Staff Engineer I, DevOps Engineering​

Bain & CompanyGeneral Information Job Title Staff Engineer I, DevOps Engineering​ Job ID 109089 Work Areas Technology & Engineering Employment Type Permanent Full-Time Location(s) Mexico City, New Delhi, Warsaw Description & Requirements WHAT MAKES US A GREAT PLACE TO WORKWe are proud to be consistently recognized as one of the world’s best places to work. We are currently the top ranked consulting firm on Glassdoor’s Best Places to Work list and have earned the #1 overall spot a record seven times. Extraordinary teams are at the heart of our business strategy, but these don’t happen by chance. They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment. We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally.WHO YOU’LL WORK WITHCoro is Bain's persistent product development and engineering organization, building and operating the firm's proprietary digital solutions. Coro brings together technology, data, and services to create differentiated value for Bain's clients and case teams.This role sits within Coro's DevOps and Assurance team, part of the Next Generation Software Solutions (NGSS) department. The team enables secure, efficient, and reliable delivery of technology across Bain's global ecosystem, focusing on both technical operations and platform assurance so that every deployment meets the firm's standards for quality, security, and compliance.WHERE YOU’LL FIT WITHIN THE TEAM The Staff Engineer owns the design, architecture, and long-term direction of cloud infrastructure and software delivery across Coro's DevOps and Assurance team. Working alongside architects and backend engineers, this engineer sets the technical standard for how the team provisions infrastructure, ships software, and secures its platforms, and ensures those platforms scale as the build plan expands.This is a critical foundational role in the early stages of the platform build, requiring both strong technical fundamentals and the pragmatism to make infrastructure decisions that support a fast-moving product team.WHAT YOU’LL DO Infrastructure Architecture & Automation – 30%Own the design and evolution of cloud infrastructure built on Terraform and Terraform Cloud. Define the module structure, state strategy, and remote backend conventions the rest of the team builds against.Architect Azure networking end to end: VNet/subnet topology, private endpoints, DNS resolution, NSG design, and Front Door Premium configuration across dev, demo, and production.Set the standard for provisioning Azure platform services (App Services, Azure SQL, Azure OpenAI, Container Registry (e.g. Azure Container Registry, Cloudsmith), Key Vault, Entra ID, Storage Accounts / ADLS Gen2) and ensure environment parity by design.Own the automation roadmap for the team: identify manual, repetitive operational work, own the backlog of it, and drive it toward self-service and infrastructure-as-code so operational load trends down over time.Partner with Bain's central cloud and infrastructure teams to shape shared processes, tooling, and standards for operational work.Cloud & Platform Management (Azure) – 20%Own Azure Kubernetes Service (AKS) architecture, including node pools, scaling strategy, spot instance usage, and workload connectivity to dependent services (databases, storage, AI services).Define identity and access architecture: Entra ID app registrations, managed identities, RBAC model, and integration with external IdPs (Okta).Set infrastructure standards for database platforms (Azure SQL Serverless, PostgreSQL Flexible Server, Cosmos DB), including connectivity, Entra auth, firewall rules, and private endpoints.Ensure platform reliability and robust access controls across all environments, and act as the senior escalation point for platform-level issues.CI/CD & Software Delivery – 15%Define and own the CI/CD strategy using GitHub Actions for container builds, infrastructure deployments, and application releases, setting the patterns other engineers extend.Establish the container image lifecycle standard: build, scan, push to a container registry (e.g. Azure Container Registry, Cloudsmith), and deploy to AKS or App Services.Design environment promotion workflows with appropriate gating, secrets management (Key Vault), and rollback strategies.Architect and operate GitHub-hosted private runners where required, including network integration with Azure VNets.Monitoring, Security & Assurance – 15%Own the observability strategy using the team's monitoring stack (e.g. Datadog, Azure Application Insights). Define what the team monitors, alerts on, and how it optimizes cost and reliability.Lead the response to security findings: triage, containment, IAM scoping, container image CVE remediation, and endpoint hardening, and set the remediation standards others follow.Lead L2/L3 incident escalations, including root-cause analysis, user journey tracing, and log analysis, and drive the improvements that prevent recurrence.Define and enforce solution compliance across products: network isolation, least-privilege access, secrets hygiene, and deployment guardrails.Own the developer experience: set the standard for local development environments and deployment documentation so engineers across the distributed team can onboard quickly and operate with minimal infrastructure friction.Technical Leadership & Team Development – 20%Lead and mentor DevOps engineers: set technical direction, review designs, grow the team's depth, and raise the bar on engineering practice.Anticipate the needs of stakeholders across NGSS and the wider business, and shape the platform roadmap proactively rather than reactively.Partner with architects, product engineers, and security teams to align on infrastructure standards and shape platform roadmaps across NGSS.Drive DevOps culture and automation-first thinking across the engineering organization, and lead knowledge sharing.Contribute to and often lead technical discovery, POCs, and innovation workstreams to validate new tools, technologies, and architectural patterns.ABOUT YOUEducation & ExperienceBachelor's or Master's degree in Computer Science, Engineering, or a related technical field.7–9 years of experience in DevOps, infrastructure engineering, or cloud platform engineering, with time spent at a senior or staff level.Proven track record of architecting and operating cloud infrastructure in production at scale, owning technical decisions end to end.Demonstrated experience leading and mentoring DevOps or platform engineers in fast-paced product organizations.Professional Skills & MindsetExcellent communication and collaboration skills, with the ability to translate complex technical topics for diverse stakeholders and to set direction others can follow.Proactive, analytical, and systematic, with strong problem-solving skills and the ability to trace issues across multiple layers (DNS, networking, identity, application).Results-driven with a strong bias for automation and continuous improvement, and a track record of driving operational load down over time.Comfortable owning ambiguity and working with limited direction: able to define standards and roadmaps where none exist yet, and to manage multiple stakeholders independently.Familiarity with Agile methodologies and a genuine commitment to team enablement and growth.Technical ExpertiseDeep hands-on expertise with Terraform and Terraform Cloud (or equivalent): module design, state strategy, and remote backends at scale.Strong mastery of Azure services, including AKS, Networking (VNets, subnets, private endpoints, NSGs, DNS zones), App Services, Key Vault, Container Registry, and Storage Accounts.Deep experience with containerization technologies (Docker, Kubernetes) and container image lifecycle management.Expertise in roles, permissions, and IAM, particularly Microsoft Entra ID and Okta.Advanced CI/CD automation using GitHub Actions, Azure DevOps, and related DevOps toolchains, with the ability to define patterns for a team.Proficient in Linux administration and automation scripting (Bash, PowerShell, Python) for reusable workflows.Strong command of monitoring and observability platforms (e.g. Datadog, Azure Application Insights).Deep familiarity with Azure private networking: private endpoints (blob, DFS, SQL, PostgreSQL), Private DNS Zones, and VNet integration for App Services and AKS.Command of database deployment and management from an infrastructure perspective, Azure SQL Serverless, PostgreSQL Flexible Server, and Cosmos DB.Strong foundation in security remediation: container CVE patching, IAM scoping, NSG/firewall tightening, and WAF/Front Door rule management.Preferred QualificationsProfessional certifications such as Azure DevOps Engineer Expert, Azure Administrator, Terraform Associate, or CKA (or equivalent).Experience owning multi-environment governance, cost optimization (FinOps), and compliance frameworks in cloud environments.Familiarity with Azure OpenAI, Cognitive Search, Databricks, and the integration of AI services into enterprise platforms.Experience with workflow orchestration tools (Airflow, or similar DAG/pipeline systems).Snowflake administration or connectivity from a DevOps lens.Experience with AI/ML observability tools such as LangSmith or Arize.Familiarity with AI coding assistants such as Cursor, Claude Code, or Codex to speed up development. Go back Apply Share this job: LinkedIn X EmailRemotefull timeStaff
Active

