JD 7 - Dev Ops | Senior Consultant

Sumeru Solutions

  • Dallas, TX
  • 1 day ago

    Highlights

    Primary Responsibilities: Security Agent Automation (WS-1): Lead development of automation scripts for integrating AWS Security Agent components with customer CI/CD tools and repositories; assist cloud infrastructure and security consultants with service implementation design. Automated Account Vending (WS-2): Design and implement automated account vending ensuring new Security Lab accounts inherit baseline security controls, guardrails, and compliance configurations.

    Numbers & Facts

    LocationDallas, TX

    Description

    JD 7 - Dev Ops | Senior Consultant

    The Depository Trust & Clearing Corporation | DTCC_ProServs_Portfolio Assessment_FICC-Project | Source Row 69 | RR(s): RR-0694246

    Client Name (Column AD)

    The Depository Trust & Clearing Corporation

    Job Description (Column W)

    Included below under Role Scope & Key Responsibilities

    Role Specialization (Column G)

    Dev Ops

    Role Experience (Column F)

    Senior Consultant - L6, 8+ years relevant experience

    Role Summary

    This Senior Consultant role builds automation, CI/CD, Infrastructure-as-Code and operational runbooks for AWS delivery. The consultant is expected to operate as an embedded AWS SME, provide hands-on implementation support, and create audit-ready technical documentation aligned to regulated Financial Services delivery expectations.

    Role Scope & Key Responsibilities (from Column W)

    Primary Responsibilities:

    • Security Agent Automation (WS-1): Lead development of automation scripts for integrating AWS Security Agent components with customer CI/CD tools and repositories; assist cloud infrastructure and security consultants with service implementation design
    • Automated Account Vending (WS-2): Design and implement automated account vending ensuring new Security Lab accounts inherit baseline security controls, guardrails, and compliance configurations
    • IRE & Clean Room Automation (WS-3): Serve as automation design lead for Independent Recovery Environment, including:
    • Automate CI/CD pipeline integration for code scanning, artifact validation, artifact hashing, and deployment controls
    • Build automated recovery runbooks using AWS Step Functions and Systems Manager
    • Develop backup integrity verification canaries and validation testing scripts
    • Create automated operational toolchain for data recovery from BitBucket and Nexus repositories
    • Amazon EKS Security Lab (WS-4): Assist with design, implementation, and deployment of Amazon EKS initial security baseline and lab environment setup
    • Knowledge Transfer: Contribute to automation and IaC templates, operational procedures, and administration guides for all workstreams

    Key Deliverables:

    • Terraform modules for Security Agent infrastructure and account vending
    • Python automation scripts for CI/CD integration and recovery orchestration
    • Step Functions state machines for automated recovery workflows
    • Backup integrity canaries and validation testing frameworks
    • GitOps workflow configurations and integrations
    • Operational runbooks and administration guides

    AWS Skills & Services (added)

    Infrastructure as Code & Automation:

    • Terraform: Expert-level proficiency in Terraform for AWS infrastructure provisioning, module development, state management, and multi-account deployments
    • AWS CloudFormation: StackSets for multi-account deployments, nested stacks, and drift detection
    • AWS CDK: Programmatic infrastructure definition for complex automation patterns
    • Python: Strong scripting capabilities for automation, AWS SDK (boto3), and integration with CI/CD tools

    Compute & Orchestration:

    • AWS Step Functions: State machine design for recovery orchestration, error handling, and workflow automation
    • AWS Systems Manager: Automation documents, Run Command, Session Manager, Parameter Store, and Patch Manager for operational toolchains
    • AWS Lambda: Serverless automation for event-driven workflows, backup validation, and artifact processing
    • Amazon EKS: Cluster provisioning, security baseline configuration, IRSA (IAM Roles for Service Accounts), pod security policies/standards

    Account Management & Governance:

    • AWS Organizations: Multi-account strategy, OU structure design, and SCP policies
    • AWS Control Tower: Landing zone automation, Account Factory customization, and guardrails
    • AWS Service Catalog: Automated account vending, standardized resource provisioning, and compliance-approved templates

    Security & Compliance:

    • AWS IAM: Advanced policies, permission boundaries, cross-account roles, and service accounts
    • AWS Secrets Manager: Secure credential management, secret rotation, and integration with CI/CD pipelines
    • AWS KMS: Customer Managed Keys (CMKs), key policies, and encryption automation
    • AWS Security Hub: Centralized security findings, compliance standards, and automated remediation
    • Amazon GuardDuty: Threat detection integration and automated response workflows
    • AWS Config: Configuration compliance, resource inventory, and conformance packs

    Backup & Disaster Recovery:

    • AWS Backup: Centralized backup management, backup plans, vault locking, and cross-account/cross-region backup
    • AWS Backup Audit Manager: Compliance framework design and backup policy enforcement
    • Amazon S3: Object Lock (WORM compliance), versioning, lifecycle policies, and cross-region replication
    • AWS Elastic Disaster Recovery (DRS): Continuous replication and recovery orchestration

    CI/CD & DevOps:

    • AWS CodePipeline: Pipeline orchestration for automated deployments and artifact validation
    • AWS CodeBuild: Managed build service for code scanning, artifact hashing, and container image builds
    • AWS CodeDeploy: Automated deployment to EC2, EKS, and Lambda
    • Amazon ECR: Container image registry with vulnerability scanning and lifecycle policies
    • AWS CodeCommit: Git repository integration (alternative to BitBucket)

    Monitoring & Observability:

    • Amazon CloudWatch: Metrics, logs, alarms, dashboards, and canary monitoring (CloudWatch Synthetics)
    • AWS X-Ray: Distributed tracing for automation workflows
    • CloudWatch Logs Insights: Advanced log querying for troubleshooting
    • Amazon EventBridge: Event-driven automation and cross-account event routing

    Networking & Security:

    • Amazon VPC: Advanced networking, security groups, NACLs, VPC peering, and PrivateLink
    • AWS Transit Gateway: Hub-and-spoke architecture and route table isolation
    • AWS Network Firewall: Stateful/stateless rules and intrusion prevention
    • Amazon Route 53: DNS management and private hosted zones

    Storage & Data Management:

    • Amazon S3: Bucket policies, encryption, event notifications, and presigned URLs
    • Amazon EFS: Shared file storage for EKS persistent volumes
    • AWS DataSync: Automated data transfer for backup and recovery workflows

    GitOps & Version Control:

    • AWS CodeCommit / GitHub / GitLab integration: GitOps workflow patterns
    • Flux / ArgoCD on EKS: GitOps continuous deployment for Kubernetes
    • BitBucket integration: Operational toolchain recovery and automation (nice-to-have)
    • Nexus Repository integration: Artifact management and recovery automation (nice-to-have)

    Container & Kubernetes Security:

    • Amazon EKS: Security baseline configuration, network policies, pod security standards, secrets encryption
    • Amazon ECR: Image scanning, vulnerability assessment, and immutable tags
    • AWS App Mesh: Service mesh for microservices security and observability
    • Kubernetes RBAC: Role-based access control and service account management

    Automation & Testing:

    • AWS CloudWatch Synthetics: Canary scripts for backup integrity verification and endpoint monitoring
    • AWS Systems Manager Automation: Automated remediation and operational runbooks
    • Python Testing Frameworks: pytest, unittest for validation testing scripts
    • Terraform Testing: terratest, tflint for IaC validation

    Financial Services & Industry Skills (added)

    • Large regulated financial-services delivery with formal change-control, audit and risk governance
    • Operational resilience expectations including RTO/RPO, multi-region DR and evidence for audit review
    • Awareness of applicable controls and regulations such as DORA, NIST CSF 2.0, PCI DSS, SEC cyber rules, RegSCI and SIFMU/FMI expectations where relevant
    • Ability to create Tech Risk-ready documentation including ADRs, runbooks, design docs, threat models and validation evidence
    • Clear communication with client engineering, security, SRE, data and platform stakeholders as an embedded SME

    Certifications / Qualifications

    • AWS Certified DevOps Engineer - Professional
    • AWS Certified Solutions Architect - Associate / Professional
    • HashiCorp Terraform Associate / CKA preferred

    General Requirements

    • 8+ years of relevant hands-on delivery experience at L6 scope
    • Prior delivery in a large regulated enterprise environment, preferably financial services
    • Ability to write architecture decision records, design documents, runbooks and test evidence for client Tech Risk review
    • Strong stakeholder communication across engineering, security, operations, SRE and delivery teams
    • Compliance with AWS ProServe and client onboarding, security, vetting and time-zone overlap requirements

    Similar Jobs