JD 7 - Dev Ops | Senior Consultant
The Depository Trust & Clearing Corporation | DTCC_ProServs_Portfolio Assessment_FICC-Project | Source Row 69 | RR(s): RR-0694246
Client Name (Column AD) | The Depository Trust & Clearing Corporation |
Job Description (Column W) | Included below under Role Scope & Key Responsibilities |
Role Specialization (Column G) | Dev Ops |
Role Experience (Column F) | Senior Consultant - L6, 8+ years relevant experience |
This Senior Consultant role builds automation, CI/CD, Infrastructure-as-Code and operational runbooks for AWS delivery. The consultant is expected to operate as an embedded AWS SME, provide hands-on implementation support, and create audit-ready technical documentation aligned to regulated Financial Services delivery expectations.
Role Scope & Key Responsibilities (from Column W)
Primary Responsibilities:
- Security Agent Automation (WS-1): Lead development of automation scripts for integrating AWS Security Agent components with customer CI/CD tools and repositories; assist cloud infrastructure and security consultants with service implementation design
- Automated Account Vending (WS-2): Design and implement automated account vending ensuring new Security Lab accounts inherit baseline security controls, guardrails, and compliance configurations
- IRE & Clean Room Automation (WS-3): Serve as automation design lead for Independent Recovery Environment, including:
- Automate CI/CD pipeline integration for code scanning, artifact validation, artifact hashing, and deployment controls
- Build automated recovery runbooks using AWS Step Functions and Systems Manager
- Develop backup integrity verification canaries and validation testing scripts
- Create automated operational toolchain for data recovery from BitBucket and Nexus repositories
- Amazon EKS Security Lab (WS-4): Assist with design, implementation, and deployment of Amazon EKS initial security baseline and lab environment setup
- Knowledge Transfer: Contribute to automation and IaC templates, operational procedures, and administration guides for all workstreams
Key Deliverables:
- Terraform modules for Security Agent infrastructure and account vending
- Python automation scripts for CI/CD integration and recovery orchestration
- Step Functions state machines for automated recovery workflows
- Backup integrity canaries and validation testing frameworks
- GitOps workflow configurations and integrations
- Operational runbooks and administration guides
AWS Skills & Services (added)
Infrastructure as Code & Automation:
- Terraform: Expert-level proficiency in Terraform for AWS infrastructure provisioning, module development, state management, and multi-account deployments
- AWS CloudFormation: StackSets for multi-account deployments, nested stacks, and drift detection
- AWS CDK: Programmatic infrastructure definition for complex automation patterns
- Python: Strong scripting capabilities for automation, AWS SDK (boto3), and integration with CI/CD tools
Compute & Orchestration:
- AWS Step Functions: State machine design for recovery orchestration, error handling, and workflow automation
- AWS Systems Manager: Automation documents, Run Command, Session Manager, Parameter Store, and Patch Manager for operational toolchains
- AWS Lambda: Serverless automation for event-driven workflows, backup validation, and artifact processing
- Amazon EKS: Cluster provisioning, security baseline configuration, IRSA (IAM Roles for Service Accounts), pod security policies/standards
Account Management & Governance:
- AWS Organizations: Multi-account strategy, OU structure design, and SCP policies
- AWS Control Tower: Landing zone automation, Account Factory customization, and guardrails
- AWS Service Catalog: Automated account vending, standardized resource provisioning, and compliance-approved templates
Security & Compliance:
- AWS IAM: Advanced policies, permission boundaries, cross-account roles, and service accounts
- AWS Secrets Manager: Secure credential management, secret rotation, and integration with CI/CD pipelines
- AWS KMS: Customer Managed Keys (CMKs), key policies, and encryption automation
- AWS Security Hub: Centralized security findings, compliance standards, and automated remediation
