identity & Access Management - Manage identity and access across the SaaS ecosystem including Google Workspace (with Context-Aware Access), 1Password, Microsoft Entra, GitHub, Slack, and other platforms - Set up and integrate new systems with SSO (SAML, OIDC, OAuth 2.0) - Enforce account lifecycle hygiene: provisioning on day one, prompt suspension on departure, regular audits of authorized devices and access - Maintain organizational systems for credential management -- vaults, naming conventions, cross-references Security & Compliance - Maintain SOC 2 compliance posture and manage compliance automation platforms (Vanta) - Respond to client security questionnaires and provide compliance documentation for engagements across government, defense, and enterprise sectors - Manage endpoint detection and response (CrowdStrike Falcon), network canaries (Thinkst), email security (Material Security), and mobile device verification (iVerify) - Proactively maintain security posture through vulnerability scanning, configuration audits, and patch management - Monitor for and respond to supply chain threats -- package manager attacks, extension supply chain risks, dependency vulnerabilities -- with real-time detection where possible - Write and maintain security policies, runbooks, and documentation Cloud Infrastructure - Manage and rationalize cloud infrastructure across GCP and other providers -- understand what's running, why, what it costs, and whether it should still exist - Maintain accurate inventory, eliminate waste, and enforce least-privilege access for service accounts and cloud IAM - Develop reporting to monitor fleet health, compliance state, and infrastructure costs Automation & Tooling - Automate repetitive tasks across the company through scripting and custom tooling - Build internal tools to improve employee self-service - Maintain and extend workflow automation and internal tooling infrastructure - Manage developer tooling governance: Claude API access, VS Code extension security, GitHub organization administration and Advanced Security - Evaluate and implement new technologies to improve operational efficiency -- with rigorous vetting. In an era of AI-generated and AI-adjacent tooling, we hold ourselves to a higher standard for what enters our environment. Every tool, integration, and dependency must be evaluated for security posture before adoption. Documentation & Transparency - Document every configuration, script, and policy change in GitHub and public Slack channels. Anyone in the organization should be able to understand what is running on their machine at any given time. - Work visibly. Planned changes announced in advance, coverage gaps flagged early, status always obvious. Leadership should never have to ask what's happening in IT. - Maintain the IT scripts and configuration repository as the single source of truth for what is deployed across the fleet. Technical Support & Availability - Provide technical support and guidance to employees in a remote-first environment via Slack - Provide coverage for critical issues outside standard business hours -- password resets, account lockouts, and urgent security events cannot always wait for Monday - Review code contributions to IT repositories and provide meaningful technical feedback - Identify security events and integrate alerting processes into Slack Why This Role Matters At most companies, IT security is a checkbox exercise. At Trail of Bits, our internal security posture is an extension of our reputation. Our employees audit critical infrastructure for the world's most targeted organizations -- they notice when their own company's systems fall short. Nation-state adversaries have real reasons to target a firm like ours. The IT Operations Engineer is the person who ensures that our internal systems are as resilient as the standards we set for our clients. When you do this well, 100 people across 14 countries work without friction, leadership never has to intervene in IT, and our own house is in order -- visibly, provably, and at all times.
