Description
WHAT MAKES US A GREAT PLACE TO WORK
We are proud to be consistently recognized as one of the world’s best places to work.
We are currently the top ranked consulting firm on Glassdoor’s Best Places to Work list and have earned the #1 overall spot a record seven times.
Extraordinary teams are at the heart of our business strategy, but these don’t happen by chance.
They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment.
We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally.
WHO YOU’LL WORK WITH
Coro is Bain's persistent product development and engineering organization, building and operating the firm's proprietary digital solutions.
Coro brings together technology, data, and services to create differentiated value for Bain's clients and case teams.
This role sits within Coro's DevOps and Assurance team, part of the Next Generation Software Solutions (NGSS) department.
The team enables secure, efficient, and reliable delivery of technology across Bain's global ecosystem, focusing on both technical operations and platform assurance so that every deployment meets the firm's standards for quality, security, and compliance.
WHERE YOU’LL FIT WITHIN THE TEAM
The Staff Engineer owns the design, architecture, and long-term direction of cloud infrastructure and software delivery across Coro's DevOps and Assurance team.
Working alongside architects and backend engineers, this engineer sets the technical standard for how the team provisions infrastructure, ships software, and secures its platforms, and ensures those platforms scale as the build plan expands.
This is a critical foundational role in the early stages of the platform build, requiring both strong technical fundamentals and the pragmatism to make infrastructure decisions that support a fast-moving product team.
WHAT YOU’LL DO
Infrastructure Architecture & Automation – 30%
Own the design and evolution of cloud infrastructure built on Terraform and Terraform Cloud.
Define the module structure, state strategy, and remote backend conventions the rest of the team builds against.Architect Azure networking end to end: VNet/subnet topology, private endpoints, DNS resolution, NSG design, and Front Door Premium configuration across dev, demo, and production.Set the standard for provisioning Azure platform services (App Services, Azure SQL, Azure OpenAI, Container Registry (e.g.
Azure Container Registry, Cloudsmith), Key Vault, Entra ID, Storage Accounts / ADLS Gen2) and ensure environment parity by design.Own the automation roadmap for the team: identify manual, repetitive operational work, own the backlog of it, and drive it toward self-service and infrastructure-as-code so operational load trends down over time.Partner with Bain's central cloud and infrastructure teams to shape shared processes, tooling, and standards for operational work.Cloud & Platform Management (Azure) – 20%
Own Azure Kubernetes Service (AKS) architecture, including node pools, scaling strategy, spot instance usage, and workload connectivity to dependent services (databases, storage, AI services).Define identity and access architecture: Entra ID app registrations, managed identities, RBAC model, and integration with external IdPs (Okta).Set infrastructure standards for database platforms (Azure SQL Serverless, PostgreSQL Flexible Server, Cosmos DB), including connectivity, Entra auth, firewall rules, and private endpoints.Ensure platform reliability and robust access controls across all environments, and act as the senior escalation point for platform-level issues.CI/CD & Software Delivery – 15%
Define and own the CI/CD strategy using GitHub Actions for container builds, infrastructure deployments, and application releases, setting the patterns other engineers extend.Establish the container image lifecycle standard: build, scan, push to a container registry (e.g.
Azure Container Registry, Cloudsmith), and deploy to AKS or App Services.Design environment promotion workflows with appropriate gating, secrets management (Key Vault), and rollback strategies.Architect and operate GitHub-hosted private runners where required, including network integration with Azure VNets.Monitoring, Security & Assurance – 15%
Own the observability strategy using the team's monitoring stack (e.g.
Datadog, Azure Application Insights).
Define what the team monitors, alerts on, and how it optimizes cost and reliability.Lead the response to security findings: triage, containment, IAM scoping, container image CVE remediation, and endpoint hardening, and set the remediation standards others follow.Lead L2/L3 incident escalations, including root-cause analysis, user journey tracing, and log analysis, and drive the improvements that prevent recurrence.Define and enforce solution compliance across products: network isolation, least-privilege access, secrets hygiene, and deployment guardrails.Own the developer experience: set the standard for local development environments and deployment documentation so engineers across the distributed team can onboard quickly and operate with minimal infrastructure friction.Technical Leadership & Team Development – 20%
Lead and mentor DevOps engineers: set technical direction, review designs, grow the team's depth, and raise the bar on engineering practice.Anticipate the needs of stakeholders across NGSS and the wider business, and shape the platform roadmap proactively rather than reactively.Partner with architects, product engineers, and security teams to align on infrastructure standards and shape platform roadmaps across NGSS.Drive DevOps culture and automation-first thinking across the engineering organization, and lead knowledge sharing.Contribute to and often lead technical discovery, POCs, and innovation workstreams to validate new tools, technologies, and architectural patterns.
ABOUT YOU
Education & Experience
Bachelor's or Master's degree in Computer Science, Engineering, or a related technical field.7–9 years of experience in DevOps, infrastructure engineering, or cloud platform engineering, with time spent at a senior or staff level.Proven track record of architecting and operating cloud infrastructure in production at scale, owning technical decisions end to end.Demonstrated experience leading and mentoring DevOps or platform engineers in fast-paced product organizations.Professional Skills & Mindset
Excellent communication and collaboration skills, with the ability to translate complex technical topics for diverse stakeholders and to set direction others can follow.Proactive, analytical, and systematic, with strong problem-solving skills and the ability to trace issues across multiple layers (DNS, networking, identity, application).Results-driven with a strong bias for automation and continuous improvement, and a track record of driving operational load down over time.Comfortable owning ambiguity and working with limited direction: able to define standards and roadmaps where none exist yet, and to manage multiple stakeholders independently.Familiarity with Agile methodologies and a genuine commitment to team enablement and growth.Technical Expertise
Deep hands-on expertise with Terraform and Terraform Cloud (or equivalent): module design, state strategy, and remote backends at scale.Strong mastery of Azure services, including AKS, Networking (VNets, subnets, private endpoints, NSGs, DNS zones), App Services, Key Vault, Container Registry, and Storage Accounts.Deep experience with containerization technologies (Docker, Kubernetes) and container image lifecycle management.Expertise in roles, permissions, and IAM, particularly Microsoft Entra ID and Okta.Advanced CI/CD automation using GitHub Actions, Azure DevOps, and related DevOps toolchains, with the ability to define patterns for a team.Proficient in Linux administration and automation scripting (Bash, PowerShell, Python) for reusable workflows.Strong command of monitoring and observability platforms (e.g.
Datadog, Azure Application Insights).Deep familiarity with Azure private networking: private endpoints (blob, DFS, SQL, PostgreSQL), Private DNS Zones, and VNet integration for App Services and AKS.Command of database deployment and management from an infrastructure perspective, Azure SQL Serverless, PostgreSQL Flexible Server, and Cosmos DB.Strong foundation in security remediation: container CVE patching, IAM scoping, NSG/firewall tightening, and WAF/Front Door rule management.Preferred Qualifications
Professional certifications such as Azure DevOps Engineer Expert, Azure Administrator, Terraform Associate, or CKA (or equivalent).Experience owning multi-environment governance, cost optimization (FinOps), and compliance frameworks in cloud environments.Familiarity with Azure OpenAI, Cognitive Search, Databricks, and the integration of AI services into enterprise platforms.Experience with workflow orchestration tools (Airflow, or similar DAG/pipeline systems).Snowflake administration or connectivity from a DevOps lens.Experience with AI/ML observability tools such as LangSmith or Arize.Familiarity with AI coding assistants such as Cursor, Claude Code, or Codex to speed up development.