- Amazon GuardDuty: Threat detection integration and automated response workflows
- AWS Config: Configuration compliance, resource inventory, and conformance packs
Backup & Disaster Recovery:
- AWS Backup: Centralized backup management, backup plans, vault locking, and cross-account/cross-region backup
- AWS Backup Audit Manager: Compliance framework design and backup policy enforcement
- Amazon S3: Object Lock (WORM compliance), versioning, lifecycle policies, and cross-region replication
- AWS Elastic Disaster Recovery (DRS): Continuous replication and recovery orchestration
CI/CD & DevOps:
- AWS CodePipeline: Pipeline orchestration for automated deployments and artifact validation
- AWS CodeBuild: Managed build service for code scanning, artifact hashing, and container image builds
- AWS CodeDeploy: Automated deployment to EC2, EKS, and Lambda
- Amazon ECR: Container image registry with vulnerability scanning and lifecycle policies
- AWS CodeCommit: Git repository integration (alternative to BitBucket)
Monitoring & Observability:
- Amazon CloudWatch: Metrics, logs, alarms, dashboards, and canary monitoring (CloudWatch Synthetics)
- AWS X-Ray: Distributed tracing for automation workflows
- CloudWatch Logs Insights: Advanced log querying for troubleshooting
- Amazon EventBridge: Event-driven automation and cross-account event routing
Networking & Security:
- Amazon VPC: Advanced networking, security groups, NACLs, VPC peering, and PrivateLink
- AWS Transit Gateway: Hub-and-spoke architecture and route table isolation
- AWS Network Firewall: Stateful/stateless rules and intrusion prevention
- Amazon Route 53: DNS management and private hosted zones
Storage & Data Management:
- Amazon S3: Bucket policies, encryption, event notifications, and presigned URLs
- Amazon EFS: Shared file storage for EKS persistent volumes
- AWS DataSync: Automated data transfer for backup and recovery workflows
GitOps & Version Control:
- AWS CodeCommit / GitHub / GitLab integration: GitOps workflow patterns
- Flux / ArgoCD on EKS: GitOps continuous deployment for Kubernetes
- BitBucket integration: Operational toolchain recovery and automation (nice-to-have)
- Nexus Repository integration: Artifact management and recovery automation (nice-to-have)
Container & Kubernetes Security:
- Amazon EKS: Security baseline configuration, network policies, pod security standards, secrets encryption
- Amazon ECR: Image scanning, vulnerability assessment, and immutable tags
- AWS App Mesh: Service mesh for microservices security and observability
- Kubernetes RBAC: Role-based access control and service account management
Automation & Testing:
- AWS CloudWatch Synthetics: Canary scripts for backup integrity verification and endpoint monitoring
- AWS Systems Manager Automation: Automated remediation and operational runbooks
- Python Testing Frameworks: pytest, unittest for validation testing scripts
- Terraform Testing: terratest, tflint for IaC validation
Financial Services & Industry Skills (added)
- Large regulated financial-services delivery with formal change-control, audit and risk governance
- Operational resilience expectations including RTO/RPO, multi-region DR and evidence for audit review
- Awareness of applicable controls and regulations such as DORA, NIST CSF 2.0, PCI DSS, SEC cyber rules, RegSCI and SIFMU/FMI expectations where relevant
- Ability to create Tech Risk-ready documentation including ADRs, runbooks, design docs, threat models and validation evidence
- Clear communication with client engineering, security, SRE, data and platform stakeholders as an embedded SME
Certifications / Qualifications
- AWS Certified DevOps Engineer - Professional
- AWS Certified Solutions Architect - Associate / Professional
- HashiCorp Terraform Associate / CKA preferred
- 8+ years of relevant hands-on delivery experience at L6 scope
- Prior delivery in a large regulated enterprise environment, preferably financial services
- Ability to write architecture decision records, design documents, runbooks and test evidence for client Tech Risk review
- Strong stakeholder communication across engineering, security, operations, SRE and delivery teams
- Compliance with AWS ProServe and client onboarding, security, vetting and time-zone overlap requirements