Job Requirements
- Experience
- Significant experience in IT Operations, DevOps, or Systems Administration -- we care more about what you can demonstrate than how many years you've been doing it
- Strong background in endpoint management using MDM systems or open-source tools
- Previous experience as the primary or solo IT person at a company
- Experience inheriting and improving existing infrastructure -- not just greenfield builds
- Programming & Automation
- Strong programming skills in Python and Bash
- Comfortable writing production-quality scripts and tools that scale, not just code that works
- Experience automating workflows and building internal tooling
- Able to review others' code and provide constructive, technically grounded feedback
- Endpoint & Platform Expertise
- Expert-level macOS administration experience with deep familiarity with MDM, system configuration, and endpoint management
- Experience managing Windows and Linux devices
- Identity & Access Management
- Experience with authentication and access control protocols including OAuth 2.0, SAML, FIDO/U2F, TOTP/HOTP, and other multi-factor authentication methods
- Experience with Google Workspace administration, 1Password or similar credential management, and identity providers (Entra or similar)
- Cloud Infrastructure
- Experience managing cloud infrastructure on AWS, Azure, or GCP
- Demonstrated ability to audit, rationalize, and optimize cloud environments -- not just provision new resources
- Compliance & Security
- SOC 2 compliance knowledge required
- Experience responding to client security questionnaires and providing compliance documentation
- Familiarity with NIST SP 800-171, NIST SP 800-53, CMMC, or FedRAMP is a plus
- Experience with vulnerability scanning and patch management processes
- Familiarity with zero-trust security architectures is a plus
- Communication & Organization
- Excellent written communication skills -- you'll write documentation, runbooks, and security policies that others rely on
- Strong organizational skills and ability to manage multiple priorities independently
- Comfortable providing support and guidance to a remote, technical workforce
- Systems thinker: you diagnose root causes, not just symptoms, and build processes that prevent recurrence
- Nice to Have
- Background working at a cybersecurity or security-focused organization
- Experience with infrastructure-as-code
- Experience inheriting and stabilizing IT environments during periods of organizational growth or transition
Benefits
- Competitive salary commensurate with experience
- Comprehensive health insurance
- Equipment budget
- Professional development
- Flexible PTO
Related Guides
Related Categories
Related Job Pages
More DevOps Engineer Jobs
• Design, implement, and manage GCP-based infrastructure ensuring scalability, performance, and cost efficiency. • Build and maintain CI/CD pipelines that support reliable deployments and automated testing. • Implement Infrastructure as Code (IaC) and automate environment setup and configuration. • Establish and maintain observability frameworks : monitoring, logging, and alerting for uptime and performance. • Collaborate with Security and Engineering to enforce least privilege, compliance, and Zero Trust principles. • Troubleshoot and optimize system performance, ensuring high availability and disaster recovery readiness. • Contribute to DevOps best practices and mentor other engineers on automation, cloud, and reliability.
• Design, build, and maintain CI/CD pipelines across development, QA, training, and production environments • Standardize and optimize deployment processes for consistent, reliable, and scalable delivery • Administer and support Azure DevOps pipelines, including repositories, agent pools, environments, and service connections • Implement infrastructure-as-code (IaC) and reusable automation solutions for environment setup and application delivery • Configure and support cloud and on-premises environments to ensure performance, stability, and alignment with business needs • Drive adoption of automated testing, validation checks, and quality gates within CI/CD pipelines • Troubleshoot build, deployment, and environment issues and perform root cause analysis • Implement monitoring, alerting, and logging solutions to improve reliability and reduce risk • Leverage AI-assisted tools to enhance development workflows, code validation, and pipeline efficiency • Evaluate and recommend tools and process improvements to increase delivery performance and developer productivity • Partner with engineering teams throughout planning, design, and delivery processes • Provide guidance on DevOps best practices, deployment strategies, and pipeline design • Act as a liaison across development, infrastructure, security, networking, and data teams • Ensure delivery processes meet security and compliance standards, including access controls and audit requirements • Maintain documentation for systems, pipelines, and processes and identify improvement opportunities
• Conduct training for Engineers and engineering teams on software defined/driven processes • Troubleshoot issues in systems and leverage problems for teaching • Enable automation of configuration management for all services • Recommend software deployment strategies for DevOps engineers • Build and optimize comprehensive automation systems across business lines • Develop automation scripts and solutions for technology services • Provide input into the architecture and technical leadership of the DevOps infrastructure • Assist more junior members in software development, testing, service provisioning, and management
Senior DevOps Engineer
SkyFiSkyFi is an equal-opportunity employer that values and encourages workplace diversity.
