Lead Cloud Engineer
This is a Non-Employee Contingent Worker Role providing services for TIAA’s family of companies and will be employed by TIAA's preferred 3rd Party Supplier. As a Non-Employee CW, perform a variety of moderately complex business planning, support, and project-related duties. Demonstrates an exceptional standard of quality and holds themselves accountable to achieving excellent results.
This role will sit onsite, likely in a hybrid capacity, at the location(s) listed in this posting.
The anticipated term of this engagement will be 14 months. This term could be extended based on company business needs.CW-Info Systems Engineer IVThe Engineering job designs information systems that are appropriate for users' needs and consistent with the overall design of the organization's information systems architecture. Under limited supervision, this job is responsible for the installation, configuration and maintenance of the organization's operating systems.
Key Responsibilities and Duties
- Formulates system scope through research and fact-finding to develop or modify moderately complex information systems.
- Evaluates and implements changes to existing system logic difficulties and documentation as necessary.
- Reviews flow charts, models, and procedures and feasibility studies to design possible system solutions.
- Reviews technical documentation to guide system users and to assist with the ongoing operation, maintenance, and development of the system.
- Collaborates with system analysts, engineers, and programmers to design systems and to determine project limitations and capabilities, performance requirements, systems performance standards, and interfaces.
- Identifies and documents all system constraints, implications and consequences of various proposed system changes.
- Educates end users on system designs and functionalities through creation of training materials and conducting demos.
- Evaluates the efficiency and effectiveness of application operations and troubleshooting problems.
- University (Degree) Preferred
- 5+ Years Required; 7+ Years Preferred
- Physical Requirements: Sedentary Work
Career Level
8IC
This role will serve as the primary technical builder and delivery owner for PIVOT, an initiative to automate vulnerability management, patching, access governance, and configuration compliance across the Data Protection and Storage platform estate, including PPDM, Data Domain, Avamar, Rubrik, and NetApp ONTAP. This is a hands-on engineering role, converting existing prototypes into production-grade automation on a compressed 60–90 day delivery timeline.
Responsibilities:
- Build orchestrated patching playbooks with pre/post validation for PPDM, Data Domain, Avamar, Rubrik, and ONTAP, enabling on-disclosure CVE remediation
- Develop a CVE-to-asset correlation service against live platform inventory
- Build scheduled backup posture validation covering immutability, retention locks, replication, and anti-ransomware controls; advance existing prototypes to production
- Implement configuration drift detection using ActiveIQ and ONTAP REST APIs, with automated baselines for top security-critical settings (FIPS, encryption-at-rest, audit logging, export policies)
- Build automated deprovisioning workflows for backup admin access tied to HR/IAM events
- Integrate vault-based credential rotation for backup automation service accounts
- Produce audit-ready documentation and evidence artifacts for each automated control
Qualifications:
Required:
- 7+ years of relevant IT experience, with significant hands-on work in data protection, backup and storage infrastructure
- Demonstrated hands-on experience administering and engineering solutions on PPDM, Data Domain, ECS, Rubrik, and/or NetApp ONTAP in enterprise environments
- Proven experience building automation and orchestration tooling (scripting, APIs, playbooks)
- Working knowledge of vulnerability management concepts, including CVE tracking, patch cycles, and asset correlation
- Experience with REST API integration, particularly with NetApp ActiveIQ and/or ONTAP APIs
- Experience with credential vaulting and automated secrets/credential rotation (e.g., CyberArk, HashiCorp Vault, or similar)
- Strong scripting ability (PowerShell, Python, or similar) for building integrations and automation
- Demonstrated ability to work independently and deliver production-grade solutions under compressed timelines
- Experience producing technical documentation and audit/compliance evidence artifacts
Preferred:
- Bachelor's degree in Information Technology, Computer Science, or related technical field
- Vendor certifications relevant to Dell PowerProtect (PPDM/Data Domain/ECS), Rubrik, or NetApp platforms
- Experience with security configuration baselining and drift detection tooling
- Familiarity with FIPS compliance, encryption-at-rest standards, and audit logging requirements in enterprise storage environments
- Experience integrating with IAM/HR systems (e.g., SailPoint, Workday, ServiceNow) for automated provisioning/deprovisioning
- Experience with anti-ransomware and immutability controls in backup environments (retention lock, replication validation)
- Familiarity with CI/CD pipelines or infrastructure-as-code practices as applied to automation delivery
- Strong stakeholder communication skills, with ability to translate technical automation work into audit-ready evidence and business-facing status updates
Anticipated Posting End Date:
2026-09-11Base Pay Range: $50.43/hr - $81.59/hrActual base salary may vary based upon, but not limited to, relevant experience, time in role, base salary of internal peers, prior performance, business sector, and geographic location.
_____________________________________________________________________________________________________
Equal Opportunity
We are an Equal Opportunity Employer. TIAA does not discriminate against any candidate or employee on the basis of age, race, color, national origin, sex, religion, veteran status, disability, sexual orientation, gender identity, or any other legally protected status.
Our full EEO & Non-Discrimination statement is on our careers home page, and you can read more about your rights and view government notices here.
Accessibility Support
TIAA offers support for those who need assistance with our online application process to provide an equal employment opportunity to all job seekers, including individuals with disabilities.
If you are a U.S. applicant and desire a reasonable accommodation to complete a job application please use one of the below options to contact our accessibility support team:
Phone: (800) 842-2755
Email: accessibility.support@tiaa.org
Drug and Smoking Policy
TIAA maintains a drug-free and smoke/free workplace.
Privacy Notices
For Applicants of TIAA, Nuveen and Affiliates residing in US (other than California), click here.
For Applicants of TIAA, Nuveen and Affiliates residing in California, please click here.
For Applicants of TIAA Global Capabilities, click here.
For Applicants of Nuveen residing in Europe and APAC, please click here.