Job Closed
This listing is no longer active.
Affirm is a financial services company that is on a mission to provide its customers with “honest financial products that improve lives.” As an employer, Af
Senior Software Engineer (Infrastructure)
Location
United States
Posted
60 days ago
Salary
$169K - $240K / year
Seniority
Senior
Job Description
Senior Software Engineer (Infrastructure)
Affirm
Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest. The Trust Infra team elevates the security posture of our infrastructure and services by embedding security in everything from provisioning to deployment, improving developer experience through automation, and building guardrails that enable safe, rapid delivery. Artifacts owned by this team include our secrets management system, authentication and authorization, cryptography, certificate workloads, and other core security components within our Kubernetes and cloud infrastructure. What You'll Do - You will be responsible for owning and delivering quarterly goals for your team, leading engineers on your team through ambiguity to solve open-ended problems, and ensuring that everyone is supported throughout delivery. - You will support your peers and stakeholders in the product development lifecycle by collaborating with product management, design & analytics by participating in ideation, articulating technical constraints, and partnering on decisions that properly consider risks and trade-offs. - You will proactively identify project, process, technology or business issues, advocate for them, and lead in solving them. - You will support the operations and availability of your team’s artifacts by creating and monitoring metrics, escalating when needed, and supporting “keep the lights on” & on-call efforts. - You will foster a culture of quality and ownership on your team by setting or improving code review and design standards for your team, and advocating for them beyond your team through your writing and tech talks. - You will help develop talent on your team by providing feedback and guidance, and leading by example. What We Look For - You have 4+ years of experience designing, developing and launching backend systems at scale using languages like Python or Kotlin. - You have a track record of developing highly available distributed systems using technologies like AWS, MySQL and Kubernetes. - You have deep expertise of Kubernetes resource management, Helm charts, and operator patterns, centered around security workloads. - You have experience defining a technical plan for the delivery of a significant feature or system component with an elegant, simple and extensible design. You write high quality code that is easily understood and used by others. - You are proficient at making significant changes in a large code base, and have developed a suite of tools and practices that enable you and your team to do so safely. - Your experience demonstrates that you take ownership of your growth, proactively seeking feedback from your team, your manager, and your stakeholders. - You have strong verbal and written communication skills that support effective collaboration with our global engineering team. - This position requires either equivalent practical experience or a Bachelor’s degree in a related field. Pay Grade - N Equity Grade - 8 Employees new to Affirm typically come in at the start of the pay range. Affirm focuses on providing a simple and transparent pay structure which is based on a variety of factors, including location, experience and job-related skills. Base pay is part of a total compensation package that may include equity rewards, monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidized medical coverage, dental and vision for you and your dependents.) USA base pay range (CA, WA, NY, NJ, CT) per year: $190,000 - 240,000 USA base pay range (all other U.S. states) per year: $169,000-219,000 #LI-Remote Affirm is proud to be a remote-first company! The majority of our roles are remote and you can work almost anywhere within the country of employment. Affirmers in proximal roles have the flexibility to work remotely, but will occasionally be required to work out of their assigned Affirm office. A limited number of roles remain office-based due to the nature of their job responsibilities. We’re extremely proud to offer competitive benefits that are anchored to our core value of people come first. Some key highlights of our benefits package include: - Health care coverage - Affirm covers all premiums for all levels of coverage for you and your dependents - Flexible Spending Wallets - generous stipends for spending on Technology, Food, various Lifestyle needs, and family forming expenses - Time off - competitive vacation and holiday schedules allowing you to take time off to rest and recharge - ESPP - An employee stock purchase plan enabling you to buy shares of Affirm at a discount We believe It’s On Us to provide an inclusive interview experience for all, including people with disabilities. We are happy to provide reasonable accommodations to candidates in need of individualized support during the hiring process. [For U.S. positions that could be performed in Los Angeles or San Francisco] Pursuant to the San Francisco Fair Chance Ordinance and Los Angeles Fair Chance Initiative for Hiring Ordinance, Affirm will consider for employment qualified applicants with arrest and conviction records. By clicking "Submit Application," you acknowledge that you have read Affirm's Global Candidate Privacy Notice and hereby freely and unambiguously give informed consent to the collection, processing, use, and storage of your personal information as described therein.