Title Senior DevOps Engineer Our Mission We're unlocking the secrets of our planet. SkyFi simplifies obtaining high-resolution Earth observation data and analytics, ensuring businesses and professionals a seamless and efficient user experience. No more complex procedures or hefty price tags. We're empowering everyone, from individuals to companies, to understand and utilize the power of space for good. What we do has tremendous potential to solve meaningful problems in our world. This technology is a powerful tool for enterprises and individuals, enabling them to leverage satellite imagery and analytics for critical applications: assessing the structural integrity of bridges to prevent failures, monitoring crop health for optimized agricultural output, tracking endangered species for environmental conservation, and exploring a myriad of other innovative use cases yet to be discovered. Grab the chance to be part of this. Join a team of open-minded, dynamic people solving new challenges and working on new technology in an exciting market with immense growth. SkyFi is the place for you. The Job As a Senior DevOps Engineer, you will design, build, and maintain the cloud infrastructure powering SkyFi's Earth Observation platform. You will work at the intersection of satellite technology and modern cloud-native systems, operating across GCP and AWS, managing production Kubernetes clusters, and championing GitOps-driven delivery. This role requires deep expertise in infrastructure-as-code, CI/CD, and site reliability practices, along with comfortable proficiency in Python for automation and operational tooling. The ideal candidate thrives with minimal supervision, excels when tackling ambiguous, high-impact problems, and is eager to learn about the fascinating Earth Observation industry. This Role Reports To: Engineering Manager, DevOps You Will Be Expected To - Design, deploy, and maintain production Kubernetes clusters; own cluster lifecycle management, performance tuning, and capacity planning. - Build and manage cloud infrastructure across GCP and AWS using Terraform and Terragrunt, following infrastructure-as-code best practices. - Develop, optimize, and maintain CI/CD pipelines using GitHub Actions and Flux CD to enable reliable, GitOps-driven deployments of containerized applications. - Develop Python-based tooling and automation to support infrastructure and platform operations. - Troubleshoot and resolve operational, networking, pipeline, and infrastructure issues across multi-cloud environments. - Identify, document, and automate repetitive or critical workflows to reduce operational burden on the engineering team. - Implement and maintain comprehensive monitoring, alerting, and observability using tools such as Prometheus and Grafana. - Ensure compliance with security, governance, and regulatory requirements, including those tied to classified environments. - Collaborate with development and operations teams to gather requirements and translate them into reliable infrastructure solutions. - Partner with fellow engineers to architect, develop, and scale the product while keeping operational reliability and cost-efficiency in mind. - Champion cloud-native best practices, infrastructure-as-code principles, and GitOps workflows across the engineering organization. What We Are Looking For Must-Have Qualifications - Active U.S. security clearance (required). - U.S. citizenship (required). - 6+ years of professional experience in DevOps, SRE, or Platform Engineering. - 5+ years of hands-on experience operating and managing Kubernetes in production environments. - Strong hands-on experience with both GCP and AWS - Proficiency with Terraform and Terragrunt for infrastructure provisioning and management. - Hands-on experience with Flux CD for GitOps-based continuous delivery. - Hands-on experience building and maintaining CI/CD pipelines with GitHub Actions. - Strong scripting skills in Bash and/or Python - Solid experience with Docker and container orchestration. - Deep understanding of modern DevOps principles, cloud-native architecture, and infrastructure-as-code practices. - Solid understanding and experience with observability systems like Grafana/Prometheus - Strong Linux systems administration skills. - Proactivity and ability to work with minimal supervision Preferred Qualifications - Familiarity with service mesh technologies (e.g., Istio, Linkerd). - Previous experience supporting 24/7/365 production services. - Experience working in early-stage or high-growth startup environments. - Excellent organizational and documentation skills. At SkyFi You Will - Be well compensated. Possibility for equity - Receive best-in-class benefits, including premium medical, dental, and vision coverage and 20 days paid time off - Play a critical role in building a market-changing product in the exciting realm of Space - Thrive in a fast-paced, dynamic environment that rewards initiative, innovation, and getting things done SkyFi is an equal-opportunity employer that values and encourages workplace diversity. Salary Band: $170,000-$220,000