Job description

General Information Job Title Staff Engineer I, DevOps Engineering​ Job ID 109089 Work Areas Technology & Engineering Employment Type Permanent Full-Time Location(s) Mexico City, New Delhi, Warsaw Description & Requirements WHAT MAKES US A GREAT PLACE TO WORKWe are proud to be consistently recognized as one of the world’s best places to work. We are currently the top ranked consulting firm on Glassdoor’s Best Places to Work list and have earned the #1 overall spot a record seven times. Extraordinary teams are at the heart of our business strategy, but these don’t happen by chance. They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment. We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally.WHO YOU’LL WORK WITHCoro is Bain's persistent product development and engineering organization, building and operating the firm's proprietary digital solutions. Coro brings together technology, data, and services to create differentiated value for Bain's clients and case teams.This role sits within Coro's DevOps and Assurance team, part of the Next Generation Software Solutions (NGSS) department. The team enables secure, efficient, and reliable delivery of technology across Bain's global ecosystem, focusing on both technical operations and platform assurance so that every deployment meets the firm's standards for quality, security, and compliance.WHERE YOU’LL FIT WITHIN THE TEAM The Staff Engineer owns the design, architecture, and long-term direction of cloud infrastructure and software delivery across Coro's DevOps and Assurance team. Working alongside architects and backend engineers, this engineer sets the technical standard for how the team provisions infrastructure, ships software, and secures its platforms, and ensures those platforms scale as the build plan expands.This is a critical foundational role in the early stages of the platform build, requiring both strong technical fundamentals and the pragmatism to make infrastructure decisions that support a fast-moving product team.WHAT YOU’LL DO Infrastructure Architecture & Automation – 30%Own the design and evolution of cloud infrastructure built on Terraform and Terraform Cloud. Define the module structure, state strategy, and remote backend conventions the rest of the team builds against.Architect Azure networking end to end: VNet/subnet topology, private endpoints, DNS resolution, NSG design, and Front Door Premium configuration across dev, demo, and production.Set the standard for provisioning Azure platform services (App Services, Azure SQL, Azure OpenAI, Container Registry (e.g. Azure Container Registry, Cloudsmith), Key Vault, Entra ID, Storage Accounts / ADLS Gen2) and ensure environment parity by design.Own the automation roadmap for the team: identify manual, repetitive operational work, own the backlog of it, and drive it toward self-service and infrastructure-as-code so operational load trends down over time.Partner with Bain's central cloud and infrastructure teams to shape shared processes, tooling, and standards for operational work.Cloud & Platform Management (Azure) – 20%Own Azure Kubernetes Service (AKS) architecture, including node pools, scaling strategy, spot instance usage, and workload connectivity to dependent services (databases, storage, AI services).Define identity and access architecture: Entra ID app registrations, managed identities, RBAC model, and integration with external IdPs (Okta).Set infrastructure standards for database platforms (Azure SQL Serverless, PostgreSQL Flexible Server, Cosmos DB), including connectivity, Entra auth, firewall rules, and private endpoints.Ensure platform reliability and robust access controls across all environments, and act as the senior escalation point for platform-level issues.CI/CD & Software Delivery – 15%Define and own the CI/CD strategy using GitHub Actions for container builds, infrastructure deployments, and application releases, setting the patterns other engineers extend.Establish the container image lifecycle standard: build, scan, push to a container registry (e.g. Azure Container Registry, Cloudsmith), and deploy to AKS or App Services.Design environment promotion workflows with appropriate gating, secrets management (Key Vault), and rollback strategies.Architect and operate GitHub-hosted private runners where required, including network integration with Azure VNets.Monitoring, Security & Assurance – 15%Own the observability strategy using the team's monitoring stack (e.g. Datadog, Azure Application Insights). Define what the team monitors, alerts on, and how it optimizes cost and reliability.Lead the response to security findings: triage, containment, IAM scoping, container image CVE remediation, and endpoint hardening, and set the remediation standards others follow.Lead L2/L3 incident escalations, including root-cause analysis, user journey tracing, and log analysis, and drive the improvements that prevent recurrence.Define and enforce solution compliance across products: network isolation, least-privilege access, secrets hygiene, and deployment guardrails.Own the developer experience: set the standard for local development environments and deployment documentation so engineers across the distributed team can onboard quickly and operate with minimal infrastructure friction.Technical Leadership & Team Development – 20%Lead and mentor DevOps engineers: set technical direction, review designs, grow the team's depth, and raise the bar on engineering practice.Anticipate the needs of stakeholders across NGSS and the wider business, and shape the platform roadmap proactively rather than reactively.Partner with architects, product engineers, and security teams to align on infrastructure standards and shape platform roadmaps across NGSS.Drive DevOps culture and automation-first thinking across the engineering organization, and lead knowledge sharing.Contribute to and often lead technical discovery, POCs, and innovation workstreams to validate new tools, technologies, and architectural patterns.ABOUT YOUEducation & ExperienceBachelor's or Master's degree in Computer Science, Engineering, or a related technical field.7–9 years of experience in DevOps, infrastructure engineering, or cloud platform engineering, with time spent at a senior or staff level.Proven track record of architecting and operating cloud infrastructure in production at scale, owning technical decisions end to end.Demonstrated experience leading and mentoring DevOps or platform engineers in fast-paced product organizations.Professional Skills & MindsetExcellent communication and collaboration skills, with the ability to translate complex technical topics for diverse stakeholders and to set direction others can follow.Proactive, analytical, and systematic, with strong problem-solving skills and the ability to trace issues across multiple layers (DNS, networking, identity, application).Results-driven with a strong bias for automation and continuous improvement, and a track record of driving operational load down over time.Comfortable owning ambiguity and working with limited direction: able to define standards and roadmaps where none exist yet, and to manage multiple stakeholders independently.Familiarity with Agile methodologies and a genuine commitment to team enablement and growth.Technical ExpertiseDeep hands-on expertise with Terraform and Terraform Cloud (or equivalent): module design, state strategy, and remote backends at scale.Strong mastery of Azure services, including AKS, Networking (VNets, subnets, private endpoints, NSGs, DNS zones), App Services, Key Vault, Container Registry, and Storage Accounts.Deep experience with containerization technologies (Docker, Kubernetes) and container image lifecycle management.Expertise in roles, permissions, and IAM, particularly Microsoft Entra ID and Okta.Advanced CI/CD automation using GitHub Actions, Azure DevOps, and related DevOps toolchains, with the ability to define patterns for a team.Proficient in Linux administration and automation scripting (Bash, PowerShell, Python) for reusable workflows.Strong command of monitoring and observability platforms (e.g. Datadog, Azure Application Insights).Deep familiarity with Azure private networking: private endpoints (blob, DFS, SQL, PostgreSQL), Private DNS Zones, and VNet integration for App Services and AKS.Command of database deployment and management from an infrastructure perspective, Azure SQL Serverless, PostgreSQL Flexible Server, and Cosmos DB.Strong foundation in security remediation: container CVE patching, IAM scoping, NSG/firewall tightening, and WAF/Front Door rule management.Preferred QualificationsProfessional certifications such as Azure DevOps Engineer Expert, Azure Administrator, Terraform Associate, or CKA (or equivalent).Experience owning multi-environment governance, cost optimization (FinOps), and compliance frameworks in cloud environments.Familiarity with Azure OpenAI, Cognitive Search, Databricks, and the integration of AI services into enterprise platforms.Experience with workflow orchestration tools (Airflow, or similar DAG/pipeline systems).Snowflake administration or connectivity from a DevOps lens.Experience with AI/ML observability tools such as LangSmith or Arize.Familiarity with AI coding assistants such as Cursor, Claude Code, or Codex to speed up development. Go backGeneral Information Job Title Staff Engineer I, DevOps Engineering​ Job ID 109089 Work Areas Technology & Engineering Employment Type Permanent Full-Time Location(s) Mexico City, New Delhi, Warsaw Description & Requirements WHAT MAKES US A GREAT PLACE TO WORKWe are proud to be consistently recognized as one of the world’s best places to work. We are currently the top ranked consulting firm on Glassdoor’s Best Places to Work list and have earned the #1 overall spot a record seven times. Extraordinary teams are at the heart of our business strategy, but these don’t happen by chance. They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment. We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally.WHO YOU’LL WORK WITHCoro is Bain's persistent product development and engineering organization, building and operating the firm's proprietary digital solutions. Coro brings together technology, data, and services to create differentiated value for Bain's clients and case teams.This role sits within Coro's DevOps and Assurance team, part of the Next Generation Software Solutions (NGSS) department. The team enables secure, efficient, and reliable delivery of technology across Bain's global ecosystem, focusing on both technical operations and platform assurance so that every deployment meets the firm's standards for quality, security, and compliance.WHERE YOU’LL FIT WITHIN THE TEAM The Staff Engineer owns the design, architecture, and long-term direction of cloud infrastructure and software delivery across Coro's DevOps and Assurance team. Working alongside architects and backend engineers, this engineer sets the technical standard for how the team provisions infrastructure, ships software, and secures its platforms, and ensures those platforms scale as the build plan expands.This is a critical foundational role in the early stages of the platform build, requiring both strong technical fundamentals and the pragmatism to make infrastructure decisions that support a fast-moving product team.WHAT YOU’LL DO Infrastructure Architecture & Automation – 30%Own the design and evolution of cloud infrastructure built on Terraform and Terraform Cloud. Define the module structure, state strategy, and remote backend conventions the rest of the team builds against.Architect Azure networking end to end: VNet/subnet topology, private endpoints, DNS resolution, NSG design, and Front Door Premium configuration across dev, demo, and production.Set the standard for provisioning Azure platform services (App Services, Azure SQL, Azure OpenAI, Container Registry (e.g. Azure Container Registry, Cloudsmith), Key Vault, Entra ID, Storage Accounts / ADLS Gen2) and ensure environment parity by design.Own the automation roadmap for the team: identify manual, repetitive operational work, own the backlog of it, and drive it toward self-service and infrastructure-as-code so operational load trends down over time.Partner with Bain's central cloud and infrastructure teams to shape shared processes, tooling, and standards for operational work.Cloud & Platform Management (Azure) – 20%Own Azure Kubernetes Service (AKS) architecture, including node pools, scaling strategy, spot instance usage, and workload connectivity to dependent services (databases, storage, AI services).Define identity and access architecture: Entra ID app registrations, managed identities, RBAC model, and integration with external IdPs (Okta).Set infrastructure standards for database platforms (Azure SQL Serverless, PostgreSQL Flexible Server, Cosmos DB), including connectivity, Entra auth, firewall rules, and private endpoints.Ensure platform reliability and robust access controls across all environments, and act as the senior escalation point for platform-level issues.CI/CD & Software Delivery – 15%Define and own the CI/CD strategy using GitHub Actions for container builds, infrastructure deployments, and application releases, setting the patterns other engineers extend.Establish the container image lifecycle standard: build, scan, push to a container registry (e.g. Azure Container Registry, Cloudsmith), and deploy to AKS or App Services.Design environment promotion workflows with appropriate gating, secrets management (Key Vault), and rollback strategies.Architect and operate GitHub-hosted private runners where required, including network integration with Azure VNets.Monitoring, Security & Assurance – 15%Own the observability strategy using the team's monitoring stack (e.g. Datadog, Azure Application Insights). Define what the team monitors, alerts on, and how it optimizes cost and reliability.Lead the response to security findings: triage, containment, IAM scoping, container image CVE remediation, and endpoint hardening, and set the remediation standards others follow.Lead L2/L3 incident escalations, including root-cause analysis, user journey tracing, and log analysis, and drive the improvements that prevent recurrence.Define and enforce solution compliance across products: network isolation, least-privilege access, secrets hygiene, and deployment guardrails.Own the developer experience: set the standard for local development environments and deployment documentation so engineers across the distributed team can onboard quickly and operate with minimal infrastructure friction.Technical Leadership & Team Development – 20%Lead and mentor DevOps engineers: set technical direction, review designs, grow the team's depth, and raise the bar on engineering practice.Anticipate the needs of stakeholders across NGSS and the wider business, and shape the platform roadmap proactively rather than reactively.Partner with architects, product engineers, and security teams to align on infrastructure standards and shape platform roadmaps across NGSS.Drive DevOps culture and automation-first thinking across the engineering organization, and lead knowledge sharing.Contribute to and often lead technical discovery, POCs, and innovation workstreams to validate new tools, technologies, and architectural patterns.ABOUT YOUEducation & ExperienceBachelor's or Master's degree in Computer Science, Engineering, or a related technical field.7–9 years of experience in DevOps, infrastructure engineering, or cloud platform engineering, with time spent at a senior or staff level.Proven track record of architecting and operating cloud infrastructure in production at scale, owning technical decisions end to end.Demonstrated experience leading and mentoring DevOps or platform engineers in fast-paced product organizations.Professional Skills & MindsetExcellent communication and collaboration skills, with the ability to translate complex technical topics for diverse stakeholders and to set direction others can follow.Proactive, analytical, and systematic, with strong problem-solving skills and the ability to trace issues across multiple layers (DNS, networking, identity, application).Results-driven with a strong bias for automation and continuous improvement, and a track record of driving operational load down over time.Comfortable owning ambiguity and working with limited direction: able to define standards and roadmaps where none exist yet, and to manage multiple stakeholders independently.Familiarity with Agile methodologies and a genuine commitment to team enablement and growth.Technical ExpertiseDeep hands-on expertise with Terraform and Terraform Cloud (or equivalent): module design, state strategy, and remote backends at scale.Strong mastery of Azure services, including AKS, Networking (VNets, subnets, private endpoints, NSGs, DNS zones), App Services, Key Vault, Container Registry, and Storage Accounts.Deep experience with containerization technologies (Docker, Kubernetes) and container image lifecycle management.Expertise in roles, permissions, and IAM, particularly Microsoft Entra ID and Okta.Advanced CI/CD automation using GitHub Actions, Azure DevOps, and related DevOps toolchains, with the ability to define patterns for a team.Proficient in Linux administration and automation scripting (Bash, PowerShell, Python) for reusable workflows.Strong command of monitoring and observability platforms (e.g. Datadog, Azure Application Insights).Deep familiarity with Azure private networking: private endpoints (blob, DFS, SQL, PostgreSQL), Private DNS Zones, and VNet integration for App Services and AKS.Command of database deployment and management from an infrastructure perspective, Azure SQL Serverless, PostgreSQL Flexible Server, and Cosmos DB.Strong foundation in security remediation: container CVE patching, IAM scoping, NSG/firewall tightening, and WAF/Front Door rule management.Preferred QualificationsProfessional certifications such as Azure DevOps Engineer Expert, Azure Administrator, Terraform Associate, or CKA (or equivalent).Experience owning multi-environment governance, cost optimization (FinOps), and compliance frameworks in cloud environments.Familiarity with Azure OpenAI, Cognitive Search, Databricks, and the integration of AI services into enterprise platforms.Experience with workflow orchestration tools (Airflow, or similar DAG/pipeline systems).Snowflake administration or connectivity from a DevOps lens.Experience with AI/ML observability tools such as LangSmith or Arize.Familiarity with AI coding assistants such as Cursor, Claude Code, or Codex to speed up development.General InformationGeneral Information

