{"id":1488488,"url":"https://alion.io/job/origami-risk-llc-devops-manager-platform","title":"DevOps Manager, Platform","company":{"id":7314,"name":"Origami Risk LLC","domain":"origamirisk.com","url":"https://alion.io/company/origami-risk-llc","size_band":"51-200","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"iCIMS","truth_index":null},"role":"DevOps","role_family":"DevOps","seniority":"lead","employment_type":null,"work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":[],"countries":[],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":145000,"max":185000,"currency":"USD","period":"year","gross":null,"usd_annual":185000},"salary_estimate":null,"experience_years_min":2,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Amazon Aurora","optional":false},{"name":"Amazon CloudWatch","optional":false},{"name":"Amazon ECS","optional":false},{"name":"Amazon EKS","optional":false},{"name":"Amazon S3","optional":false},{"name":"Ansible","optional":false},{"name":"API Gateway","optional":false},{"name":"AWS","optional":false},{"name":"AWS Fargate","optional":false},{"name":"AWS Lambda","optional":false},{"name":"Azure DevOps","optional":false},{"name":"CI/CD","optional":false},{"name":"Claude Code","optional":false},{"name":"Configuration Management","optional":false},{"name":"Cursor","optional":false},{"name":"Datadog","optional":false},{"name":"DNS","optional":false},{"name":"Docker","optional":false},{"name":"DynamoDB","optional":false},{"name":"Flyway","optional":false},{"name":"GitHub Actions","optional":false},{"name":"Helm","optional":false},{"name":"IAM","optional":false},{"name":"Incident Management","optional":false},{"name":"Kubernetes","optional":false},{"name":"Langfuse","optional":false},{"name":"Least Privilege","optional":false},{"name":"LLM","optional":false},{"name":"LLM Guardrails","optional":false},{"name":"New Relic","optional":false},{"name":"NIST 800-53","optional":false},{"name":"OpenSearch","optional":false},{"name":"Platform Engineering","optional":false},{"name":"PowerShell","optional":false},{"name":"Python","optional":false},{"name":"Rest API","optional":false},{"name":"SOC 2","optional":false},{"name":"Sumo Logic","optional":false},{"name":"Terraform","optional":false},{"name":"AWS Step Functions","optional":true},{"name":"Azure","optional":true},{"name":"Java","optional":true}],"status":"live","first_seen_at":"2026-09-30T00:05:15Z","employer_posted_date":"2026-09-30","last_verified_at":"2026-09-30T09:50:52Z","board_verified":true,"closed_at":null,"days_open":2,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":2},"description":"Overview\nA great platform team is defined not by how many tickets it closes, but by how little friction stands between an engineer's idea and a running service, because the team built the pipelines, golden paths, and AI-augmented workflows that make delivery self-service. The DevOps Manager, Platform is the people leader and hands-on technical operator who makes that true at Origami Risk.\nThis manager leads the team that builds, runs, and continuously improves the developer platform and delivery automation that Engineering teams depend on to ship every day, spanning CI/CD pipelines and shared templates, service-layer Terraform, the EKS container platform and capabilities golden path, application connectivity and service data stores, environment promotion, and the AI tooling layered on top. Everything runs in AWS, on top of the landing zone the Cloud Infrastructure team owns. This is a hands-on technical leader who coaches Engineers on platform-engineering craft, sets a high bar for delivery reliability and operational discipline, drives AI adoption into daily DevOps workflows, and partners with Engineering, Release, SRE, and Cloud Infrastructure so that the path to production is a source of competitive advantage and not a constraint on what Engineering can deliver. On this team, manual work is a problem to be solved, automation is the default, and every Engineer is expected to use AI to work faster and diagnose more accurately.\nStarting base pay for this role is between $145,000 and $185,000. The actual base pay is dependent upon many factors, such as transferable skills, work experience, business needs, training, location, and market demands. The base pay range is subject to change and may be modified in the future. This role will be eligible for a bonus as well as competitive medical, dental, and vision benefits, wellness reimbursement, life insurance, and a 401(k) with company match. We offer vacation and sick leave benefits (under a flexible time off policy in most states).