Job Requirements
Bellevue, WA
Top Secret/SCI Polygraph
Career Level not specified
$129,200 - $174,800
Job Description
Description
Region Services Corporate Infrastructure (RSCI) Core Services owns the foundational Windows infrastructure that every team in Amazon Dedicated Cloud (ADC) depends on - Active Directory, DNS, DHCP, DFS, Group Policy, and Enterprise Configuration Manager (ECM). These services run across multiple isolated environments supporting U.S. Government customers. We are not looking for someone to maintain the status quo. Our team is transforming from a manually-operated infrastructure organization into a DevOps-driven engineering team. We need a Systems Development Engineer who will own the design and implementation of our automation architecture - building the Ansible frameworks, AWS pipelines, and operational tooling that eliminate manual processes and enable our services to scale. This is not a "write a playbook when you get time" role. You will architect how we codify, deploy, configure, and lifecycle-manage Windows infrastructure services through automation. You will design reusable Ansible roles and collections, build CI/CD pipelines using AWS CDK, instrument services with CloudWatch monitoring, and establish the patterns that the rest of the team adopts. You need working familiarity with the Windows services we manage - but your primary value is your ability to engineer the systems that manage them. You will also participate in an on-call rotation, owning incidents for the services your automation manages. When things break, you fix them - and then you build the automation that prevents recurrence. The candidate selected must obtain and maintain a security clearance at the TS/SCI with polygraph level. Upon start, the selected candidate will be sponsored for a commensurate clearance for each government agency for which they perform AWS work. Key job responsibilities Own automation architecture: Design and implement the Ansible automation framework (roles, collections, inventories, execution patterns) that manages Core Services infrastructure at scale • Build delivery pipelines: Develop and maintain AWS CI/CD pipelines (CDK, CodePipeline, CodeBuild) that deliver infrastructure changes through tested, repeatable deployments • Instrument and monitor: Build CloudWatch-based observability - dashboards, alarms, and metrics - that provide proactive visibility into service health across isolated environments • Operate and support: Maintain production Windows infrastructure services (AD, DNS, DHCP, DFS, ECM, Group Policy); participate in on-call rotation and provide escalation support • Eliminate manual operations: Identify, prioritize, and migrate manual runbook processes to code-defined, version-controlled automation • Establish engineering standards: Define patterns for infrastructure-as-code, testing, code What This Role Is NOT: • This is not a desktop support or endpoint engineering role • This is not a "keep the lights on" operations role where automation is a side project • This is not a Linux/Unix position - our infrastructure is Windows, our automation targets Windows, and our scripting is PowerShell-heavy • This is a role where you are expected to write code daily, own systems end-to-end, and drive architectural decisions review, and deployment that the team follows - raise the engineering bar • Mentor and lead technically: Guide junior engineers on automation practices, code quality, and operational excellence; drive technical design reviews • Maintain documentation: Create and maintain architecture documentation, automation design docs, and operational runbooks
Basic Qualifications
- 2+ years of non-internship professional software development experience - 1+ years of designing or architecting (design patterns, reliability and scaling) of new and existing systems experience - Experience programming with at least one modern language such as C++, C#, Java, Python, Golang, PowerShell, Ruby - Cloud+ or GICSP (Global Industrial Cyber Security Professional) or GSEC (GIAC Security Essentials) or SSCP (Systems Security Certified Practitioner), or Associate's degree or above - 5+ years of systems design, software development, operations, automation, and process improvement experience - Experience with infrastructure as code, ops automation, and configuration management tools such as Chef, Puppet, or Ansible - Working familiarity with Windows Server infrastructure: Active Directory, DNS, DHCP, Group Policy
Preferred Qualifications
- Experience with infrastructure as code, ops automation, and configuration management tools such as Chef, Puppet, or Ansible - Deep knowledge of Active Directory architecture (multi-domain forests, replication, sites/services, certificate services) - Experience with AWS CDK (TypeScript or Python) for defining infrastructure - Experience operating in air-gapped or isolated network environments - Familiarity with ECM/SCCM/MECM for OS deployment and patch management - Experience with DFS namespaces and replication - Experience designing Ansible automation for Windows targets (WinRM, Windows modules) - Track record of replacing manual operational processes with scalable automation - bring examples - Experience with infrastructure testing frameworks (Molecule, Pester, or equivalent) - Understanding of PKI/certificate services and identity management in Windows environments - Experience with PowerShell (preferred), Python, Ruby, or Java Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status. Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you're applying in isn't listed, please contact your Recruiting Partner.
The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits .
USA, WA, Bellevue - 129,200.00 - 174,800.00 USD annually USA, WA, Seattle - 129,200.00 - 174,800.00 USD annually
Region Services Corporate Infrastructure (RSCI) Core Services owns the foundational Windows infrastructure that every team in Amazon Dedicated Cloud (ADC) depends on - Active Directory, DNS, DHCP, DFS, Group Policy, and Enterprise Configuration Manager (ECM). These services run across multiple isolated environments supporting U.S. Government customers. We are not looking for someone to maintain the status quo. Our team is transforming from a manually-operated infrastructure organization into a DevOps-driven engineering team. We need a Systems Development Engineer who will own the design and implementation of our automation architecture - building the Ansible frameworks, AWS pipelines, and operational tooling that eliminate manual processes and enable our services to scale. This is not a "write a playbook when you get time" role. You will architect how we codify, deploy, configure, and lifecycle-manage Windows infrastructure services through automation. You will design reusable Ansible roles and collections, build CI/CD pipelines using AWS CDK, instrument services with CloudWatch monitoring, and establish the patterns that the rest of the team adopts. You need working familiarity with the Windows services we manage - but your primary value is your ability to engineer the systems that manage them. You will also participate in an on-call rotation, owning incidents for the services your automation manages. When things break, you fix them - and then you build the automation that prevents recurrence. The candidate selected must obtain and maintain a security clearance at the TS/SCI with polygraph level. Upon start, the selected candidate will be sponsored for a commensurate clearance for each government agency for which they perform AWS work. Key job responsibilities Own automation architecture: Design and implement the Ansible automation framework (roles, collections, inventories, execution patterns) that manages Core Services infrastructure at scale • Build delivery pipelines: Develop and maintain AWS CI/CD pipelines (CDK, CodePipeline, CodeBuild) that deliver infrastructure changes through tested, repeatable deployments • Instrument and monitor: Build CloudWatch-based observability - dashboards, alarms, and metrics - that provide proactive visibility into service health across isolated environments • Operate and support: Maintain production Windows infrastructure services (AD, DNS, DHCP, DFS, ECM, Group Policy); participate in on-call rotation and provide escalation support • Eliminate manual operations: Identify, prioritize, and migrate manual runbook processes to code-defined, version-controlled automation • Establish engineering standards: Define patterns for infrastructure-as-code, testing, code What This Role Is NOT: • This is not a desktop support or endpoint engineering role • This is not a "keep the lights on" operations role where automation is a side project • This is not a Linux/Unix position - our infrastructure is Windows, our automation targets Windows, and our scripting is PowerShell-heavy • This is a role where you are expected to write code daily, own systems end-to-end, and drive architectural decisions review, and deployment that the team follows - raise the engineering bar • Mentor and lead technically: Guide junior engineers on automation practices, code quality, and operational excellence; drive technical design reviews • Maintain documentation: Create and maintain architecture documentation, automation design docs, and operational runbooks
Basic Qualifications
- 2+ years of non-internship professional software development experience - 1+ years of designing or architecting (design patterns, reliability and scaling) of new and existing systems experience - Experience programming with at least one modern language such as C++, C#, Java, Python, Golang, PowerShell, Ruby - Cloud+ or GICSP (Global Industrial Cyber Security Professional) or GSEC (GIAC Security Essentials) or SSCP (Systems Security Certified Practitioner), or Associate's degree or above - 5+ years of systems design, software development, operations, automation, and process improvement experience - Experience with infrastructure as code, ops automation, and configuration management tools such as Chef, Puppet, or Ansible - Working familiarity with Windows Server infrastructure: Active Directory, DNS, DHCP, Group Policy
Preferred Qualifications
- Experience with infrastructure as code, ops automation, and configuration management tools such as Chef, Puppet, or Ansible - Deep knowledge of Active Directory architecture (multi-domain forests, replication, sites/services, certificate services) - Experience with AWS CDK (TypeScript or Python) for defining infrastructure - Experience operating in air-gapped or isolated network environments - Familiarity with ECM/SCCM/MECM for OS deployment and patch management - Experience with DFS namespaces and replication - Experience designing Ansible automation for Windows targets (WinRM, Windows modules) - Track record of replacing manual operational processes with scalable automation - bring examples - Experience with infrastructure testing frameworks (Molecule, Pester, or equivalent) - Understanding of PKI/certificate services and identity management in Windows environments - Experience with PowerShell (preferred), Python, Ruby, or Java Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status. Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you're applying in isn't listed, please contact your Recruiting Partner.
The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits .
USA, WA, Bellevue - 129,200.00 - 174,800.00 USD annually USA, WA, Seattle - 129,200.00 - 174,800.00 USD annually
group id: amazon
AWS Cleared Jobs: Why I Chose AWS