General Information

Job Title Staff Engineer I, DevOps Engineering​ Job ID 109089 Work Areas Technology & Engineering Employment Type Permanent Full-Time Location(s) Mexico City, New Delhi, WarsawJob Title Staff Engineer I, DevOps Engineering​ Job ID 109089 Work Areas Technology & Engineering Employment Type Permanent Full-Time Location(s) Mexico City, New Delhi, WarsawJob Title Staff Engineer I, DevOps Engineering​Job TitleStaff Engineer I, DevOps Engineering​Job ID 109089Job ID109089Work Areas Technology & EngineeringWork AreasTechnology & EngineeringEmployment Type Permanent Full-TimeEmployment TypePermanent Full-TimeLocation(s) Mexico City, New Delhi, WarsawLocation(s)Mexico City, New Delhi, WarsawDescription & RequirementsDescription & Requirements

Description & Requirements

WHAT MAKES US A GREAT PLACE TO WORKWe are proud to be consistently recognized as one of the world’s best places to work. We are currently the top ranked consulting firm on Glassdoor’s Best Places to Work list and have earned the #1 overall spot a record seven times. Extraordinary teams are at the heart of our business strategy, but these don’t happen by chance. They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment. We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally.WHO YOU’LL WORK WITHCoro is Bain's persistent product development and engineering organization, building and operating the firm's proprietary digital solutions. Coro brings together technology, data, and services to create differentiated value for Bain's clients and case teams.This role sits within Coro's DevOps and Assurance team, part of the Next Generation Software Solutions (NGSS) department. The team enables secure, efficient, and reliable delivery of technology across Bain's global ecosystem, focusing on both technical operations and platform assurance so that every deployment meets the firm's standards for quality, security, and compliance.WHERE YOU’LL FIT WITHIN THE TEAM The Staff Engineer owns the design, architecture, and long-term direction of cloud infrastructure and software delivery across Coro's DevOps and Assurance team. Working alongside architects and backend engineers, this engineer sets the technical standard for how the team provisions infrastructure, ships software, and secures its platforms, and ensures those platforms scale as the build plan expands.This is a critical foundational role in the early stages of the platform build, requiring both strong technical fundamentals and the pragmatism to make infrastructure decisions that support a fast-moving product team.WHAT YOU’LL DO Infrastructure Architecture & Automation – 30%Own the design and evolution of cloud infrastructure built on Terraform and Terraform Cloud. Define the module structure, state strategy, and remote backend conventions the rest of the team builds against.Architect Azure networking end to end: VNet/subnet topology, private endpoints, DNS resolution, NSG design, and Front Door Premium configuration across dev, demo, and production.Set the standard for provisioning Azure platform services (App Services, Azure SQL, Azure OpenAI, Container Registry (e.g. Azure Container Registry, Cloudsmith), Key Vault, Entra ID, Storage Accounts / ADLS Gen2) and ensure environment parity by design.Own the automation roadmap for the team: identify manual, repetitive operational work, own the backlog of it, and drive it toward self-service and infrastructure-as-code so operational load trends down over time.Partner with Bain's central cloud and infrastructure teams to shape shared processes, tooling, and standards for operational work.Cloud & Platform Management (Azure) – 20%Own Azure Kubernetes Service (AKS) architecture, including node pools, scaling strategy, spot instance usage, and workload connectivity to dependent services (databases, storage, AI services).Define identity and access architecture: Entra ID app registrations, managed identities, RBAC model, and integration with external IdPs (Okta).Set infrastructure standards for database platforms (Azure SQL Serverless, PostgreSQL Flexible Server, Cosmos DB), including connectivity, Entra auth, firewall rules, and private endpoints.Ensure platform reliability and robust access controls across all environments, and act as the senior escalation point for platform-level issues.CI/CD & Software Delivery – 15%Define and own the CI/CD strategy using GitHub Actions for container builds, infrastructure deployments, and application releases, setting the patterns other engineers extend.Establish the container image lifecycle standard: build, scan, push to a container registry (e.g. Azure Container Registry, Cloudsmith), and deploy to AKS or App Services.Design environment promotion workflows with appropriate gating, secrets management (Key Vault), and rollback strategies.Architect and operate GitHub-hosted private runners where required, including network integration with Azure VNets.Monitoring, Security & Assurance – 15%Own the observability strategy using the team's monitoring stack (e.g. Datadog, Azure Application Insights). Define what the team monitors, alerts on, and how it optimizes cost and reliability.Lead the response to security findings: triage, containment, IAM scoping, container image CVE remediation, and endpoint hardening, and set the remediation standards others follow.Lead L2/L3 incident escalations, including root-cause analysis, user journey tracing, and log analysis, and drive the improvements that prevent recurrence.Define and enforce solution compliance across products: network isolation, least-privilege access, secrets hygiene, and deployment guardrails.Own the developer experience: set the standard for local development environments and deployment documentation so engineers across the distributed team can onboard quickly and operate with minimal infrastructure friction.Technical Leadership & Team Development – 20%Lead and mentor DevOps engineers: set technical direction, review designs, grow the team's depth, and raise the bar on engineering practice.Anticipate the needs of stakeholders across NGSS and the wider business, and shape the platform roadmap proactively rather than reactively.Partner with architects, product engineers, and security teams to align on infrastructure standards and shape platform roadmaps across NGSS.Drive DevOps culture and automation-first thinking across the engineering organization, and lead knowledge sharing.Contribute to and often lead technical discovery, POCs, and innovation workstreams to validate new tools, technologies, and architectural patterns.ABOUT YOUEducation & ExperienceBachelor's or Master's degree in Computer Science, Engineering, or a related technical field.7–9 years of experience in DevOps, infrastructure engineering, or cloud platform engineering, with time spent at a senior or staff level.Proven track record of architecting and operating cloud infrastructure in production at scale, owning technical decisions end to end.Demonstrated experience leading and mentoring DevOps or platform engineers in fast-paced product organizations.Professional Skills & MindsetExcellent communication and collaboration skills, with the ability to translate complex technical topics for diverse stakeholders and to set direction others can follow.Proactive, analytical, and systematic, with strong problem-solving skills and the ability to trace issues across multiple layers (DNS, networking, identity, application).Results-driven with a strong bias for automation and continuous improvement, and a track record of driving operational load down over time.Comfortable owning ambiguity and working with limited direction: able to define standards and roadmaps where none exist yet, and to manage multiple stakeholders independently.Familiarity with Agile methodologies and a genuine commitment to team enablement and growth.Technical ExpertiseDeep hands-on expertise with Terraform and Terraform Cloud (or equivalent): module design, state strategy, and remote backends at scale.Strong mastery of Azure services, including AKS, Networking (VNets, subnets, private endpoints, NSGs, DNS zones), App Services, Key Vault, Container Registry, and Storage Accounts.Deep experience with containerization technologies (Docker, Kubernetes) and container image lifecycle management.Expertise in roles, permissions, and IAM, particularly Microsoft Entra ID and Okta.Advanced CI/CD automation using GitHub Actions, Azure DevOps, and related DevOps toolchains, with the ability to define patterns for a team.Proficient in Linux administration and automation scripting (Bash, PowerShell, Python) for reusable workflows.Strong command of monitoring and observability platforms (e.g. Datadog, Azure Application Insights).Deep familiarity with Azure private networking: private endpoints (blob, DFS, SQL, PostgreSQL), Private DNS Zones, and VNet integration for App Services and AKS.Command of database deployment and management from an infrastructure perspective, Azure SQL Serverless, PostgreSQL Flexible Server, and Cosmos DB.Strong foundation in security remediation: container CVE patching, IAM scoping, NSG/firewall tightening, and WAF/Front Door rule management.Preferred QualificationsProfessional certifications such as Azure DevOps Engineer Expert, Azure Administrator, Terraform Associate, or CKA (or equivalent).Experience owning multi-environment governance, cost optimization (FinOps), and compliance frameworks in cloud environments.Familiarity with Azure OpenAI, Cognitive Search, Databricks, and the integration of AI services into enterprise platforms.Experience with workflow orchestration tools (Airflow, or similar DAG/pipeline systems).Snowflake administration or connectivity from a DevOps lens.Experience with AI/ML observability tools such as LangSmith or Arize.Familiarity with AI coding assistants such as Cursor, Claude Code, or Codex to speed up development.WHAT MAKES US A GREAT PLACE TO WORKWe are proud to be consistently recognized as one of the world’s best places to work. We are currently the top ranked consulting firm on Glassdoor’s Best Places to Work list and have earned the #1 overall spot a record seven times. Extraordinary teams are at the heart of our business strategy, but these don’t happen by chance. They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment. We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally.WHO YOU’LL WORK WITHCoro is Bain's persistent product development and engineering organization, building and operating the firm's proprietary digital solutions. Coro brings together technology, data, and services to create differentiated value for Bain's clients and case teams.This role sits within Coro's DevOps and Assurance team, part of the Next Generation Software Solutions (NGSS) department. The team enables secure, efficient, and reliable delivery of technology across Bain's global ecosystem, focusing on both technical operations and platform assurance so that every deployment meets the firm's standards for quality, security, and compliance.WHERE YOU’LL FIT WITHIN THE TEAM The Staff Engineer owns the design, architecture, and long-term direction of cloud infrastructure and software delivery across Coro's DevOps and Assurance team. Working alongside architects and backend engineers, this engineer sets the technical standard for how the team provisions infrastructure, ships software, and secures its platforms, and ensures those platforms scale as the build plan expands.This is a critical foundational role in the early stages of the platform build, requiring both strong technical fundamentals and the pragmatism to make infrastructure decisions that support a fast-moving product team.WHAT YOU’LL DO Infrastructure Architecture & Automation – 30%Own the design and evolution of cloud infrastructure built on Terraform and Terraform Cloud. Define the module structure, state strategy, and remote backend conventions the rest of the team builds against.Architect Azure networking end to end: VNet/subnet topology, private endpoints, DNS resolution, NSG design, and Front Door Premium configuration across dev, demo, and production.Set the standard for provisioning Azure platform services (App Services, Azure SQL, Azure OpenAI, Container Registry (e.g. Azure Container Registry, Cloudsmith), Key Vault, Entra ID, Storage Accounts / ADLS Gen2) and ensure environment parity by design.Own the automation roadmap