Tech S and T-Infra Automation Consultant-ISR-Senior-GDSF02
Job description
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.
Infrastructure Automation Engineer (DevSecOps) – Azure, Kubernetes & Terraform
Experience: 6–9 years
Role Overview
We are seeking experienced and hands-on Senior Infrastructure Automation Engineers (DevSecOps) with strong proficiency in Azure and Kubernetes to design, provision, automate, secure, and support scalable multicloud infrastructure for enterprise workloads.
The role requires deep expertise in Infrastructure as Code with Terraform, container orchestration on Kubernetes, automated CI/CD pipeline engineering, Python-based infrastructure automation, and embedding security controls across the build, deploy, and run lifecycle, with a strong focus on reliability, compliance, cost-awareness, and delivery quality.
Key Responsibilities
- Design, provision, and manage scalable multicloud infrastructure with Azure as the primary platform and AWS as the secondary platform.
- Architect and operate production-grade Kubernetes clusters (AKS / EKS / self-managed) covering deployments, scaling, networking, ingress, secrets, RBAC, upgrades, and operational troubleshooting.
- Implement and govern Infrastructure as Code using Terraform — module design, remote state, workspaces, policy-as-code, and reusable platform components for repeatable, secure, and auditable deployments.
- Build, maintain, and optimize end-to-end CI/CD pipelines for application and infrastructure delivery, including build, test, scan, approval, and progressive deployment workflows.
- Develop Python-based automation, tooling, and operators to streamline provisioning, configuration, remediation, and day-2 operations across cloud platforms.
- Embed DevSecOps practices across the SDLC — SAST, DAST, SCA, container image scanning, IaC scanning, secrets management, and policy-as-code (OPA / Sentinel / Kyverno).
- Integrate cloud infrastructure with enterprise networking, IAM, security, monitoring, logging, and DevOps toolchains in line with enterprise standards.
- Monitor platform health, lead incident response, perform root cause analysis, and drive continuous service and reliability improvements.
- Ensure infrastructure is resilient, secure, compliant, cost-aware, and aligned with enterprise architecture, security baselines, and operational standards.
- Mentor junior engineers, lead technical reviews, and contribute to platform engineering standards, runbooks, and reference architectures.
Required Skills and Experience
- 6+ years of overall experience in cloud infrastructure engineering, DevOps, DevSecOps, or platform engineering, with at least 3+ years in a senior or lead capacity.
- Strong hands-on experience with Azure services (AKS, VNet, Azure AD / Entra ID, Key Vault, Storage, Monitor, Policy, Azure DevOps); working knowledge of AWS services (EKS, EC2, VPC, IAM, S3, CloudWatch) as the secondary platform.
- Deep, production-grade experience with Kubernetes and the broader container ecosystem (Docker, Helm, Istio / service mesh, ingress controllers, operators).
- Strong expertise in Terraform — module development, state management, multi-environment patterns, and integration with policy-as-code frameworks.
- Proven experience designing and operating CI/CD pipelines using Azure DevOps, GitHub Actions, Jenkins, GitLab CI, or equivalent, including pipeline security and supply-chain controls.
- Strong proficiency in Python for infrastructure automation, tooling, and integration; working knowledge of Bash / Shell scripting.
- Solid grounding in cloud security — IAM, network segmentation, encryption, secrets management, vulnerability management, and DevSecOps tooling (e.g., Trivy, Checkov, tfsec, SonarQube, Snyk, Aqua / Prisma Cloud).
- Good understanding of cloud networking, hybrid connectivity, load balancing, observability, logging, and access controls.
- Demonstrated experience troubleshooting complex infrastructure issues, deployment failures, distributed systems, and performance bottlenecks.
- Strong awareness of cloud governance, compliance frameworks (ISO 27001, SOC 2, CIS Benchmarks), cost optimization, and operational best practices.
- Strong analytical, problem-solving, documentation, collaboration, and stakeholder communication skills.
Qualification and Certifications
- B.E. / B.Tech in Computer Science, Information Technology, Engineering, or a related discipline.
- One or more relevant certifications strongly preferred — Microsoft Azure (AZ-104 / AZ-305 / AZ-400), CKA / CKAD / CKS, HashiCorp Terraform Associate, AWS Solutions Architect / DevOps Engineer, or recognized security certifications (CCSK, CompTIA Security+).
- Strong commitment to continuous learning and staying current with cloud, DevSecOps, Kubernetes, and platform engineering practices.
Good-to-Have Skills
- Exposure to GCP and broader multi-cloud operating models.
- Experience with policy-as-code and guardrails (OPA / Gatekeeper, Kyverno, Azure Policy, Sentinel).
- Experience with service mesh, GitOps tooling (ArgoCD, Flux), and progressive delivery patterns.
- Experience with monitoring and observability stacks such as Prometheus, Grafana, Azure Monitor, CloudWatch, ELK, Datadog, or Dynatrace.
- Experience with Azure Cost Management, AWS Cost Explorer, tagging strategies, and FinOps practices.
- Exposure to platform engineering, internal developer platforms (IDP), release management, and SRE practices.
Working Expectations
- Collaborate effectively with architecture, engineering, security, application, and operations teams across geographies.
- Maintain clear, version-controlled documentation for infrastructure design, deployment steps, SOPs, runbooks, and automation scripts.
- Demonstrate strong ownership in resolving issues, improving reliability, hardening security posture, and enhancing automation across cloud platforms.
- Follow enterprise delivery standards, security controls, change and operational procedures, and quality expectations.
- Provide technical mentorship and act as an escalation point for complex infrastructure, automation, and security challenges.
EY | Building a better working world
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.
Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.
Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.