Senior AI Systems Engineer

CloudZeroBoston, MA
$145,000 - $230,000Hybrid

About The Position

CloudZero is making a foundational hire in the Office of the CTO: the person who builds the data and AI platform the rest of the company operates on. Almost everything a team needs, whether it is the pipeline number, the churn signal, or the answer an agent gives a CS rep at 4pm, depends on data that today lives across dozens of SaaS systems and is moved by hand. You'll build the layer that ends that: governed pipelines into Snowflake, a modeled surface analysts and agents can query without guessing at joins, and the environments where agents run with real identity and real cost attribution. You'll also own the systems underneath it, including Okta, Jamf, Google Workspace, Slack, Jira, and Ravenna, because they're the identity and event substrate that the platform inherits. The Okta group that provisions a new hire's laptop is the same group that determines what an agent can access when that person invokes it. Whoever owns one should own both. Hybrid out of our Boston office. Some flexibility outside East Coast hours helps, since our employees and customers are global.

Requirements

  • 7+ years at the intersection of data engineering and infrastructure. You've built pipelines and the platforms they run on, and been on call for both.
  • Deep Snowflake experience as an analytical warehouse, an operational intelligence layer, and a governed substrate for agents. You know its RBAC, policy, and cost model, not just its SQL dialect.
  • Real modeling and transformation craft with dbt or equivalent, tested and version-controlled, plus orchestration (Dagster, Airflow, Prefect) and opinions about idempotency, backfills, and late-arriving data.
  • Strong software engineering fundamentals. Python required, SQL assumed, Go or Bash a plus.
  • IaC at scale (Pulumi, CDK, CloudFormation) where you set the standard rather than follow it.
  • Hands-on production AI and LLM experience with agents, RAG, tool-calling, and MCP or equivalent, plus a point of view on agent identity, tool governance, and what breaks once it's live.
  • Deep AWS (Bedrock, IAM, EventBridge, Lambda) with working knowledge of GCP and Azure.
  • Strong API instincts: you've stitched SaaS systems together with REST, webhooks, and event hooks, and know where those integrations rot.
  • Working command of the IT toolkit: Okta SSO and Workflows, Jamf including packaging, Google Workspace, and Jira, plus experience automating employee lifecycle against an HRIS.
  • A root-cause mindset and a bias for shipping.
  • You're exceptional with people. This role sits close to every team, and how you make someone feel matters.

Nice To Haves

  • Streaming or event-driven data experience (Kafka, Kinesis, Snowpipe)
  • Data observability and lineage tooling in production
  • Experience evaluating retrieval quality, where you measured whether RAG actually worked rather than just shipping it
  • Practical familiarity with SOC 2 or ISO 27001
  • Examples of agents, pipelines, or automations that retired a recurring class of work

Responsibilities

  • Build the data and AI platform the rest of the company operates on.
  • Build governed pipelines into Snowflake, a modeled surface analysts and agents can query without guessing at joins, and the environments where agents run with real identity and real cost attribution.
  • Own the systems underneath, including Okta, Jamf, Google Workspace, Slack, Jira, and Ravenna, because they're the identity and event substrate that the platform inherits.
  • Own the data platform, including ingestion from SaaS estate and cloud billing sources, CDC and ELT out of Salesforce/HubSpot, Jira, Okta, Ravenna, UKG, and support tooling, with schema drift handled and backfills that are boring.
  • Develop the modeled warehouse: conformed dimensions, tested transformations, and a semantic layer where "ARR" resolves to one number regardless of who asks.
  • Ensure data quality as a product concern: freshness SLAs, drift alerting, lineage.
  • Implement governance in the warehouse itself: Snowflake RBAC, row- and column-level policy, and masking mapped to Okta groups.
  • Provide cost visibility per team, per workload, per agent.
  • Build data products other teams run on: Marketing attribution, Finance close support, Sales pipeline, and CS health, as self-serve surfaces rather than a request queue.
  • Own the retrieval layer agents depend on: chunking strategy, embedding pipelines, index freshness, and evaluation of retrieval quality.
  • Implement the identity-inheritance model, so an agent invoked by a CS rep or a finance analyst operates with exactly the permissions they have across AWS, Snowflake, and SaaS.
  • Build AI Landing Zones across AWS, GCP, Azure, and Snowflake: governed, self-service environments where any department can deploy agents safely without being cloud engineers.
  • Own the developer experience for internal agent builders: templates, deploy paths, docs, and office hours.
  • Own the core IT platform (Okta, Jamf, Google Workspace, Slack, Jira, Ravenna) run as a product with a roadmap and a shrinking manual surface.
  • Automate employee lifecycle end-to-end: joiners, movers, and leavers driven by HRIS as the source of truth, with no human in the loop.
  • Manage the cloud perimeter: account structure, SCPs, IAM, and network segmentation for our major cloud providers (AWS, Azure, Snowflake), plus a Security partnership.

Benefits

  • Collaborative, fast-moving environment where your work makes a direct impact.
  • Ownership, creativity, and curiosity are valued.
  • Work with cutting-edge technology.
  • Drive meaningful outcomes.
  • Grow with a company that's scaling fast.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service