for the team: identify manual, repetitive operational work, own the backlog of it, and drive it toward self-service and infrastructure-as-code so operational load trends down over time.Partner with Bain's central cloud and infrastructure teams to shape shared processes, tooling, and standards for operational work.Cloud & Platform Management (Azure) – 20%Own Azure Kubernetes Service (AKS) architecture, including node pools, scaling strategy, spot instance usage, and workload connectivity to dependent services (databases, storage, AI services).Define identity and access architecture: Entra ID app registrations, managed identities, RBAC model, and integration with external IdPs (Okta).Set infrastructure standards for database platforms (Azure SQL Serverless, PostgreSQL Flexible Server, Cosmos DB), including connectivity, Entra auth, firewall rules, and private endpoints.Ensure platform reliability and robust access controls across all environments, and act as the senior escalation point for platform-level issues.CI/CD & Software Delivery – 15%Define and own the CI/CD strategy using GitHub Actions for container builds, infrastructure deployments, and application releases, setting the patterns other engineers extend.Establish the container image lifecycle standard: build, scan, push to a container registry (e.g. Azure Container Registry, Cloudsmith), and deploy to AKS or App Services.Design environment promotion workflows with appropriate gating, secrets management (Key Vault), and rollback strategies.Architect and operate GitHub-hosted private runners where required, including network integration with Azure VNets.Monitoring, Security & Assurance – 15%Own the observability strategy using the team's monitoring stack (e.g. Datadog, Azure Application Insights). Define what the team monitors, alerts on, and how it optimizes cost and reliability.Lead the response to security findings: triage, containment, IAM scoping, container image CVE remediation, and endpoint hardening, and set the remediation standards others follow.Lead L2/L3 incident escalations, including root-cause analysis, user journey tracing, and log analysis, and drive the improvements that prevent recurrence.Define and enforce solution compliance across products: network isolation, least-privilege access, secrets hygiene, and deployment guardrails.Own the developer experience: set the standard for local development environments and deployment documentation so engineers across the distributed team can onboard quickly and operate with minimal infrastructure friction.Technical Leadership & Team Development – 20%Lead and mentor DevOps engineers: set technical direction, review designs, grow the team's depth, and raise the bar on engineering practice.Anticipate the needs of stakeholders across NGSS and the wider business, and shape the platform roadmap proactively rather than reactively.Partner with architects, product engineers, and security teams to align on infrastructure standards and shape platform roadmaps across NGSS.Drive DevOps culture and automation-first thinking across the engineering organization, and lead knowledge sharing.Contribute to and often lead technical discovery, POCs, and innovation workstreams to validate new tools, technologies, and architectural patterns.ABOUT YOUEducation & ExperienceBachelor's or Master's degree in Computer Science, Engineering, or a related technical field.7–9 years of experience in DevOps, infrastructure engineering, or cloud platform engineering, with time spent at a senior or staff level.Proven track record of architecting and operating cloud infrastructure in production at scale, owning technical decisions end to end.Demonstrated experience leading and mentoring DevOps or platform engineers in fast-paced product organizations.Professional Skills & MindsetExcellent communication and collaboration skills, with the ability to translate complex technical topics for diverse stakeholders and to set direction others can follow.Proactive, analytical, and systematic, with strong problem-solving skills and the ability to trace issues across multiple layers (DNS, networking, identity, application).Results-driven with a strong bias for automation and continuous improvement, and a track record of driving operational load down over time.Comfortable owning ambiguity and working with limited direction: able to define standards and roadmaps where none exist yet, and to manage multiple stakeholders independently.Familiarity with Agile methodologies and a genuine commitment to team enablement and growth.Technical ExpertiseDeep hands-on expertise with Terraform and Terraform Cloud (or equivalent): module design, state strategy, and remote backends at scale.Strong mastery of Azure services, including AKS, Networking (VNets, subnets, private endpoints, NSGs, DNS zones), App Services, Key Vault, Container Registry, and Storage Accounts.Deep experience with containerization technologies (Docker, Kubernetes) and container image lifecycle management.Expertise in roles, permissions, and IAM, particularly Microsoft Entra ID and Okta.Advanced CI/CD automation using GitHub Actions, Azure DevOps, and related DevOps toolchains, with the ability to define patterns for a team.Proficient in Linux administration and automation scripting (Bash, PowerShell, Python) for reusable workflows.Strong command of monitoring and observability platforms (e.g. Datadog, Azure Application Insights).Deep familiarity with Azure private networking: private endpoints (blob, DFS, SQL, PostgreSQL), Private DNS Zones, and VNet integration for App Services and AKS.Command of database deployment and management from an infrastructure perspective, Azure SQL Serverless, PostgreSQL Flexible Server, and Cosmos DB.Strong foundation in security remediation: container CVE patching, IAM scoping, NSG/firewall tightening, and WAF/Front Door rule management.Preferred QualificationsProfessional certifications such as Azure DevOps Engineer Expert, Azure Administrator, Terraform Associate, or CKA (or equivalent).Experience owning multi-environment governance, cost optimization (FinOps), and compliance frameworks in cloud environments.Familiarity with Azure OpenAI, Cognitive Search, Databricks, and the integration of AI services into enterprise platforms.Experience with workflow orchestration tools (Airflow, or similar DAG/pipeline systems).Snowflake administration or connectivity from a DevOps lens.Experience with AI/ML observability tools such as LangSmith or Arize.Familiarity with AI coding assistants such as Cursor, Claude Code, or Codex to speed up development.WHAT MAKES US A GREAT PLACE TO WORKWe are proud to be consistently recognized as one of the world’s best places to work. We are currently the top ranked consulting firm on Glassdoor’s Best Places to Work list and have earned the #1 overall spot a record seven times. Extraordinary teams are at the heart of our business strategy, but these don’t happen by chance. They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment. We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally.WHO YOU’LL WORK WITHCoro is Bain's persistent product development and engineering organization, building and operating the firm's proprietary digital solutions. Coro brings together technology, data, and services to create differentiated value for Bain's clients and case teams.This role sits within Coro's DevOps and Assurance team, part of the Next Generation Software Solutions (NGSS) department. The team enables secure, efficient, and reliable delivery of technology across Bain's global ecosystem, focusing on both technical operations and platform assurance so that every deployment meets the firm's standards for quality, security, and compliance.WHERE YOU’LL FIT WITHIN THE TEAM The Staff Engineer owns the design, architecture, and long-term direction of cloud infrastructure and software delivery across Coro's DevOps and Assurance team. Working alongside architects and backend engineers, this engineer sets the technical standard for how the team provisions infrastructure, ships software, and secures its platforms, and ensures those platforms scale as the build plan expands.This is a critical foundational role in the early stages of the platform build, requiring both strong technical fundamentals and the pragmatism to make infrastructure decisions that support a fast-moving product team.WHAT YOU’LL DO Infrastructure Architecture & Automation – 30%Own the design and evolution of cloud infrastructure built on Terraform and Terraform Cloud. Define the module structure, state strategy, and remote backend conventions the rest of the team builds against.Architect Azure networking end to end: VNet/subnet topology, private endpoints, DNS resolution, NSG design, and Front Door Premium configuration across dev, demo, and production.Set the standard for provisioning Azure platform services (App Services, Azure SQL, Azure OpenAI, Container Registry (e.g. Azure Container Registry, Cloudsmith), Key Vault, Entra ID, Storage Accounts / ADLS Gen2) and ensure environment parity by design.Own the automation roadmap for the team: identify manual, repetitive operational work, own the backlog of it, and drive it toward self-service and infrastructure-as-code so operational load trends down over time.Partner with Bain's central cloud and infrastructure teams to shape shared processes, tooling, and standards for operational work.Cloud & Platform Management (Azure) – 20%Own Azure Kubernetes Service (AKS) architecture, including node pools, scaling strategy, spot instance usage, and workload connectivity to dependent services (databases, storage, AI services).Define identity and access architecture: Entra ID app registrations, managed identities, RBAC model, and integration with external IdPs (Okta).Set infrastructure standards for database platforms (Azure SQL Serverless, PostgreSQL Flexible Server, Cosmos DB), including connectivity, Entra auth, firewall rules, and private endpoints.Ensure platform reliability and robust access controls across all environments, and act as the senior escalation point for platform-level issues.CI/CD & Software Delivery – 15%Define and own the CI/CD strategy using GitHub Actions for container builds, infrastructure deployments, and application releases, setting the patterns other engineers extend.Establish the container image lifecycle standard: build, scan, push to a container registry (e.g. Azure Container Registry, Cloudsmith), and deploy to AKS or App Services.Design environment promotion workflows with appropriate gating, secrets management (Key Vault), and rollback strategies.Architect and operate GitHub-hosted private runners where required, including network integration with Azure VNets.Monitoring, Security & Assurance – 15%Own the observability strategy using the team's monitoring stack (e.g. Datadog, Azure Application Insights). Define what the team monitors, alerts on, and how it optimizes cost and reliability.Lead the response to security findings: triage, containment, IAM scoping, container image CVE remediation, and endpoint hardening, and set the remediation standards others follow.Lead L2/L3 incident escalations, including root-cause analysis, user journey tracing, and log analysis, and drive the improvements that prevent recurrence.Define and enforce solution compliance across products: network isolation, least-privilege access, secrets hygiene, and deployment guardrails.Own the developer experience: set the standard for local development environments and deployment documentation so engineers across the distributed team can onboard quickly and operate with minimal infrastructure friction.Technical Leadership & Team Development – 20%Lead and mentor DevOps engineers: set technical direction, review designs, grow the team's depth, and raise the bar on engineering practice.Anticipate the needs of stakeholders across NGSS and the wider business, and shape the platform roadmap proactively rather than reactively.Partner with architects, product engineers, and security teams to align on infrastructure standards and shape platform roadmaps across NGSS.Drive DevOps culture and automation-first thinking across the engineering organization, and lead knowledge sharing.Contribute to and often lead technical discovery, POCs, and innovation workstreams to validate new tools, technologies, and architectural patterns.ABOUT YOUEducation & ExperienceBachelor's or Master's degree in Computer Science, Engineering, or a related technical field.7–9 years of experience in DevOps, infrastructure engineering, or cloud platform engineering, with time spent at a senior or staff level.Proven track record of architecting and operating cloud infrastructure in production at scale, owning technical decisions end to end.Demonstrated experience leading and mentoring DevOps or platform engineers in fast-paced product organizations.Professional Skills & MindsetExcellent communication and collaboration skills, with the ability to translate complex technical topics for diverse stakeholders and to set direction others can follow.Proactive, analytical, and systematic, with strong problem-solving skills and the ability to trace issues across multiple layers (DNS, networking, identity, application).Results-driven with a strong bias for automation and continuous improvement, and a track record of driving operational load down over time.Comfortable owning ambiguity and working with limited direction: able to define standards and roadmaps where none exist yet, and to manage multiple stakeholders independently.Familiarity with Agile methodologies and a genuine commitment to team enablement and growth.Technical ExpertiseDeep hands-on expertise with Terraform and Terraform Cloud (or equivalent): module design, state strategy, and remote backends at scale.Strong mastery of Azure services, including AKS, Networking (VNets, subnets, private endpoints, NSGs, DNS zones), App Services, Key Vault, Container Registry, and Storage Accounts.Deep experience with containerization technologies (Docker, Kubernetes) and container image lifecycle management.Expertise in roles, permissions, and IAM, particularly Microsoft Entra ID and Okta.Advanced CI/CD automation using GitHub Actions, Azure DevOps, and related DevOps toolchains, with the ability to define patterns for a team.Proficient in Linux administration and automation scripting (Bash, PowerShell, Python) for reusable workflows.Strong command of monitoring and observability platforms (e.g. Datadog, Azure Application Insights).Deep familiarity with Azure private networking: private endpoints (blob, DFS, SQL, PostgreSQL), Private DNS Zones, and VNet integration for App Services and AKS.Command of database deployment and management from an infrastructure perspective, Azure SQL Serverless, PostgreSQL Flexible Server, and Cosmos DB.Strong foundation in security remediation: container CVE patching, IAM scoping, NSG/firewall tightening, and WAF/Front Door rule management.Preferred QualificationsProfessional certifications such as Azure DevOps Engineer Expert, Azure Administrator, Terraform Associate, or CKA (or equivalent).Experience owning multi-environment governance, cost optimization (FinOps), and compliance frameworks in cloud environments.Familiarity with Azure OpenAI, Cognitive Search, Databricks, and the integration of AI services into enterprise platforms.Experience with workflow orchestration tools (Airflow, or similar DAG/pipeline systems).Snowflake administration or connectivity from a DevOps lens.Experience with AI/ML observability tools such as LangSmith or Arize.Familiarity with AI coding assistants such as Cursor, Claude Code, or Codex to speed up development.WHAT MAKES US A GREAT PLACE TO WORKWe are proud to be consistently recognized as one of the world’s best places to work. We are currently the top ranked consulting firm on Glassdoor’s Best Places to Work list and have earned the #1 overall spot a record seven times. Extraordinary teams are at the heart of our business strategy, but these don’t happen by chance. They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment. We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally.WHO YOU’LL WORK WITHCoro is Bain's persistent product development and engineering organization, building and operating the firm's proprietary digital solutions. Coro brings together technology, data, and services to create differentiated value for Bain's clients and case teams.This role sits within Coro's DevOps and Assurance team, part of the Next Generation Software Solutions (NGSS) department. The team enables secure, efficient, and reliable delivery of technology across Bain's global ecosystem, focusing on both technical operations and platform assurance so that every deployment meets the firm's standards for quality, security, and compliance.WHERE YOU’LL FIT WITHIN THE TEAM The Staff Engineer owns the design, architecture, and long-term direction of cloud infrastructure and software delivery across Coro's DevOps and Assurance team. Working alongside architects and backend engineers, this engineer sets the technical standard for how the team provisions infrastructure, ships software, and secures its platforms, and ensures those platforms scale as the build plan expands.This is a critical foundational role in the early stages of the platform build, requiring both strong technical fundamentals and the pragmatism to make infrastructure decisions that support a fast-moving product team.WHAT YOU’LL DO Infrastructure Architecture & Automation – 30%Own the design and evolution of cloud infrastructure built on Terraform and Terraform Cloud. Define the module structure, state strategy, and remote backend conventions the rest of the team builds against.Architect Azure networking end to end: VNet/subnet topology, private endpoints, DNS resolution, NSG design, and Front Door Premium configuration across dev, demo, and production.Set the standard for provisioning Azure platform services (App Services, Azure SQL, Azure OpenAI, Container Registry (e.g. Azure Container Registry, Cloudsmith), Key Vault, Entra ID, Storage Accounts / ADLS Gen2) and ensure environment parity by design.Own the automation roadmap for the team: identify manual, repetitive operational work, own the backlog of it, and drive it toward self-service and infrastructure-as-code so operational load trends down over time.Partner with Bain's central cloud and infrastructure teams to shape shared processes, tooling, and standards for operational work.Cloud & Platform Management (Azure) – 20%Own Azure Kubernetes Service (AKS) architecture, including node pools, scaling strategy, spot instance usage, and workload connectivity to dependent services (databases, storage, AI services).Define identity and access architecture: Entra ID app registrations, managed identities, RBAC model, and integration with external IdPs (Okta).Set infrastructure standards for database platforms (Azure SQL Serverless, PostgreSQL Flexible Server, Cosmos DB), including connectivity, Entra auth, firewall rules, and private endpoints.Ensure platform reliability and robust access controls across all environments, and act as the senior escalation point for platform-level issues.CI/CD & Software Delivery – 15%Define and own the CI/CD strategy using GitHub Actions for container builds, infrastructure deployments, and application releases, setting the patterns other engineers extend.Establish the container image lifecycle standard: build, scan, push to a container registry (e.g. Azure Container Registry, Cloudsmith), and deploy to AKS or App Services.Design environment promotion workflows with appropriate gating, secrets management (Key Vault), and rollback strategies.Architect and operate GitHub-hosted private runners where required, including network integration with Azure VNets.Monitoring, Security & Assurance – 15%Own the observability strategy using the team's monitoring stack (e.g. Datadog, Azure Application Insights). Define what the team monitors, alerts on, and how it optimizes cost and reliability.Lead the response to security findings: triage, containment, IAM scoping, container image CVE remediation, and endpoint hardening, and set the remediation standards others follow.Lead L2/L3 incident escalations, including root-cause analysis, user journey tracing, and log analysis, and drive the improvements that prevent recurrence.Define and enforce solution compliance across products: network isolation, least-privilege access, secrets hygiene, and deployment guardrails.Own the developer experience: set the standard for local development environments and deployment documentation so engineers across the distributed team can onboard quickly and operate with minimal infrastructure friction.Technical Leadership & Team Development – 20%Lead and mentor DevOps engineers: set technical direction, review designs, grow the team's depth, and raise the bar on engineering practice.Anticipate the needs of stakeholders across NGSS and the wider business, and shape the platform roadmap proactively rather than reactively.Partner with architects, product engineers, and security teams to align on infrastructure standards and shape platform roadmaps across NGSS.Drive DevOps culture and automation-first thinking across the engineering organization, and lead knowledge sharing.Contribute to and often lead technical discovery, POCs, and innovation workstreams to validate new tools, technologies, and architectural patterns.ABOUT YOUEducation & ExperienceBachelor's or Master's degree in Computer Science, Engineering, or a related technical field.7–9 years of experience in DevOps, infrastructure engineering, or cloud platform engineering, with time spent at a senior or staff level.Proven track record of architecting and operating cloud infrastructure in production at scale, owning technical decisions end to end.Demonstrated experience leading and mentoring DevOps or platform engineers in fast-paced product organizations.Professional Skills & MindsetExcellent communication and collaboration skills, with the ability to translate complex technical topics for diverse stakeholders and to set direction others can follow.Proactive, analytical, and systematic, with strong problem-solving skills and the ability to trace issues across multiple layers (DNS, networking, identity, application).Results-driven with a strong bias for automation and continuous improvement, and a track record of driving operational load down over time.Comfortable owning ambiguity and working with limited direction: able to define standards and roadmaps where none exist yet, and to manage multiple stakeholders independently.Familiarity with Agile methodologies and a genuine commitment to team enablement and growth.Technical ExpertiseDeep hands-on expertise with Terraform and Terraform Cloud (or equivalent): module design, state strategy, and remote backends at scale.Strong mastery of Azure services, including AKS, Networking (VNets, subnets, private endpoints, NSGs, DNS zones), App Services, Key Vault, Container Registry, and Storage Accounts.Deep experience with containerization technologies (Docker, Kubernetes) and container image lifecycle management.Expertise in roles, permissions, and IAM, particularly Microsoft Entra ID and Okta.Advanced CI/CD automation using GitHub Actions, Azure DevOps, and related DevOps toolchains, with the ability to define patterns for a team.Proficient in Linux administration and automation scripting (Bash, PowerShell, Python) for reusable workflows.Strong command of monitoring and observability platforms (e.g. Datadog, Azure Application Insights).Deep familiarity with Azure private networking: private endpoints (blob, DFS, SQL, PostgreSQL), Private DNS Zones, and VNet integration for App Services and AKS.Command of database deployment and management from an infrastructure perspective, Azure SQL Serverless, PostgreSQL Flexible Server, and Cosmos DB.Strong foundation in security remediation: container CVE patching, IAM scoping, NSG/firewall tightening, and WAF/Front Door rule management.Preferred QualificationsProfessional certifications such as Azure DevOps Engineer Expert, Azure Administrator, Terraform Associate, or CKA (or equivalent).Experience owning multi-environment governance, cost optimization (FinOps), and compliance frameworks in cloud environments.Familiarity with Azure OpenAI, Cognitive Search, Databricks, and the integration of AI services into enterprise platforms.Experience with workflow orchestration tools (Airflow, or similar DAG/pipeline systems).Snowflake administration or connectivity from a DevOps lens.Experience with AI/ML observability tools such as LangSmith or Arize.Familiarity with AI coding assistants such as Cursor, Claude Code, or Codex to speed up development.

