First Horizon Bank Logo

First Horizon Bank

IT SYSTEMS ENGINEER SR

Posted 10 Hours Ago
Be an Early Applicant
In-Office
Charlotte, NC, USA
Senior level
In-Office
Charlotte, NC, USA
Senior level
Designs and operates an Infrastructure-as-Code platform using Crossplane, Helm, Kubernetes, and GitOps. Builds reusable Crossplane compositions, resource definitions, configuration packages, and production Helm charts for self-service cloud provisioning. Integrates infrastructure validation, policy enforcement, testing, drift detection, and CI/CD workflows. Troubleshoots Kubernetes and infrastructure delivery issues, supports platform reliability and on-call operations, and creates documentation for internal engineering teams.
The summary above was generated by AI

Platform Infrastructure Engineer – Infrastructure-as-Code

Description:

As a Platform Infrastructure Engineer, you will be a crucial part of First Horizon's Infrastructure-as-Code team, building and operating the foundational infrastructure that powers the organization's developer and cloud experience. Your primary focus will be designing, implementing, and managing Infrastructure-as-Code to deliver self-service, declarative cloud resource provisioning through Kubernetes-native APIs. Leveraging senior-level Kubernetes expertise, you will define reusable infrastructure patterns, author declarative resource definitions, and build composable templates that enable development teams to provision and manage cloud resources consistently, securely, and at scale. You will collaborate closely with Architects and engineering teams to evolve the platform from manual and imperative workflows toward a fully GitOps-driven, policy-governed infrastructure model — ensuring reliability, repeatability, and compliance across all environments.

Responsibilities:

  • Leverage Engineering background and skills as an Infrastructure-as-Code Platform Engineer
    • Design, develop, and maintain declarative infrastructure patterns using Crossplane and Helm to enable self-service cloud resource provisioning.
    • Build, test, and version reusable IaC components (Compositions, Helm charts, Configuration Packages) within a common infrastructure framework.
    • Understands Semantic versioning and release management as applied to infrastructure artifacts and chart repositories.
  • Complete understanding of Software Development Lifecycle as it applies to infrastructure code
    • Experience with breaking down infrastructure components into modular, composable, and version-controlled resources.
    • Extensive understanding of Git branching methodologies and their impact on infrastructure code promotion across environments.
  • Infrastructure-as-Code with Crossplane & Helm
    • Design and maintain Crossplane Compositions, CompositeResourceDefinitions (XRDs), and Claims to provision and manage cloud resources as Kubernetes-native APIs.
    • Build and publish reusable Crossplane Configuration Packages for self-service infrastructure consumption by development teams.
    • Configure and manage Crossplane Providers, handling credentials securely through Kubernetes Secrets or external secret stores.
    • Develop, version, and maintain production-grade Helm charts for internal services, platform components, and third-party tooling.
    • Manage Helm chart repositories (OCI registries) and implement chart testing pipelines using helm linthelm unittest, and kubeconform.
    • Build Helm templating patterns that support multi-environment, multi-cluster deployments with values overlays and library charts.
    • Implement GitOps workflows (ArgoCD or Flux) for continuous deployment of both Helm releases and Crossplane claims.
    • Migrate legacy IaC (e.g., Terraform/HCL) toward Crossplane-managed Kubernetes-native resource models where appropriate.
  • CI/CD & DevOps Platform Fluency
    • Maintain a strong working understanding of CI/CD platforms and DevOps toolchains to ensure IaC components integrate seamlessly into existing build, test, and deployment pipelines.
    • Collaborate with DevOps teams to embed infrastructure validation, policy checks, and drift detection into pipeline stages.
    • Troubleshoot issues end-to-end across the infrastructure delivery chain (source, build, package, deploy, and runtime) in coordination with DevOps engineering.
  • Support and evolve the IaC platform by:
    • Supporting the full infrastructure lifecycle ensuring highly scalable and reliable service.
    • Unit and integration testing of new and proposed infrastructure changes.
    • Identifying deficiencies and applying solutions to infrastructure patterns through IaC principles and framework.
    • Utilizing monitoring and observability to both troubleshoot infrastructure drift and provide feedback into the infrastructure development lifecycle.
    • Understanding and promoting infrastructure and application Security best practices.
    • Participating in on-call to support the IaC platform and underlying infrastructure.
    • Authoring support documentation, runbooks, and user guides for internal teams consuming IaC resources.
  • Work closely with Architects and Leads to understand infrastructure requirements and align with product and technology vision.
  • Continuously explore and stay current on new and emerging IaC technologies, Kubernetes ecosystem tooling, and cloud provider capabilities.

