Staff Infrastructure & Security Engineer

Vouch InsuranceChicago, IL
$200,000 - $240,000

About The Position

Serve as the technical DRI for the Infra & Security group: own the architecture, set the standards, and make the technical calls across infrastructure, DevOps, and security engineering. Own the cloud platform end-to-end: infrastructure reliability, CI/CD and delivery automation, and the infrastructure-as-code beneath them. Drive a simpler, isolated architecture through shrinking the surface area we defend and maintain: Retire legacy and unused services, consolidate SaaS and vendors, and unwind standing external dependencies. Own infra & security incident-response: a staffed rotation with no single point of failure, severity-matched response, actionable alerting, and runbooks. Bring identity and access under a single source of truth: human, service, machine, and agent identity. Build the Production-agent Infrastructure that lets autonomous agents run and self-verify safely in production. Drive and maintain our security-compliance and supply-chain scanning programs.

Requirements

  • Deep cloud engineering experience, primarily in AWS: designing, building, and operating production infrastructure at scale.
  • Strong in CI/CD and delivery automation (CircleCI, Nomad, or equivalent) and infrastructure-as-code (Terraform), with ownership of a real production system's reliability.
  • Apply security pragmatically: isolation, least-privilege, RBAC, blast-radius containment.
  • A formal background in information security or cybersecurity, including having led a SOC 2 (or similar) compliance audit.
  • Has led at least one enterprise security-breach or data-leak incident response.
  • Comfortable as a hands-on technical lead and DRI: work through architecture, standards, and code review, set technical direction, and raise the bar across a team.
  • A bias toward simplicity and subtraction.
  • AI-forward: build for isolation, safe data, and non-human identity, and the infrastructure behind it.
  • Communicate crisply across engineering, IT/Security, Legal, and Finance.

Nice To Haves

  • Experience operating Temporal or similar durable-workflow infrastructure in production.
  • Hands-on with supply-chain / dependency vulnerability scanning (Endor Labs, Snyk, or equivalent).
  • Compliance-as-code experience: treating controls and evidence as an engineering artifact.
  • Familiarity with agent / sandbox isolation patterns: dedicated accounts, scoped tokens, ephemeral environments, and data masking.
  • Secrets and credential management at scale (1Password, AWS SSM, or equivalent).
  • Experience in insurance, fintech, or another regulated domain.
  • A university degree in cybersecurity or a related field.

Responsibilities

  • Serve as the technical DRI for the Infra & Security group: own the architecture, set the standards, and make the technical calls across infrastructure, DevOps, and security engineering.
  • Own the cloud platform end-to-end: infrastructure reliability, CI/CD and delivery automation, and the infrastructure-as-code beneath them.
  • Drive a simpler, isolated architecture through shrinking the surface area we defend and maintain: Retire legacy and unused services, consolidate SaaS and vendors, and unwind standing external dependencies.
  • Own infra & security incident-response: a staffed rotation with no single point of failure, severity-matched response, actionable alerting, and runbooks.
  • Bring identity and access under a single source of truth: human, service, machine, and agent identity.
  • Build the Production-agent Infrastructure that lets autonomous agents run and self-verify safely in production.
  • Drive and maintain our security-compliance and supply-chain scanning programs.

Benefits

  • Competitive compensation and equity packages
  • Health, dental, and vision insurance
  • Parental leave
  • Flexible vacation time
  • Wellness allowance
  • Technology allowance
  • Company-sponsored personal and professional development
  • L&D: Partnerships with Ethena and monthly Lunch & Learns
  • Wellbeing: access to many wellbeing perks, including Peloton, Fetch, OneMedical, Headspace care+, etc.
  • Caregiver Support: company seed into the dependent care FSA and company sponsored Care.com membership.
  • Regular performance reviews: Vouch conducts regular performance discussions with all team members, offering goal setting and check-ins, development discussions, and promotion opportunities.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service