WHAT MAKES US A GREAT PLACE TO WORK

WHAT MAKES US A GREAT PLACE TO WORKWHAT MAKES US A GREAT PLACE TO WORK

We are proud to be consistently recognized as one of the world’s best places to work. We are currently the top ranked consulting firm on Glassdoor’s Best Places to Work list and have earned the #1 overall spot a record seven times. Extraordinary teams are at the heart of our business strategy, but these don’t happen by chance. They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment. We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally.

We are proud to be consistently recognized as one of the world’s best places to work. We are currently the top ranked consulting firm onGlassdoor’s Best Places to WorkGlassdoor’s Best Places to Worklist and have earned the #1 overall spot a record seven times. Extraordinary teams are at the heart of our business strategy, but these don’t happen by chance. They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment. We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally.

WHO YOU’LL WORK WITH

WHO YOU’LL WORK WITHWHO YOU’LL WORK WITH

Coro is Bain's persistent product development and engineering organization, building and operating the firm's proprietary digital solutions. Coro brings together technology, data, and services to create differentiated value for Bain's clients and case teams.

Coro is Bain's persistent product development and engineering organization, building and operating the firm's proprietary digital solutions. Coro brings together technology, data, and services to create differentiated value for Bain's clients and case teams.

This role sits within Coro's DevOps and Assurance team, part of the Next Generation Software Solutions (NGSS) department. The team enables secure, efficient, and reliable delivery of technology across Bain's global ecosystem, focusing on both technical operations and platform assurance so that every deployment meets the firm's standards for quality, security, and compliance.

This role sits within Coro's DevOps and Assurance team, part of the Next Generation Software Solutions (NGSS) department. The team enables secure, efficient, and reliable delivery of technology across Bain's global ecosystem, focusing on both technical operations and platform assurance so that every deployment meets the firm's standards for quality, security, and compliance.

WHERE YOU’LL FIT WITHIN THE TEAM

WHERE YOU’LL FIT WITHIN THE TEAMWHERE YOU’LL FIT WITHIN THE TEAM

The Staff Engineer owns the design, architecture, and long-term direction of cloud infrastructure and software delivery across Coro's DevOps and Assurance team. Working alongside architects and backend engineers, this engineer sets the technical standard for how the team provisions infrastructure, ships software, and secures its platforms, and ensures those platforms scale as the build plan expands.

The Staff Engineer owns the design, architecture, and long-term direction of cloud infrastructure and software delivery across Coro's DevOps and Assurance team. Working alongside architects and backend engineers, this engineer sets the technical standard for how the team provisions infrastructure, ships software, and secures its platforms, and ensures those platforms scale as the build plan expands.

This is a critical foundational role in the early stages of the platform build, requiring both strong technical fundamentals and the pragmatism to make infrastructure decisions that support a fast-moving product team.

This is a critical foundational role in the early stages of the platform build, requiring both strong technical fundamentals and the pragmatism to make infrastructure decisions that support a fast-moving product team.

WHAT YOU’LL DO

WHAT YOU’LL DOWHAT YOU’LL DO

Infrastructure Architecture & Automation – 30%

Infrastructure Architecture & Automation – 30%Infrastructure Architecture & Automation – 30%
  • Own the design and evolution of cloud infrastructure built on Terraform and Terraform Cloud. Define the module structure, state strategy, and remote backend conventions the rest of the team builds against.
Own the design and evolution of cloud infrastructure built on Terraform and Terraform Cloud. Define the module structure, state strategy, and remote backend conventions the rest of the team builds against.
  • Architect Azure networking end to end: VNet/subnet topology, private endpoints, DNS resolution, NSG design, and Front Door Premium configuration across dev, demo, and production.
Architect Azure networking end to end: VNet/subnet topology, private endpoints, DNS resolution, NSG design, and Front Door Premium configuration across dev, demo, and production.
  • Set the standard for provisioning Azure platform services (App Services, Azure SQL, Azure OpenAI, Container Registry (e.g. Azure Container Registry, Cloudsmith), Key Vault, Entra ID, Storage Accounts / ADLS Gen2) and ensure environment parity by design.
Set the standard for provisioning Azure platform services (App Services, Azure SQL, Azure OpenAI, Container Registry (e.g. Azure Container Registry, Cloudsmith), Key Vault, Entra ID, Storage Accounts / ADLS Gen2) and ensure environment parity by design.
  • Own the automation roadmap for the team: identify manual, repetitive operational work, own the backlog of it, and drive it toward self-service and infrastructure-as-code so operational load trends down over time.
Own the automation roadmap for the team: identify manual, repetitive operational work, own the backlog of it, and drive it toward self-service and infrastructure-as-code so operational load trends down over time.
  • Partner with Bain's central cloud and infrastructure teams to shape shared processes, tooling, and standards for operational work.
Partner with Bain's central cloud and infrastructure teams to shape shared processes, tooling, and standards for operational work.

Cloud & Platform Management (Azure) – 20%

Cloud & Platform Management (Azure) – 20%Cloud & Platform Management (Azure) – 20%
  • Own Azure Kubernetes Service (AKS) architecture, including node pools, scaling strategy, spot instance usage, and workload connectivity to dependent services (databases, storage, AI services).
Own Azure Kubernetes Service (AKS) architecture, including node pools, scaling strategy, spot instance usage, and workload connectivity to dependent services (databases, storage, AI services).
  • Define identity and access architecture: Entra ID app registrations, managed identities, RBAC model, and integration with external IdPs (Okta).
Define identity and access architecture: Entra ID app registrations, managed identities, RBAC model, and integration with external IdPs (Okta).
  • Set infrastructure standards for database platforms (Azure SQL Serverless, PostgreSQL Flexible Server, Cosmos DB), including connectivity, Entra auth, firewall rules, and private endpoints.
Set infrastructure standards for database platforms (Azure SQL Serverless, PostgreSQL Flexible Server, Cosmos DB), including connectivity, Entra auth, firewall rules, and private endpoints.
  • Ensure platform reliability and robust access controls across all environments, and act as the senior escalation point for platform-level issues.
Ensure platform reliability and robust access controls across all environments, and act as the senior escalation point for platform-level issues.

