Manager, Cloud Automation Engineering

Voya FinancialAtlanta, GA
$114,480 - $170,070Hybrid

About The Position

Voya's Infrastructure Engineering organization is modernizing how cloud infrastructure gets built, changed, and governed across Azure, AWS, and OCI. Terraform and Ansible/AAP automation already run production workloads today — VM lifecycle and disaster-recovery failover, capacity management, and GitOps-driven application delivery — but much of that automation grew organically, without the version control, peer review, and audit trail that a regulated financial services environment requires. This role owns closing that gap: replacing ungoverned, direct-to-production automation patterns with a secure, auditable, and genuinely usable cloud automation platform. As Manager, Cloud Automation Engineering, you are a builder-operator hybrid: hands-on architect and contributor to the pipelines and platforms your team runs, and the people leader accountable for their delivery and growth. You will personally design and help build the CI/CD architecture for Terraform, Ansible/AAP, and GitOps (ArgoCD) — version-pinned artifact promotion, policy-as-code gates, and DTAP segregation — while also running forensic audits of the current estate to quantify risk and build the evidence base for remediation. You'll partner directly with security, compliance, and audit stakeholders to map every pipeline gate to a named control (SDLC-2, CP-054, CP-064, ITAM-3, SOC-12, Source Code Protection Standard), and you'll lead and grow a team of cloud/platform engineers who share that same builder mindset.

Requirements

  • Bachelor's degree in Computer Science, Engineering, or a related field, or equivalent practical experience.
  • 10+ years in infrastructure, platform, or cloud engineering, with deep hands-on infrastructure-as-code experience.
  • 5+ years in a leadership role directly managing engineers delivering cloud infrastructure automation.
  • Expert-level Terraform: module design, state management, provider and version pinning, multi-environment workspace/state strategy.
  • Expert-level Ansible: roles, collections, execution environments, and production experience with Ansible Automation Platform (Job Templates, Workflow Templates, RBAC, credential management).
  • Hands-on GitOps experience with ArgoCD or an equivalent tool on Kubernetes/OpenShift.
  • Deep experience building CI/CD pipelines (GitHub Actions or equivalent), including version-pinned artifact promotion across Dev/Test/Acceptance/Prod.
  • Hands-on with policy-as-code and static/composition-analysis tooling — OPA or equivalent policy engines, infrastructure linting and configuration scanners, Ansible lint/testing frameworks, and CVE/software composition analysis scanners.
  • Experience with artifact management platforms (e.g., JFrog Artifactory), including SBOM generation and artifact signing.
  • Multi-cloud hands-on experience across Azure, AWS, and/or OCI, including compute, networking, and disaster-recovery/failover automation.
  • Experience with enterprise secrets-management platforms (e.g., CyberArk Conjur, HashiCorp Vault) and eliminating secrets-in-code patterns.
  • Working knowledge of SIEM/observability integration for audit logging and security-event retention requirements.
  • Demonstrated experience operating in a regulated, audited environment — financial services strongly preferred — including SDLC governance frameworks, segregation-of-duties controls, and formal change/release management.
  • Experience running or contributing to control audits (branch protection, committer/collaborator review, secrets scanning, CI coverage) and translating findings into a prioritized remediation roadmap.
  • Excellent written and verbal communication; able to translate deep technical and compliance findings into a business-risk narrative for senior stakeholders.
  • Strong stakeholder management across security, compliance, and application engineering teams.
  • Comfortable operating as both an individual contributor writing production code and pipelines, and a people leader accountable for team output.

Nice To Haves

  • Experience with modern SIEM/observability stacks beyond traditional log-management tools.
  • Familiarity with Red Hat OpenShift GitOps or equivalent enterprise Kubernetes platforms.
  • Experience standing up a greenfield automation platform from scratch, not only uplifting an existing one.
  • Background contributing to, or leading formal IT control audits or SOX-adjacent evidence packages.

Responsibilities

  • Architect and personally build the Terraform (anchored on the shared-module repo) and Ansible/AAP pipelines spanning Azure, AWS, and OCI, replacing live branch-sync and direct-apply patterns with version-pinned, gated promotion.
  • Design and implement GitOps delivery via ArgoCD/OpenShift GitOps, moving self-syncing application patterns onto a discrete build-and-gate stage.
  • Define reference architectures, module/role standards, and reusable shared-module conventions — CI, CODEOWNERS, branch protection, semantic version tagging — enforced across every consumer repository.
  • Own end-to-end remediation of the Terraform uplift and Ansible greenfield rebuild: committer-limit enforcement, branch protection and peer review, version-pinned promotion across Dev/Test/Acceptance/Prod, and independent release-owner approval gates ahead of production.
  • Build and mature the security tooling stack: static analysis and policy-as-code for Terraform (linting, cloud-config scanning, OPA) and for Ansible (lint, Molecule, container/CVE scanning), plus software composition analysis and secret scanning across the estate.
  • Stand up SIEM and audit-trail coverage for Git activity, plan/apply and job-execution events, and secrets access; own the formal exception process where tooling choices deviate from the enterprise standard.
  • Close artifact-provenance gaps: SBOM generation and signed-artifact publishing for every build that reaches production.
  • Run forensic, evidence-based audits of live IaC estates — repository inventory, collaborator and committer counts, CI coverage, secrets hygiene, tag and version currency — to quantify governance gaps and build the business case for remediation or rebuild.
  • Identify and close shadow-repo and personal-namespace automation risk; consolidate automation onto sanctioned, org-owned repositories.
  • Partner with Change Management, Release Management, and the Change Advisory Board to map pipeline gates to formal change records, approval boards, and code-freeze/pre-production lockdown windows.
  • Own the automation supporting live production workloads across Azure, AWS, and OCI — VM lifecycle, disaster-recovery failover, and capacity management — ensuring changes flow through gated, auditable pipelines rather than console, SSH, or unreviewed branch-sync paths.
  • Partner with automation-platform owners to move control-plane configuration (job templates, RBAC, credential scopes) to config-as-code with the same version-pinning discipline applied to application code.
  • Build, lead, and grow a team of cloud and platform engineers, balancing hands-on architecture and code contribution with people leadership — hiring, performance, and career development.
  • Serve as the escalation point and technical authority for cloud automation architecture decisions; mentor engineers on secure pipeline design and infrastructure-as-code practices.
  • Represent cloud automation engineering in enterprise architecture, security, and compliance forums; translate technical risk and roadmap into terms senior technology and business stakeholders can act on.

Benefits

  • Health, dental, vision and life insurance plans
  • 401(k) Savings plan – with generous company matching contributions (up to 6%)
  • Voya Retirement Plan – employer paid cash balance retirement plan (4%)
  • Tuition reimbursement up to $5,250/year
  • Paid time off – including 20 days paid time off, nine paid company holidays and a flexible Diversity Celebration Day.
  • Paid volunteer time — 40 hours per calendar year
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service