Back to jobs

Senior Cloud Operations Engineer

United States

At Dragos, the mission is personal. The systems we protect deliver the water you drink, power your home, and keep the hospitals your community depends on running. Those critical infrastructure systems that power our civilization around the world are under attack every day by adversaries. When those systems fail, people are immediately at risk. We are the global leader in xOT cybersecurity, combining technology, threat intelligence, and expert services. The people here chose this work because they understand what is at stake. Here, you will find a remote-first mission-driven team across North America, Europe, the Middle East, and APAC built on authenticity, transparency, and trust. If safeguarding the systems that protect your family, friends, and community is the kind of work that matters to you, you are in the right place. 

About the Role 

We are seeking an experienced Senior Cloud Operations Engineer to join our Cloud Skill Community. This role owns the operational health of the Dragos customer cloud fleet across Azure, AWS, and GCP -- both Dragos-managed and customer-managed environments. You will drive fleet reliability, deployment automation, and day-to-day operations at scale, bringing a strong infrastructure-as-code mindset and a bias toward automation and repeatability. 

Responsibilities 

  • Operate, maintain, and improve the Dragos cloud fleet across Azure, AWS, and GCP
  • Own the full customer environment lifecycle -- onboarding, configuration, upgrades, and off boarding
  • Build and maintain Terraform-based infrastructure-as-code for customer environment provisioning and fleet standardization
  • Manage fleet health, drift detection, patching, and version lifecycle management at customer scale
  • Design and enforce multi-tenant isolation patterns -- blast radius containment, RBAC at scale, and cross-account access controls
  • Configure and maintain cloud networking components across all three providers (VPCs/VNets, peering, transit gateways, DNS, firewalls, load balancers)
  • Manage cloud-to-OT/on-prem connectivity for customer environments
  • Implement and maintain IAM, secrets management, and compliance posture across cloud providers
  • Build and maintain Datadog observability -- monitors, dashboards, log pipelines, and SLOs
  • Participate in an on-call rotation (PagerDuty) for the Dragos cloud fleet -- triage, respond to, and resolve production incidents across customer environments
  • Drive SRE practices: define SLOs, manage error budgets, maintain runbooks, and lead post-incident reviews
  • Support audit and compliance activities including evidence collection for FedRAMP, SOC2, and customer-specific requirements
  • Identify and eliminate toil through automation and process improvement 

Qualifications 

  • 4+ years of hands-on cloud operations experience across one or more of Azure, AWS, or GCP
  • Strong proficiency with Terraform for infrastructure-as-code (primary IaC tool at Dragos)
  • Experience operating cloud environments at scale -- fleet management, patching, upgrades, drift detection
  • Hands-on experience with multi-tenant cloud architectures and customer-facing environment management
  • Solid knowledge of cloud networking: VPCs/VNets, peering, transit gateways, DNS, firewalls, and hybrid connectivity
  • Experience with IAM across AWS, Azure Entra ID, and/or GCP -- roles, policies, federation, SSO
  • Proficiency with Datadog for monitoring, alerting, dashboards, and log pipelines
  • Comfort with on-call responsibilities -- this role participates in a PagerDuty rotation for the customer cloud fleet
  • Experience with SRE practices: SLO definition, error budget management, incident response, and blameless post-mortems
  • Strong scripting skills in Python and/or Bash
  • Familiarity with compliance frameworks (FedRAMP, SOC2, NIST CSF) and audit evidence collection
  • Strong ownership mindset and accountability for production stability
  • Excellent communication, documentation, and collaboration skills 

Preferred Qualifications 

  • Experience with all three major cloud providers: Azure, AWS, and GCP
  • Experience managing cloud environments for external customers (customer-managed and vendor-managed models)
  • Cybersecurity Experience
  • Familiarity with cloud-to-OT/ICS network connectivity and segmentation
  • Experience with secrets management tooling: HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, GCP Secret Manager
  • Experience with cloud-native fleet tools: AWS Systems Manager, Azure Arc, GCP Fleet Management
  • Proficiency with policy-as-code tools (OPA, Sentinel, AWS SCPs, Azure Policy)
  • Experience with FinOps practices and cloud cost optimization
  • Familiarity with Cloud Security Posture Management (CSPM) tooling
  • Experience with CI/CD pipeline authoring (GitHub Actions)
  • Passion for automation and continuously improving operational efficiency 

Compensation: 

  • Salary:  $165,000
  • Competitive Equity Package  
  • Comprehensive Benefits Plan 

 

  

#LI-NH1 #LI-REMOTE 

 

Dragos is an Equal Opportunity Employer and considers applicants for employment without regard to race, color, religion, sex, orientation, national origin, age, disability, genetics, or any other basis forbidden under federal, state, or local laws. All new hires must pass a background check as a condition of employment.

Create a Job Alert

Interested in building your career at Dragos? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Dragos’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

As part of our hiring process, The Dragos team uses Greenhouse’s AI-powered Talent Matching tool to compare your application against our job requirements. A human is always in the loop and is the final decision maker. 

Learn more