CI/CD & Software Delivery – 15%

CI/CD & Software Delivery – 15%CI/CD & Software Delivery – 15%
  • Define and own the CI/CD strategy using GitHub Actions for container builds, infrastructure deployments, and application releases, setting the patterns other engineers extend.
Define and own the CI/CD strategy using GitHub Actions for container builds, infrastructure deployments, and application releases, setting the patterns other engineers extend.
  • Establish the container image lifecycle standard: build, scan, push to a container registry (e.g. Azure Container Registry, Cloudsmith), and deploy to AKS or App Services.
Establish the container image lifecycle standard: build, scan, push to a container registry (e.g. Azure Container Registry, Cloudsmith), and deploy to AKS or App Services.
  • Design environment promotion workflows with appropriate gating, secrets management (Key Vault), and rollback strategies.
Design environment promotion workflows with appropriate gating, secrets management (Key Vault), and rollback strategies.
  • Architect and operate GitHub-hosted private runners where required, including network integration with Azure VNets.
Architect and operate GitHub-hosted private runners where required, including network integration with Azure VNets.

Monitoring, Security & Assurance – 15%

Monitoring, Security & Assurance – 15%Monitoring, Security & Assurance – 15%
  • Own the observability strategy using the team's monitoring stack (e.g. Datadog, Azure Application Insights). Define what the team monitors, alerts on, and how it optimizes cost and reliability.
Own the observability strategy using the team's monitoring stack (e.g. Datadog, Azure Application Insights). Define what the team monitors, alerts on, and how it optimizes cost and reliability.
  • Lead the response to security findings: triage, containment, IAM scoping, container image CVE remediation, and endpoint hardening, and set the remediation standards others follow.
Lead the response to security findings: triage, containment, IAM scoping, container image CVE remediation, and endpoint hardening, and set the remediation standards others follow.
  • Lead L2/L3 incident escalations, including root-cause analysis, user journey tracing, and log analysis, and drive the improvements that prevent recurrence.
Lead L2/L3 incident escalations, including root-cause analysis, user journey tracing, and log analysis, and drive the improvements that prevent recurrence.
  • Define and enforce solution compliance across products: network isolation, least-privilege access, secrets hygiene, and deployment guardrails.
Define and enforce solution compliance across products: network isolation, least-privilege access, secrets hygiene, and deployment guardrails.
  • Own the developer experience: set the standard for local development environments and deployment documentation so engineers across the distributed team can onboard quickly and operate with minimal infrastructure friction.
Own the developer experience: set the standard for local development environments and deployment documentation so engineers across the distributed team can onboard quickly and operate with minimal infrastructure friction.

Technical Leadership & Team Development – 20%

Technical Leadership & Team Development – 20%Technical Leadership & Team Development – 20%
  • Lead and mentor DevOps engineers: set technical direction, review designs, grow the team's depth, and raise the bar on engineering practice.
Lead and mentor DevOps engineers: set technical direction, review designs, grow the team's depth, and raise the bar on engineering practice.
  • Anticipate the needs of stakeholders across NGSS and the wider business, and shape the platform roadmap proactively rather than reactively.
Anticipate the needs of stakeholders across NGSS and the wider business, and shape the platform roadmap proactively rather than reactively.
  • Partner with architects, product engineers, and security teams to align on infrastructure standards and shape platform roadmaps across NGSS.
Partner with architects, product engineers, and security teams to align on infrastructure standards and shape platform roadmaps across NGSS.
  • Drive DevOps culture and automation-first thinking across the engineering organization, and lead knowledge sharing.
Drive DevOps culture and automation-first thinking across the engineering organization, and lead knowledge sharing.
  • Contribute to and often lead technical discovery, POCs, and innovation workstreams to validate new tools, technologies, and architectural patterns.
Contribute to and often lead technical discovery, POCs, and innovation workstreams to validate new tools, technologies, and architectural patterns.

ABOUT YOU

ABOUT YOUABOUT YOU

Education & Experience

Education & ExperienceEducation & Experience
  • Bachelor's or Master's degree in Computer Science, Engineering, or a related technical field.
Bachelor's or Master's degree in Computer Science, Engineering, or a related technical field.
  • 7–9 years of experience in DevOps, infrastructure engineering, or cloud platform engineering, with time spent at a senior or staff level.
7–9 years of experience in DevOps, infrastructure engineering, or cloud platform engineering, with time spent at a senior or staff level.7–9 years
  • Proven track record of architecting and operating cloud infrastructure in production at scale, owning technical decisions end to end.
Proven track record of architecting and operating cloud infrastructure in production at scale, owning technical decisions end to end.
  • Demonstrated experience leading and mentoring DevOps or platform engineers in fast-paced product organizations.
Demonstrated experience leading and mentoring DevOps or platform engineers in fast-paced product organizations.

Professional Skills & Mindset

Professional Skills & MindsetProfessional Skills & Mindset
  • Excellent communication and collaboration skills, with the ability to translate complex technical topics for diverse stakeholders and to set direction others can follow.
Excellent communication and collaboration skills, with the ability to translate complex technical topics for diverse stakeholders and to set direction others can follow.
  • Proactive, analytical, and systematic, with strong problem-solving skills and the ability to trace issues across multiple layers (DNS, networking, identity, application).
Proactive, analytical, and systematic, with strong problem-solving skills and the ability to trace issues across multiple layers (DNS, networking, identity, application).
  • Results-driven with a strong bias for automation and continuous improvement, and a track record of driving operational load down over time.
Results-driven with a strong bias for automation and continuous improvement, and a track record of driving operational load down over time.
  • Comfortable owning ambiguity and working with limited direction: able to define standards and roadmaps where none exist yet, and to manage multiple stakeholders independently.
Comfortable owning ambiguity and working with limited direction: able to define standards and roadmaps where none exist yet, and to manage multiple stakeholders independently.
  • Familiarity with Agile methodologies and a genuine commitment to team enablement and growth.
Familiarity with Agile methodologies and a genuine commitment to team enablement and growth.

Technical Expertise

Technical ExpertiseTechnical Expertise
  • Deep hands-on expertise with Terraform and Terraform Cloud (or equivalent): module design, state strategy, and remote backends at scale.
Deep hands-on expertise with Terraform and Terraform Cloud (or equivalent): module design, state strategy, and remote backends at scale.Terraform
  • Strong mastery of Azure services, including AKS, Networking (VNets, subnets, private endpoints, NSGs, DNS zones), App Services, Key Vault, Container Registry, and Storage Accounts.
Strong mastery of Azure services, including AKS, Networking (VNets, subnets, private endpoints, NSGs, DNS zones), App Services, Key Vault, Container Registry, and Storage Accounts.AKS, Networking (VNets, subnets, private endpoints, NSGs, DNS zones), App Services, Key Vault, Container Registry, and Storage Accounts
  • Deep experience with containerization technologies (Docker, Kubernetes) and container image lifecycle management.
Deep experience with containerization technologies (Docker, Kubernetes) and container image lifecycle management.Docker, Kubernetes
  • Expertise in roles, permissions, and IAM, particularly Microsoft Entra ID and Okta.
Expertise in roles, permissions, and IAM, particularly Microsoft Entra ID and Okta.roles, permissions, and IAM,Microsoft Entra ID and Okta
  • Advanced CI/CD automation using GitHub Actions, Azure DevOps, and related DevOps toolchains, with the ability to define patterns for a team.
Advanced CI/CD automation using GitHub Actions, Azure DevOps, and related DevOps toolchains, with the ability to define patterns for a team.GitHub Actions
  • Proficient in Linux administration and automation scripting (Bash, PowerShell, Python) for reusable workflows.
Proficient in Linux administration and automation scripting (Bash, PowerShell, Python) for reusable workflows.Bash, PowerShell, Python
  • Strong command of monitoring and observability platforms (e.g. Datadog, Azure Application Insights).
Strong command of monitoring and observability platforms (e.g. Datadog, Azure Application Insights).Datadog, Azure Application Insights
  • Deep familiarity with Azure private networking: private endpoints (blob, DFS, SQL, PostgreSQL), Private DNS Zones, and VNet integration for App Services and AKS.
Deep familiarity with Azure private networking: private endpoints (blob, DFS, SQL, PostgreSQL), Private DNS Zones, and VNet integration for App Services and AKS.Azure private networking: private endpoints (blob, DFS, SQL, PostgreSQL), Private DNS Zones, and VNet integration for App Services and AKS
  • Command of database deployment and management from an infrastructure perspective, Azure SQL Serverless, PostgreSQL Flexible Server, and Cosmos DB.
Command of database deployment and management from an infrastructure perspective, Azure SQL Serverless, PostgreSQL Flexible Server, and Cosmos DB.Azure SQL Serverless, PostgreSQL Flexible Server
  • Strong foundation in security remediation: container CVE patching, IAM scoping, NSG/firewall tightening, and WAF/Front Door rule management.
Strong foundation in security remediation: container CVE patching, IAM scoping, NSG/firewall tightening, and WAF/Front Door rule management.security remediation

Preferred Qualifications

Preferred QualificationsPreferred Qualifications
  • Professional certifications such as Azure DevOps Engineer Expert, Azure Administrator, Terraform Associate, or CKA (or equivalent).
Professional certifications such as Azure DevOps Engineer Expert, Azure Administrator, Terraform Associate, or CKA (or equivalent).
  • Experience owning multi-environment governance, cost optimization (FinOps), and compliance frameworks in cloud environments.
Experience owning multi-environment governance, cost optimization (FinOps), and compliance frameworks in cloud environments.
  • Familiarity with Azure OpenAI, Cognitive Search, Databricks, and the integration of AI services into enterprise platforms.
Familiarity with Azure OpenAI, Cognitive Search, Databricks, and the integration of AI services into enterprise platforms.Azure OpenAI, Cognitive Search, Databricks
  • Experience with workflow orchestration tools (Airflow, or similar DAG/pipeline systems).
Experience with workflow orchestration tools (Airflow, or similar DAG/pipeline systems).
  • Snowflake administration or connectivity from a DevOps lens.
Snowflake administration or connectivity from a DevOps lens.Snowflake
  • Experience with AI/ML observability tools such as LangSmith or Arize.
Experience with AI/ML observability tools such as LangSmith or Arize.
  • Familiarity with AI coding assistants such as Cursor, Claude Code, or Codex to speed up development.
Familiarity with AI coding assistants such as Cursor, Claude Code, or Codex to speed up development.

