Senior DevOps Engineer / Terraform SME (AWS)
Job Summary
We are seeking a Senior DevOps Engineer with deep expertise in Terraform, HCP Terraform (Terraform Cloud), AWS security, and enterprise CI/CD automation. The ideal candidate will be a hands-on technical leader capable of driving Infrastructure-as-Code adoption, building secure cloud platforms, and leading DevOps workstreams in an enterprise AWS environment. The role requires strong technical depth, excellent communication skills, and the ability to work independently with customers and cross-functional engineering teams.
Please note, this role is not able to offer visa transfer or sponsorship now or in the future*
Responsibilities
What You’ll Do
Design build and maintain reusable Terraform modules with clear interfaces versioning and documentation so other teams can self-serve infrastructure safely
- Manage and optimize HCP Terraform workspaces using VCS-driven workflows - including workspace design variable sets run triggers and policy enforcement
- Provision and manage cloud resources (primarily AWS) following least-privilege access patterns and security best practices
- Manage secrets and sensitive configuration using HashiCorp Vault and/or AWS Secrets Manager
- Build and maintain CI/CD pipelines (GitHub Actions) with proper gating scanning testing and promotion workflows that integrate with HCP Terraform VCS-driven run model
- Conduct security reviews of infrastructure code and pipeline configurations
What You Bring
Must Have
- 5+ years of hands-on Terraform experience including writing modules with proper state management remote backends and provider configuration
- Hands-on Experience with HCP Terraform (Terraform Cloud) specifically VCS-driven workflows - workspace configuration speculative plans on PRs run approvals and managing workspace variables/variable sets
- Experience with HCP Terraform private registry for publishing and consuming internal modules
- Strong understanding of AWS IAM - policies roles trust relationships permission boundaries and service control policies
- Hands-on Experience with at least one secrets management platform: HashiCorp Vault or AWS Secrets Manager
- Solid understanding of OIDC and federated identity -how trust is established token exchange and practical application in CI/CD and cloud access
- Proven experience building and maintaining CI/CD pipelines in GitHub Actions or GitLab CI/CD including environment promotion approval gates and artifact management
- Security-first mindset - you default to deny scope permissions tightly and can articulate why
- Hands-on Experience using AI coding assistants (Amazon Q Kiro GitHub Copilot or similar) with a clear understanding of when to trust verify and override AI-generated output
- Commitment to human-in-the-loop practices code review manual approval gates for production and treating AI output as a draft - never as the final word
Nice to Have
- Experience with Sentinel within HCP Terraform
- Knowledge of infrastructure testing tools
- Contributions to internal developer platforms or self-service infrastructure tooling
Priority | Skill Area | Minimum Experience |
|---|---|---|
1 | Terraform & HCP Terraform (Terraform Cloud) | 5+ Years |
2 | AWS Security, IAM & Secrets Management | 5+ Years |
3 | CI/CD & DevOps Automation | 4+ Years |
Applications will be accepted until 7/28/2026
The annual salary for this position is between $100,000- $155,000 depending on experience and other qualifications of the successful candidate.
This position is also eligible for Cognizant’s discretionary annual incentive program, based on performance and is subject to the terms of Cognizant’s applicable plans.
Benefits: Cognizant offers the following benefits for this position, subject to applicable eligibility requirements:
· Medical/Dental/Vision/Life Insurance
· Paid holidays plus Paid Time Off
· 401(k) plan and contribution
· Long-term/Short-term Disability
· Paid Parental Leave
· Employee Stock Purchase Plan
Disclaimer: The salary, other compensation, and benefits information is accurate as of the date of this posting. Cognizant reserves the right to modify this information at any time, subject to applicable law.
À propos de Cognizant
Cognizant (NASDAQ : CTSH) est un AI Builder et une entreprise de services numériques (ESN) élaborant des solutions complètes d’IA maximisant les investissements pour des résultats concrets. Sa profonde expertise des métiers, des processus et des technologies lui permet d’intégrer dans les systèmes technologiques le contexte unique de chaque organisation de l’ingénierie à la production à l’échelle. Son objectif : améliorer l’efficacité des équipes, créer de la valeur et permettre aux grandes entreprises de rester performantes dans un monde qui évolue rapidement. Pour en savoir plus : cognizant.ai ou @cognizant.
Renseignments suppplémentaires sur l'emploi
Les informations sur la rémunération sont exactes à la date de publication. Cognizant se réserve le droit de modifier ces informations à tout moment, conformément aux lois applicables.
Les exigences linguistiques varient selon les postes, mais nous demandons à tous les candidats d’avoir une connaissance de base de l’anglais afin de faciliter les communications internes à l’échelle de l’entreprise. Pour les postes basés au Québec, une maîtrise de l’anglais est requise puisque vous fournirez des services et collaborerez avec des parties prenantes situées hors de la province, qui ne parlent pas nécessairement le français.
Cognizant est un employeur souscrivant au principe de l’égalité d’accès à l’emploi. Votre candidature et votre dossier ne seront pas examinés en fonction de la race, de la couleur, du sexe, de la religion, des croyances, de l'orientation sexuelle, de l'identité de genre, de l'origine nationale, du handicap, de l'information génétique, de la grossesse, du statut d'ancien combattant ou de toute autre caractéristique protégée telle que décrite par les lois fédérales, provinciales ou locales.
Si vous avez un handicap qui nécessite un aménagement raisonnable pour rechercher une offre d'emploi ou poser une candidature, envoyiez un courriel à [email protected] avec votre demande et vos coordonnées.











