IT SYSTEMS ENGINEER SR
First Horizon Bank
**Platform Infrastructure Engineer – Infrastructure-as-Code** **Description:** As a Platform Infrastructure Engineer, you will be a crucial part of First Horizon's Infrastructure-as-Code team, building and operating the foundational infrastructure that...
Job description
**Responsibilities:**
- Leverage Engineering background and skills as an Infrastructure-as-Code Platform Engineer
- Design, develop, and maintain declarative infrastructure patterns using Crossplane and Helm to enable self-service cloud resource provisioning.
- Build, test, and version reusable IaC components (Compositions, Helm charts, Configuration Packages) within a common infrastructure framework.
- Understands Semantic versioning and release management as applied to infrastructure artifacts and chart repositories.
- Complete understanding of Software Development Lifecycle as it applies to infrastructure code
- Experience with breaking down infrastructure components into modular, composable, and version-controlled resources.
- Extensive understanding of Git branching methodologies and their impact on infrastructure code promotion across environments.
- Infrastructure-as-Code with Crossplane & Helm
- Design and maintain **Crossplane Compositions, CompositeResourceDefinitions (XRDs), and Claims** to provision and manage cloud resources as Kubernetes-native APIs.
- Build and publish reusable **Crossplane Configuration Packages** for self-service infrastructure consumption by development teams.
- Configure and manage **Crossplane Providers**, handling credentials securely through Kubernetes Secrets or external secret stores.
- Develop, version, and maintain **production-grade Helm charts** for internal services, platform components, and third-party tooling.
- Manage **Helm chart repositories** (OCI registries) and implement chart testing pipelines using **helm lint**, **helm unittest**, and **kubeconform**.
- Build Helm templating patterns that support **multi-environment, multi-cluster** deployments with values overlays and library charts.
- Implement **GitOps workflows** (ArgoCD or Flux) for continuous deployment of both Helm releases and Crossplane claims.
- Migrate legacy IaC (e.g., Terraform/HCL) toward **Crossplane-managed Kubernetes-native** resource models where appropriate.
- CI/CD & DevOps Platform Fluency
- Maintain a strong working understanding of CI/CD platforms and DevOps toolchains to ensure IaC components integrate seamlessly into existing build, test, and deployment pipelines.
- Collaborate with DevOps teams to embed infrastructure validation, policy checks, and drift detection into pipeline stages.
- Troubleshoot issues end-to-end across the infrastructure delivery chain (source, build, package, deploy, and runtime) in coordination with DevOps engineering.
- Support and evolve the IaC platform by:
- Supporting the full infrastructure lifecycle ensuring highly scalable and reliable service.
- Unit and integration testing of new and proposed infrastructure changes.
- Identifying deficiencies and applying solutions to infrastructure patterns through IaC principles and framework.
- Utilizing monitoring and observability to both troubleshoot infrastructure drift and provide feedback into the infrastructure development lifecycle.
- Understanding and promoting infrastructure and application Security best practices.
- Participating in on-call to support the IaC platform and underlying infrastructure.
- Authoring support documentation, runbooks, and user guides for internal teams consuming IaC resources.
- Work closely with Architects and Leads to understand infrastructure requirements and align with product and technology vision.
- Continuously explore and stay current on new and emerging IaC technologies, Kubernetes ecosystem tooling, and cloud provider capabilities.
---
**Required Knowledge and Experience:**
- Minimum 10 years of experience as a DevOps or Systems Engineer or a bachelor's degree and 6 years of experience.
- Kubernetes (Senior-Level Expertise) -
- Deep understanding of cluster architecture: control plane, etcd, kubelet, kube-proxy, and API server internals
- Helm and Kustomize
- CRDs, services, operators
- Advanced RBAC design, NetworkPolicies, PodSecurityAdmission, and admission controllers
- Multi-cluster management strategies and federation patterns
- Resource scheduling, quotas, LimitRanges, priority classes, and pod disruption budgets
- Troubleshooting node-level, networking (CNI, DNS, Ingress), and storage (CSI, PV/PVC) issues
- Cluster lifecycle management: upgrades, node pool rotation, and disaster recovery
- Performance tuning: HPA, VPA, KEDA, and resource right-sizing
- Familiarity with Rancher management server is a plus.
- Infrastructure-as-Code (Crossplane & Helm) -
- **Crossplane** — Compositions, XRDs, Claims, Providers, and Composition Functions
- **Upbound** as a managed Crossplane platform — Upbound Spaces, managed control planes, and the Upbound Marketplace for Providers and Configurations
- **Helm 3** — chart development from scratch, subcharts, library charts, values schema validation
- Experience managing Helm chart repositories (OCI registries)
- Understanding of Crossplane's continuous reconciliation model and drift detection
- Experience with **GitOps tooling** (ArgoCD or Flux) for deploying Helm releases and Crossplane resources
- Familiarity with **Open Policy Agent (OPA), Gatekeeper, or Kyverno** for IaC policy enforcement is a plus
- ArgoCD (Practitioner Usage) -
- Creating and managing Application resources and ApplicationSet resources
- Understanding of App of Apps pattern for organizing infrastructure deployments
- Configuring sync policies and sync waves for orchestrated rollouts
- Using Helm charts and Kustomize overlays as application sources
- Integrating ArgoCD applications with Git repositories for GitOps-driven delivery
- Monitoring application sync status, health checks, and troubleshooting failed syncs
- Understanding sync errors, drift detection, and manual vs. automated sync behavior
- Docker containers -
- dockerfile
- docker build, kaniko
- docker registry
- Source code management -
- Bitbucket (git)
- Github
- Git branching
- Code reviews and pull request approvals.
- Scripting Languages -
- bash
- python
- YAML
- Familiarity with PowerShell is a plus.
- Programming Languages -
- Go language
- Groovy
- YAML
- Ansible
- HCL - Terraform
- Crossplane Composition Functions (Go, Python, or KCL)
- Databases/Caches:
- MongoDB
- PostgreSQL
- Redis
- Azure SQL Server
- Productivity Tools
- Jira Software (scrum/Kanban Boards) or a similar ticketing system
- Confluence or a similar wiki tool
- Follow change control methodologies.
- Excellent communication skills and ability to collaborate with employees at all skill levels; including the ability to translate and communicate technical and analytical issues to all types of end users.
Top of Form
Bottom of Form