Similar jobs

General Information Job Title Staff Engineer I, TSG Infrastructure Job ID 107537 Work Areas Technology & Engineering Employment Type Permanent Full-Time Location(s) New Delhi Description & Requirements COMPANY PROFILEBain & Company is one of the top management consulting firms in the world that helps the world’s most ambitious changemakers define the future.Across 65 cities in 40 countries, we work alongside our clients as one team with a shared ambition to achieve extraordinary results, outperforming the competition, and redefining industries. We complement our tailored, integrated expertise with a vibrant ecosystem of digital innovators to deliver better, faster, and more enduring outcomes. The firm established several functions in the Indian market early 2000s and its remit across functions has expanded over time. Since 2019, these functions have become part of Global Business Services (GBS). Global Business Services (GBS) is a network of five interconnected business functions hubs across India, Poland, Malaysia, Mexico and Portugal, serving Bain globally to run our business, support other functions, and help drive innovation internally. We are over 1000 business professionals – serving functions in operations, HR, finance, legal, tech, marketing, research, and data analytics – who support our offices globally. Our mantra of “shared innovation, seamless execution,” underpinned by a passion for results, teamwork, and creativity, helps Bain stay at the top of our game operationally. WHAT MAKES US A GREAT PLACE TO WORKWe are proud to be consistently recognized as one of the world’s best places to work. We are currently the top-ranked consulting firm on Glassdoor’s Best Places to Work list and have earned the #1 overall spot a record seven times.Extraordinary teams are at the heart of our business strategy, but these don’t happen by chance. They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment. We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally. Job SummaryThe Staff Engineer I will work as an individual contributor and technical leader and will drive the development and execution of an infrastructure platform that delivers secure, reliable, and scalable services. They will leverage their deep expertise in private datacenter, public cloud providers, infrastructure such as code, automation, and data analytics to create modern, cloud-based solutions. The Staff Engineer I will collaborate with teams both within and outside of the organization to provide world-class services. They must be adaptable, eager to learn, and focused on delivering results. In addition to platform and solution delivery responsibilities, the Staff Engineer will also play a key role in identifying areas for continuous improvement and implementing best practices.Principle Accountabilities and % of the timePlatform & Solution Delivery (60%)Help design, lead building and maintaining public and private infrastructure and solutions to support the availability, orchestration, configuration, maintenance and monitoring of infrastructure environmentsDevelop blueprints or engineer new solutions as requirements dictateMake security a priority at every step of the infrastructure, application and product lifecycleSupervise code changes or major changesMentor and coach junior team membersHelp define and advocate for effective development practicesContinuous Improvement (40%)Lead identifying issues with efficiency, stability, availability, and security of existing code and infrastructure, and bring new ideas to the table to improve overall delivery of servicesHelp to establish, implement and adhere to the corporate technology standards and guidelines Knowledge, Skills, and AbilitiesStrong in secure infrastructure frameworks and cloud security best practicesDemonstrated excellence in applying automation to all aspects of technical operationsStrong analytical, conceptual, and problem-solving abilitiesStrong ability to communicate at all levels of the entire organization and with customersStrong knowledge of Agile methodologies and processesUnderstanding of data visualization, data modeling, and compute scaling Knowledge of:Multiple public cloud providers (AWS, Azure or GCP) or private datacenter managementScripting, infrastructure as code and automation languages and tools (Ansible, Terraform, Helm, GitHub Actions, PowerShell or Python)Developing and releasing production solutions leveraging public cloud and SaaS infrastructure or tools ExperienceExperience with multiple cloud providers (AWS, Azure or GCP) or private datacenter management, familiar with other providersExperience with scripting, infrastructure as code and automation languages and tools (Ansible, Terraform, Helm, GitHub Actions, PowerShell and Python)Experience with CI/CD processes, code reviews, code deployments and pipelines Experience with logging and monitoring solutions such as Datadog, Grafana and PrometheusExperience with containers, Docker and KubernetesExperience with identity solutions such as Active Directory, AzureAD, Okta or LDAPExperience with public cloud landing zone architecturesMinimum experience withGenerative AI, Databases, data engineering, data science or business intelligence technologyExperience with Go or Python for cloud platform and infrastructure API automationExperience with Hashicorp Cloud Platform (Terraform & Vault) Education OR equivalent combination of education, training, and experience• Associate's/Bachelor’s degree or an equivalent combination of education, training and experience.Recommended Years of Relevant Experience - 5-8+ Go back Apply Share this job: LinkedIn X Emailfull timeStaff
posted 29 days ago
General Information Job Title Staff Data Engineer I, NGSS Aura Job ID 107711 Work Areas Technology & Engineering Employment Type Permanent Full-Time Location(s) Chicago Description & Requirements WHAT MAKES US A GREAT PLACE TO WORKWe are proud to be consistently recognized as one of the world's best places to work. We are currently the top ranked consulting firm on Glassdoor's Best Places to Work list and have earned the #1 overall spot a record seven times. Extraordinary teams are at the heart of our business strategy, but these don't happen by chance. They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment. We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally.WHO YOU'LL WORK WITHBain's Next Generation Software Solutions (NGSS) team is responsible for discovering, building, scaling, supporting, and maintaining software products that enable Bain's intellectual property and consulting solutions.Within this broader team, you'll be embedded in Aura, Bain's proprietary global workforce data and analytics platform. Aura processes billions of data points across more than 20 million companies worldwide, delivering the kind of workforce intelligence that once took teams of analysts weeks to produce in a matter of minutes.WHERE YOU'LL FIT WITHIN THE TEAMAs a Staff Data Engineer I, you'll be at the core of an autonomous AI system that powers high-stakes decisions for the world's top consulting firms, private equity funds, and Fortune 500 companies. You'll build the data infrastructure behind a category-defining product and play a key role in shaping Aura's data platform and engineering practices, own critical components of our data infrastructure, partner across Engineering, Product, and AI teams, and build a scalable foundation that powers analytics, machine learning, and product experiences. You'll contribute not only through implementation but also through architecture, operational excellence, and technical leadership.WHAT YOU'LL DOData Platform Architecture & InfrastructureOwn the architecture, reliability, and scalability of Aura's data platform.Design, build, and maintain reliable and scalable data pipelines from raw ingestion to downstream analytics layers (including dashboards and ML features).Lead the development of new data infrastructure projects from scratch and own delivery through production.Optimize performance and cost across data workflows (e.g., query tuning, storage optimization).Engineering Excellence & Operational SupportEstablish and maintain data engineering best practices, including testing, documentation, and observability.Participate in operational support and continuous improvement of production data systems.Establish pipeline alerting and data quality monitors in DBT across the data stack.Triage and resolve inbound data questions from business and technical stakeholders, including data discrepancies, pipeline issues, and ad-hoc data requests.Cross-functional Collaboration & Technical LeadershipPartner closely with Engineering, Product, Data Science, and AI teams to deliver scalable data solutions.Mentor engineers through code reviews and technical guidance.ABOUT YOUExperience5–8+ years of experience designing scalable data architecture.EducationAssociate's/Bachelor's degree or an equivalent combination of education, training and experience.Knowledge, Skills & AbilitiesStrong understanding of software engineering best practices (testing, CI/CD, code reviews).Demonstrated ability to lead technical initiatives and collaborate across cross-functional teams.Advanced SQL skills and deep experience with modern data warehouses, especially Snowflake.Proficient in orchestration tools such as Airflow.Experience with DBT for data modeling, transformation, and data quality monitoring.Strong Python programming skills.Experience working in cloud environments, particularly AWS (e.g., S3, Lambda, ECS, RDS, MWAA).Familiarity with version control, CI/CD workflows, and Infrastructure-as-Code.Additional QualificationsExperience owning and delivering greenfield projects independently.Deep expertise in Snowflake performance tuning and cost optimization.Background in analytics or ML data preparation.Prior experience embedded in a startup or small data team.Familiarity with OpenSearch for log analysis or search-backed data products.U.S. COMPENSATION INFORMATIONCompensation for this role includes base salary, annual discretionary performance bonus, 401(k) plan with an annual employer contribution based on years of service and Bain's best in class benefits package (details listed below).Some local governments in the United States require a good-faith, reasonable salary range to be included in job postings for open roles.The estimated annualized compensation for this role is as follows:In Illinois, the good-faith, reasonable annualized full-time salary range for this role is between $141,000 - $169,250.Annual discretionary performance bonus.This role may also be eligible for other elements of discretionary compensation.Benefits4.5% 401(k) company contribution, which increases after 3 years of service and is 100% vested upon start date.Bain & Company's comprehensive benefits and wellness program is designed to help employees achieve personal independence, protection and stability in the areas most important to you and your family.Bain pays 100% individual employee premiums for medical, dental and vision programs, offering one of the most comprehensive medical plans for employees without impacting your paycheck.Generous paid time off, including parental leave, sick leave and paid holidays.Fully vested 401(k) company contribution.Paid Life and Long-Term Disability insurance. Go back Apply Share this job: LinkedIn X Emailfull timeStaff$141K–169.3K
posted 25 days ago