Jobs and Careers
QT

Site Reliability and Security Engineer

QTS Data Centers
United Statesfull_timeVerifiedPosted 23 Nov 2025

About the role

The Senior Site Reliability and Security Engineer is responsible for ensuring the reliability, observability, and security posture of the QTS OS and SDP platforms deployed on AWS.

This role combines deep technical expertise in cloud operations and application-level security with leadership in incident response, production monitoring, and proactive threat detection.

The engineer will work closely with DevOps, backend, and application development teams to identify risks, resolve incidents, and drive continuous improvement in availability and security.

RESPONSIBILITIES

  • Monitor and analyze production environments for reliability, performance, and security risks across QTS OS and SDP platforms.
  • Lead troubleshooting of production incidents, guiding development teams to identify root causes and implement permanent fixes.
  • Collaborate with engineering teams to design and maintain robust observability practices — including metrics, logs, traces, and alerts — using AWS CloudWatch and related tools.
  • Identify and mitigate security threats across cloud infrastructure (IAM, Security Groups, VPC/PrivateLink, WAF) and application layers (API Gateway, Lambda, ECS).
  • Perform reviews of AWS IAM policies, roles, and network security configurations to detect privilege escalation or exposure risks.
  • Participate in and facilitate threat-modeling sessions with development teams.
  • Analyze code changes and 3rd-party dependencies to ensure alignment with internal security and compliance policies.
  • Partner with developers to design secure patterns for integrating new AWS services and frameworks.
  • Support incident response, participate in on-call rotation, and contribute to post-incident RCA documentation and follow-up actions.
  • Review service metrics, dashboards, and alarms to ensure coverage for critical user paths and backend systems.
  • Recommend and implement process improvements in monitoring, alerting, and escalation workflows.
  • Work with DevOps and architecture teams to assess the impact of new deployments on reliability and security posture.
  • Contribute to internal standards and best practices for secure and resilient system design.
  • Document technical findings, detection strategies, and mitigations for recurring risks.

Technical Expertise

  • AWS Services: ECS/Fargate, IAM, Security Groups, VPC/PrivateLink, WAF, Lambda, CloudWatch, S3, SQS/SNS, API Gateway, CloudFront.
  • Languages: Python, Java, TypeScript — with focus on scripting, automation, and code reviews for secure patterns.
  • Infrastructure & Tools: Terraform (IaC reviews and security validation), GitHub Actions (CI/CD observability).
  • Monitoring & Observability: AWS CloudWatch, CloudTrail, metrics/alarms configuration, log correlation, anomaly detection.
  • Security Practices: Threat modeling, SCA (Static Component Analysis), IAM least-privilege design, network isolation, runtime behavior analysis.
  • Incident Management: Root cause analysis, mitigation design, documentation, and coordination during live incidents.
  • Preferred familiarity: Snyk, CodeQL, AWS Config, or similar tools for vulnerability management.

BASIC QUALIFICATIONS

  • Bachelor’s degree in Computer Science, Engineering, or related field.
  • Due to the nature of systems and data supported, U.S. citizenship is required for this position.
  • 5+ years of experience supporting production systems in AWS, focusing on reliability or cloud security.
  • Strong understanding of AWS networking, IAM, and monitoring services.
  • Proven ability to guide teams during incident response and troubleshooting.
  • Demonstrated experience detecting and resolving infrastructure or application security risks.
  • Excellent diagnostic and analytical skills for complex distributed systems.

PREFERRED QUALIFICATIONS

  • Hands-on experience securing and monitoring large-scale AWS microservice deployments (ECS/Fargate).
  • Familiarity with automated dependency scanning, SCA tools, and security compliance monitoring.
  • Experience facilitating threat modeling sessions and implementing mitigation strategies.
  • Working knowledge of software development in Python, Java, or TypeScript.
  • Experience collaborating with DevOps and application teams to enforce secure SDLC p

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

QTS Data Centers

View company profile →