\nResponsibilities\nWhat this team runs:\nThis is the developer platform and delivery layer that sits on top of the AWS landing zone - the systems Engineering uses to build, ship, and operate services every day. The team owns the platform for application and service delivery, not the landing zone underneath it. The team owns:\nDelivery Pipelines & Build: the CI/CD build and deploy pipelines, and the shared pipeline templates that Engineering teams across the org use to ship every day. \nService-Layer IaC: the infrastructure-as-code that defines each service's cloud resources, versioned and deployed through Terraform. \nKubernetes & Container Platform: the EKS container platform and the self-service golden path that lets a new service onboard with no bespoke infrastructure work. \nApplication Connectivity: the application-facing API gateways, service DNS, and certificates that make services reachable and secure. \nService Data & Configuration: the application data stores, configuration, and secrets that each service depends on. \nEnvironment Promotion: the promotion path that moves a change safely from lower environments to production. \nAI & Internal Tooling: the AI tooling across the development lifecycle that speeds service onboarding, pipeline authoring, and day-to-day delivery. \nKey responsibilities:\nPeople Leadership & Team Development\nLeads, develops, and retains a team of DevOps Engineers building the developer platform, cultivating a high-performance culture defined by technical excellence, an automation mindset, and operational ownership. \nSets clear goals, role expectations, and success criteria for each engineer; conducts regular 1:1s and gives direct, constructive feedback with a visible path for growth. \nConducts structured performance reviews that recognize strong delivery contributions, address quality or reliability gaps specifically, and grow both AI fluency and platform-engineering depth. \nIdentifies capability gaps across the team, encompassing CI/CD, service-layer Terraform, container orchestration and EKS, API and connectivity patterns, and AI-assisted operations, while building targeted hiring, upskilling, and cross-training plans. \nFosters a culture where every manual process is a temporary state, automation is the permanent solution, and AI tooling is an expected part of how each engineer works. \nSupports Engineering hiring across the organization by participating in technical interviews and helping calibrate the platform-engineering bar. \nDeveloper Platform & Delivery Operations\nOwns the end-to-end path from “we are building a service” to “it deploys to production on its own pipeline”, repository scaffolding, ECR, Terraform workspace, pipeline, variable groups, secrets paths, hostname, gateway wiring, and alarms, reducing the elapsed time and ownership ambiguity in new-service onboarding. \nLeads the team's service-layer infrastructure-as-code practice, ensuring IaC stacks are defined, versioned, peer-reviewed, and deployed through Terraform on S3 and DynamoDB backends, with manual changes treated as exceptions to be immediately codified. \nOversees the shared pipeline templates consumed org-wide, enforcing the additive-only change policy so new parameters carry safe defaults and template changes never break existing consumers. \nSets and enforces the naming and structural standards the delivery path depends on, ECR repositories, variable groups, Kubernetes ServiceAccounts, secret paths, and private hostnames, because they are what make onboarding repeatable. \nDrives service-level cost efficiency as a continuous discipline, right-sizing service stacks, OpenSearch Serverless OCU caps, ECR lifecycle policies, and idle-stack cleanup. \nOperates within the Cloud Infrastructure team's landing zone, guardrails, and shared platforms rather than owning them, keeping clean boundaries between service delivery and the estate. \nPipelines, Build & Release Support\nOwns the per-service Azure DevOps build and deploy pipelines, build, test, scan, containerize, push, deploy, and the environment gates between them, as the team's highest-volume recurring duty. \nHolds the team accountable for container image discipline, immutable tags and distinct hotfix tags, ECR repository definitions, and lifecycle policies, so a redeploy can never silently pull a different image. \nOwns the environment promotion model, feature branch to main, one pipeline per repository gated per environment, and immutable-tag promotion with roll-forward by default, across the full environment ladder. \nBuilds the CI/CD pipelines the Release team runs, and trains and supports that team to operate them, how a promotion is gated, how to approve or retry a stage, how to read a failure, and when to escalate back to DevOps versus the service owner. \nCoaches Engineers to diagnose and eliminate the root causes of flaky, intermittent delivery failures rather than treating them as acceptable operational noise. \nService IaC & Container Platform\nOversees the EKS platform layer, add-ons, workload identity through Pod Identity and IRSA, namespaces, NetworkPolicies, and the golden-path add-ons, and multi-environment service onboarding. \nOwns the golden path, the zero-touch onboarding path for services, the shared token-gateway authorizer, and Helm support, so a new feature/capability needs no bespoke infrastructure work. \nOversees deployment automation for containerized services, Lambda functions, ECS tasks, and EKS workloads, ensuring patterns are consistent, traceable, and recoverable across environments. \nOwns application connectivity, API Gateway in REST and HTTP forms and public and private, Lambda authorizers, per-service DNS records and ACM certificates inside delegated zones, and ExternalDNS, along with end-to-end debugging of gateway-path failures. \nProvisions the service data stores that belong