Required Knowledge and Experience:

  • Minimum 10 years of experience as a DevOps or Systems Engineer or a bachelor's degree and 6 years of experience.
  • Kubernetes (Senior-Level Expertise) -
    • Deep understanding of cluster architecture: control plane, etcd, kubelet, kube-proxy, and API server internals
    • Helm and Kustomize
    • CRDs, services, operators
    • Advanced RBAC design, NetworkPolicies, PodSecurityAdmission, and admission controllers
    • Multi-cluster management strategies and federation patterns
    • Resource scheduling, quotas, LimitRanges, priority classes, and pod disruption budgets
    • Troubleshooting node-level, networking (CNI, DNS, Ingress), and storage (CSI, PV/PVC) issues
    • Cluster lifecycle management: upgrades, node pool rotation, and disaster recovery
    • Performance tuning: HPA, VPA, KEDA, and resource right-sizing
    • Familiarity with Rancher management server is a plus.
  • Infrastructure-as-Code (Crossplane & Helm) -
    • Crossplane — Compositions, XRDs, Claims, Providers, and Composition Functions
    • Upbound as a managed Crossplane platform — Upbound Spaces, managed control planes, and the Upbound Marketplace for Providers and Configurations
    • Helm 3 — chart development from scratch, subcharts, library charts, values schema validation
    • Experience managing Helm chart repositories (OCI registries)
    • Understanding of Crossplane's continuous reconciliation model and drift detection
    • Experience with GitOps tooling (ArgoCD or Flux) for deploying Helm releases and Crossplane resources
    • Familiarity with Open Policy Agent (OPA), Gatekeeper, or Kyverno for IaC policy enforcement is a plus
  • ArgoCD (Practitioner Usage) -
    • Creating and managing Application resources and ApplicationSet resources
    • Understanding of App of Apps pattern for organizing infrastructure deployments
    • Configuring sync policies and sync waves for orchestrated rollouts
    • Using Helm charts and Kustomize overlays as application sources
    • Integrating ArgoCD applications with Git repositories for GitOps-driven delivery
    • Monitoring application sync status, health checks, and troubleshooting failed syncs
    • Understanding sync errors, drift detection, and manual vs. automated sync behavior
  • Docker containers -
    • dockerfile
    • docker build, kaniko
    • docker registry
  • Source code management -
    • Bitbucket (git)
    • Github
    • Git branching
    • Code reviews and pull request approvals.
  • Scripting Languages -
    • bash
    • python
    • YAML
    • Familiarity with PowerShell is a plus.
  • Programming Languages -
    • Go language
    • Groovy
    • YAML
    • Ansible
    • HCL - Terraform
    • Crossplane Composition Functions (Go, Python, or KCL)
  • Databases/Caches:
    • MongoDB
    • PostgreSQL
    • Redis
    • Azure SQL Server
  • Productivity Tools
    • Jira Software (scrum/Kanban Boards) or a similar ticketing system
    • Confluence or a similar wiki tool
    • Follow change control methodologies.
  • Excellent communication skills and ability to collaborate with employees at all skill levels; including the ability to translate and communicate technical and analytical issues to all types of end users.

Top of Form

Bottom of Form

 

First Horizon Bank Charlotte, North Carolina, USA Office

Charlotte, United States

Similar Jobs

4 Minutes Ago
Hybrid
15-20 Hourly
Entry level
15-20 Hourly
Entry level
eCommerce • Fashion • Retail • Sales • Wearables • Design
Provides personalized styling and product recommendations, builds customer relationships, drives sales, completes POS transactions, and maintains stockroom and sales-floor operations. Requires retail selling experience, strong communication, teamwork, flexibility for varied schedules, social media awareness, and the ability to lift up to 50 pounds occasionally.
Top Skills: Omni-Channel/Virtual Selling ToolsPos SystemsSocial Media
13 Minutes Ago
In-Office
Senior level
Senior level
Healthtech • Logistics • Pharmaceutical
Leads proactive threat hunting within a Security Operations Center, investigating adversarial activity and improving detection, response, monitoring, and security controls. Responsibilities include researching emerging threats, developing SIEM, EDR, and SOAR detection methodologies, performing security gap assessments, correlating security data, supporting incident response and recovery, enhancing alerting, and briefing stakeholders on critical risks.
Top Skills: EdrGoLinuxmacOSMitre Att&CkPowershellPythonSIEMSoarWindows
27 Minutes Ago
Easy Apply
Hybrid
Easy Apply
95K-120K Annually
Mid level
95K-120K Annually
Mid level
Marketing Tech • Mobile • Software
Manage enterprise customer relationships for Braze, serving as a trusted advisor and primary contact. Partner with Account Executives to drive renewals, retention, and expansion; develop success plans; increase feature adoption; analyze product usage; conduct business reviews; provide enablement and nontechnical support; gather customer feedback; coordinate cross-functional teams; and transition customers from onboarding to ongoing success. The role may include onsite customer meetings and international travel.
Top Skills: APIsHTMLMarketing AnalyticsMarketing AutomationMobileSaaS

What you need to know about the Charlotte Tech Scene

Ranked among the hottest tech cities in 2024 by CompTIA, Charlotte is quickly cementing its place as a major U.S. tech hub. Home to more than 90,000 tech workers, the city’s ecosystem is primed for continued growth, fueled by billions in annual funding from heavyweights like Microsoft and RevTech Labs, which has created thousands of fintech jobs and made the city a go-to for tech pros looking for their next big opportunity.

Key Facts About Charlotte Tech

  • Number of Tech Workers: 90,859; 6.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lowe’s, Bank of America, TIAA, Microsoft, Honeywell
  • Key Industries: Fintech, artificial intelligence, cybersecurity, cloud computing, e-commerce
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (CED)
  • Notable Investors: Microsoft, Google, Falfurrias Management Partners, RevTech Labs Foundation
  • Research Centers and Universities: University of North Carolina at Charlotte, Northeastern University, North Carolina Research Campus

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account