Benefits
- 401(K), 401(K) matching, Adoption Assistance, Childcare benefits, Commuter benefits, Company equity, Company-sponsored outings, Company sponsored family events, Continuing education stipend, Dedicated diversity and inclusion staff, Dental insurance, Disability insurance, Diversity manifesto, Volunteer in local community, Employee stock purchase plan, Family medical leave, Fitness stipend, Flexible Spending Account (FSA), Flexible work schedule, Generous parental leave, Generous PTO, Company-sponsored happy hours, Health insurance, Job training & conferences, Open door policy, Life insurance, Mentorship program, Paid volunteer time, Online course subscriptions available, Onsite gym, Open office floor plan, Paid holidays, Paid sick days, Partners with nonprofits, Performance bonus, Promote from within, Lunch and learns, Relocation assistance, Remote work program, Return-to-work program post parental leave, Free snacks and drinks, Team based strategic planning, OKR operational model, Continuing education available during work hours, Tuition reimbursement, Mandated unconscious bias training, Vision insurance, Wellness programs, Some meals provided, Mental health benefits, Home-office stipend for remote employees, Diversity employee resource groups, Hiring practices that promote diversity, Fertility benefits, Employee resource groups, Employee-led culture committees, Quarterly engagement surveys, In-person all-hands meetings, President's club, Employee awards, Diversity recruitment program, Pension, Pay transparency, Transgender health care benefits, Abortion travel benefits, Mother's room, Personal development training, Apprenticeship programs, Flexible time off, Bereavement leave benefits
Related Guides
Related Categories
Related Job Pages
More Infrastructure Engineer Jobs
Infrastructure Engineer
TKO Group Holdings, IncIMG is a leading global sports marketing agency, specializing in media rights management and sales, multi-channel content production and distribution, brand partnerships, strategic consulting, digital services, and events management. Powers growth of revenues, fanbases, and IP for more than 200 federations, associations, events, and teams Subsidiary of TKO Group Holdings, Inc. (NYSE: TKO)
Who We Are: IMG is a leading global sports marketing agency, specializing in media rights management and sales, multi-channel content production and distribution, brand partnerships, strategic consulting, digital services, and events management. It powers growth of revenues, fanbases and IP for more than 200 federations, associations, events, and teams, including the National Football League, English Premier League, International Olympic Committee, National Hockey League, Major League Soccer, ATP and WTA Tours, the AELTC (Wimbledon), Euroleague Basketball, CONMEBOL, DP World Tour, and The R&A, as well as UFC, WWE, and PBR. IMG is a subsidiary of TKO Group Holdings, Inc. (NYSE: TKO), a premium sports and entertainment company. TKO Group Holdings, Inc. (NYSE: TKO) is a premium sports and entertainment company. TKO owns iconic properties including UFC, the world’s premier mixed martial arts organization; WWE, the global leader in sports entertainment; and PBR, the world’s premier bull riding organization. Together, these properties reach 1 billion households across 210 countries and territories and organize more than 500 live events year-round, attracting more than three million fans. TKO also services and partners with major sports rights holders through IMG, an industry-leading global sports marketing agency; and On Location, a global leader in premium experiential hospitality. Infrastructure Lead acts as the senior onsite technical authority and IT Incident Commander of all IT matters while at site, migration related or otherwise. Leads Windows application migrations, absorbs Helpdesk and project escalations, triages concurrent incidents in real time, and maintains operational control during cutovers. Shields Quest migration engineer from noise while continuously improving tactics and playbooks. This role requires exceptional situational awareness, extremely high technical aptitude, decisive judgment under pressure, and the ability to manage chaos in ambiguous migration scenario. What You’ll Do- • Act as the senior onsite IT authority and Incident Commander during migrations • Lead Windows application migrations tied to the project • Absorb and triage escalations from Helpdesk, project teams, and stakeholders • Serve as the final onsite escalation point for all IT issues, migration-related or otherwise • Manage multiple concurrent incidents while maintaining a global view of migration health • Monitor, assign, and work Hypercare ServiceNow Assignment Group incidents • Continuously refine escalation paths, playbooks, and migration tactics What Success Looks Like • Operational issues are contained onsite • Systemic problems are identified and mitigated early • Migration execution quality improves consistently • Stakeholder confidence remains high during cutovers What We’re Looking For- • Senior-level Windows infrastructure and application migration experience • Proven experience operating in high-pressure incident or cutover environments • Strong judgment, composure, and decision-making under ambiguity • Experience supporting enterprise migrations, M&A programs, or complex IT transformations TKO EEO Statement: TKO is an Equal Opportunity Employer and complies with all applicable federal, state, and local laws regarding non-discrimination in employment. TKO makes employment decisions based on merit and qualifications, without considering an employee’s or applicant’s race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, marital status, veteran status, or any other basis prohibited under federal, state or local laws governing non-discrimination in employment in every location in which the Company has facilities. TKO also provides reasonable accommodations for qualified individuals with disabilities in accordance with the Americans with Disabilities Act (ADA) and applicable state or local laws. For information about Privacy and Information Security for TKO employment candidates, please review our Privacy Policy. For information regarding Terms of Use for this and other TKO websites, please review our Terms of Use.