to a stack, application S3, SSM configuration, Secrets Manager entries, and Aurora/RDS with DDL and Flyway pipelines, handing ongoing database operations to the Database team. \nAI-Augmented DevOps Operations\nDrives adoption of AI development tools, including Claude Code and Cursor, across the team's daily workflow, establishing norms for AI-assisted IaC authoring, pipeline authoring, automation scripting, and operational documentation. \nBuilds and operates internal AI tooling across the software development lifecycle, intake, design, implementation, review, CI/CD, and operations, so product and engineering teams can move faster. \nChampions AI-assisted operations as a management discipline, integrating AI-powered log analysis, anomaly detection, runbook generation, and LLM-augmented incident analysis into workflows that reduce mean time to diagnosis. \nUses AI to accelerate the team's most demanding work, service onboarding, Terraform scaffolding, pipeline authoring, and operational diagnosis, and shares effective patterns with engineering leadership. \nHolds team members accountable for AI tool adoption and proficiency, incorporating AI fluency into performance conversations, development plans, and hiring criteria. \nService Observability & Incident Response\nLeads the team's ownership of service observability wiring, CloudWatch log groups, metrics, and traces defined in each service's Terraform, with retention and high-volume log control at the service level, and confirms a new or promoted service emits telemetry before it is handed to SRE. \nKeeps clean boundaries with the observability platforms themselves, New Relic, Datadog, Sumo Logic, and Langfuse, which Cloud Infrastructure operates, and with monitor, alert, and dashboard design, which SRE owns, positioning the team as the integration point rather than the on-call owner of those views. \nOwns the team's response to delivery-path and service-stack incidents, failed deploys, gateway and connectivity faults, image and task-definition problems, and environment configuration drift, and establishes quickly when an incident is not the team's and hands off with evidence. \nLeads blameless post-incident reviews, produces structured root cause analyses, and owns follow-through on corrective actions that prevent recurrence. \nTracks delivery reliability metrics, deployment frequency, change failure rate, lead time, and mean time to recovery for the delivery path, reporting trends and improvement actions to the Director of DevOps. \nSecurity, Compliance & Access Management\nHolds the team accountable for the security controls it owns within the delivery path, workload IAM roles scoped to a single service stack, secret paths, container image scanning, and network-policy enforcement, operating within the guardrails, SCPs, and permission boundaries Cloud Infrastructure sets. \nPartners with Application Security Engineers to integrate infrastructure-level controls, container scanning, secrets management, and network-policy enforcement, into the automation workflows the team owns. \nEnsures pipeline and platform access is timely, least-privilege, regularly reviewed, and audit-ready, service connections, OIDC role mappings, and repository and pipeline permissions. \nSupports audit readiness and evidence collection for SOC 2, ISO/IEC 27001, and NIST 800-53, maintaining accurate records of pipeline configurations, access grants, and change history for the systems the team owns. \nCross-Functional Collaboration & Stakeholder Management\nServes as the primary delivery partner to Engineering and capability teams, providing platform consultation during system design and ensuring services are operationally sound and reliably deployable. \nCollaborates with the Release and Engineering Systems teams on pipeline governance, release planning, and deployment coordination, ensuring the delivery path is validated and ready before promotion. \nPartners with the Cloud Infrastructure team on the shared boundaries between service delivery and the landing zone, the delivery toolchain, EKS placement, IAM roles, and application DNS and secrets, keep...","description_format":"text","description_chars":18383,"description_truncated":true,"requirements":{"experience_years_min":2,"management_years_min":2,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":["Education assistance","Flexible time off","Life insurance","Parental leave","Vision insurance"],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[{"name":"United Kingdom","iso":"GB"}],"relocation_offered":false,"industries":["Financial Services","Health Care","InsurTech"],"lifecycle":[{"event":"open","at":"2026-09-30T00:05:15Z"}],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":1,"expected_fill_days":31,"reasons":["conf:19","velocity","win:early"],"computed_at":"2026-10-01T05:45:00Z"},"pay":{"stated_usd_annual":185000,"is_top_pay":true},"html_url":"https://alion.io/job/origami-risk-llc-devops-manager-platform","json_url":"https://alion.io/job/origami-risk-llc-devops-manager-platform.json","meta":{"generated_at":"2026-10-02T00:56:39Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2594,"day_limit":5000,"remaining_today":2406,"minute_limit":60,"resets_at":"2026-10-03T00:00:00Z"}}}