Role Description We are seeking a Senior Cloud Infrastructure Engineer (Azure) with 10+ years of experience in enterprise cloud architecture, security, networking, and automation. This role is infrastructure-centric but modernization-focused, with a strong emphasis on the Azure Well-Architected Framework, Defender for Cloud posture management, and compliance (e.g., CIS Benchmarks, ISO/NIST). You will act as a technical driver to design and operate secure-by-design Azure environments based on Zero Trust principles, lead the architectural transition of legacy applications to modern standards, and implement robust network segmentation. You should have expert-level IaC (Terraform), deep knowledge of Azure networking and identity, and hands-on experience with Azure API Management (APIM), private endpoints, private DNS zones, and migrating legacy authentication to OAuth2 workflows. This is a role for a self-driven engineer who thrives in a fast-changing, fast-paced environment, can handle multiple projects at once, manage stressful situations, meet tight timelines, and deliver on time. Key Responsibilities - Infrastructure Design & Management - Architect and deploy Azure infrastructure aligned with the Azure Well-Architected Framework and Zero Trust security-first architecture principles. - Drive the infrastructure refactoring of .NET applications, including implementing Azure API Management to wrap legacy monoliths with modern security (OAuth2) and throttling policies. - Design hub-and-spoke network topologies, implement Private Endpoints, Private DNS Zones, and configure NSGs, route tables, and firewall rules to strictly isolate production workloads. - Architect the transition from legacy SMTP dependencies to modern, API-driven transactional email services (e.g., SendGrid integration) to ensure high deliverability and reliability. - Ensure robust network connectivity and performance, including Azure Load Balancer and Application Gateway for high availability. - Design and maintain disaster recovery strategies, multi-region failover, and backup solutions. - Security & Compliance - Implement and maintain security measures to protect data and infrastructure from threats, specifically focusing on PaaS hardening (SQL TDE, Storage Account Firewalls). - Apply Defender for Cloud and CIS Benchmarks to strengthen security posture and automate compliance reporting. - Configure Azure Entra ID, Azure AD B2C (Azure Entra External ID), Privileged Identity Management (PIM), and Just-In-Time (JIT) access controls to enforce least-privilege access. - Ensure compliance with ISO 27001, NIST, and familiarity with ISO 42001 for AI governance. - Automation & IaC - Drive pragmatic Terraform practices for infrastructure-as-code, creating modular, reusable code that prioritizes speed of delivery and maintainability over complexity. - Automate manual processes to improve efficiency and reduce errors across provisioning and configuration management. - Monitoring, Incident Management & On-Call - Implement centralized logging and monitoring solutions using Azure Monitor, Log Analytics, Application Insights, and New Relic to provide end-to-end visibility. - Integrate logs with Microsoft Sentinel and other SIEM platforms for real-time security and compliance visibility. - Lead incident management, root cause analysis, and preventive actions for critical infrastructure outages. - Participate in escalation and on-call rotations for product support, ensuring timely resolution of critical infrastructure issues. - Collaboration, Documentation & Knowledge Management - Collaborate with development and operations teams to bridge the gap between legacy code requirements and modern infrastructure standards. - Maintain comprehensive documentation, runbooks, and knowledge articles to support continuity and compliance. - Provide training and mentorship, leveraging 10–15 years of experience in knowledge management and best practices for enterprise-scale environments. Qualifications - Bachelor’s degree in Computer Science, IT, or equivalent experience. - 10+ years in cloud infrastructure engineering with expert-level Azure experience. - Expert-level proficiency in architecting enterprise-scale Azure Networking using Hub-and-Spoke topology, including advanced configuration of Azure Firewall/WAF, VNET peering, Hybrid Connection (VPN/ExpressRoute) and implementing Zero Trust connectivity for PaaS resources via Private Link, Private Endpoint and Private DNS Zones. - Proven expertise in Modernization: Demonstrated ability to implement Azure API Management, refactor legacy authentication flows (OAuth2), and modernize database security (TDE/Private Link). - Strong experience with Terraform (IaC) and automation frameworks. - Familiarity with Defender for Cloud, CIS Benchmarks, and centralized logging solutions. - Experience handling escalations and on-call responsibilities for critical infrastructure. Technical Skills - Azure services: Azure API Management (APIM), VMs, App Services (Containers), Azure SQL, Storage, Private Link, Private DNS, Azure Load Balancer, Application Gateway. - Networking: Hub-and-spoke, NSGs, route tables, Azure Firewall, VNET Peering. - Identity & Security: Azure Entra ID, Azure AD B2C, PIM/JIT, OAuth2/OIDC, Key Vault, SQL TDE. - Monitoring & Logging: Azure Monitor, Log Analytics, Application Insights, SIEM (Sentinel) integration. - Compliance: CIS Benchmarks, ISO/NIST frameworks. - Tooling: Terraform, Azure DevOps, Git, PowerShell/Az CLI. Soft Skills - Self-driven Finisher: Adaptable to fast-changing environments with a focus on closing tickets and delivering projects. - Ability to handle multiple projects, manage stress, and deliver on time. - Strong communication and documentation skills. Preferred Certifications - Microsoft Certified: Azure Solutions Architect Expert (AZ-305) - Microsoft Certified: Azure Administrator (AZ-104) - HashiCorp Certified: Terraform Associate Our core values: - Make sound decisions: We put ourselves in our customer's shoes, always ensuring we have the right facts and focus on solving the right problems. - Act like an owner: No matter the challenge, we overcome hurdles, seek out solutions, and follow through on commitments to consistently exceed expectations. - Get better every day: With our growth mindset and positive attitude, we apply our passion for innovation not just to our products, but also to ourselves. - We before me: Our collaborative spirit pushes us to act without ego, to communicate openly and honestly, and to win as a team. Benefits - Competitive salary and discretionary bonus - Flexible work environment - Career growth - Monthly team events - Industry-leading benefits plan
Senior Cloud Infrastructure Engineer
ValonEmpowering every homeowner with ease, security, and financial know-how.
• Design, build, and operate core cloud infrastructure across compute, storage, databases, and networking layers. • Own and improve the reliability, scalability, and security of Valon’s production systems as we scale to support major enterprise deployments. • Evaluate, adopt, and operationalize new infrastructure technologies (e.g., Vitess, Clickhouse, Redis) to meet evolving product and scale requirements. • Collaborate with product engineering, platform, and operations teams to define infrastructure solutions that unlock product innovation and operational efficiency. • Participate in on-call rotations and incident response, driving improvements to system observability, alerting, and reliability practices. • Contribute to architectural decisions and technical strategy for the platform, with an emphasis on pragmatic, well-reasoned trade-offs. • Mentor teammates through code reviews, design discussions, and knowledge sharing.
Staff Cloud Infrastructure Engineer
ValonEmpowering every homeowner with ease, security, and financial know-how.
• Set technical direction for cloud infrastructure at Valon, defining the architecture, standards, and roadmap for compute, storage, databases, and networking. • Lead the design and execution of complex, cross-cutting infrastructure initiatives—from new data store adoption to novel deployment architectures for enterprise customers. • Own the reliability, scalability, and security posture of Valon’s production infrastructure, driving systemic improvements across the stack. • Serve as a key technical partner to engineering leadership, product, and operations—translating business requirements into infrastructure strategy and ensuring alignment across teams. • Drive architectural decisions through design docs, RFCs, and technical reviews, setting a high bar for rigor and clarity. • Mentor and elevate the team through code reviews, design guidance, and active knowledge sharing, raising the overall technical bar. • Contribute to incident response and on-call, using incidents as opportunities to drive meaningful reliability improvements. • Identify and advocate for long-horizon infrastructure investments that position Valon for the next phase of scale and customer growth.

