Design, implement, and maintain the automated pipelines that build, harden, scan, and distribute container images (GCIs, GCRIs) and machine images (GAMIs) to 12 AWS regions on a continuous basis.
Own certificate lifecycle infrastructure — issuance, renewal, revocation, and policy enforcement — for thousands of internal TLS/mTLS endpoints across GoDaddy.
Drive security posture improvements: CVE triage, remediation SLA enforcement, SBOM generation, and supply-chain hardening for GoDaddy's foundational compute images.
Architect and operate event-driven, serverless AWS infrastructure (Lambda, SQS, EventBridge, DynamoDB, ECR) powering the image build and certificate management systems.
Identify and eliminate toil through automation — build-trigger intelligence, upstream change detection, certificate expiry monitoring, and usage analytics.
Define and socialize the architectural direction for next-generation platform capabilities, from private CA adoption to runtime image governance.
10+ years of software engineering experience, with depth in Python (3.10+) and at least one of Go, TypeScript/Node.js, or Bash for systems and infrastructure automation.
Strong command of containerization — building, layering, hardening, and debugging Docker images across multiple architectures (amd64/arm64); familiarity with multi-stage builds, base image governance, and ECR.
Hands-on experience with AWS services at production scale: Lambda, ECR, DynamoDB, SQS, EventBridge, IAM, SSM, and Secrets Manager.
Qualification
Bachelor of Science in Computer ScienceBackground in container securityKubernetes experience is a plusAI will not be used to screen
Required
Proficiency with infrastructure as code — AWS CDK (Python or TypeScript) or CloudFormation/Sceptre — including stateful resource management, multi-region deployments, and least-privilege IAM design.
Solid understanding of TLS/PKI fundamentals: certificate types (DV, EV, client vs. server, mTLS), certificate lifecycle management, CA trust chains, and key storage.
Bachelor of Science in Computer Science, Computer Engineering, Information Systems, or Math.
Experience operating or migrating to a private certificate authority — issuance policy, trust distribution, and multi-platform CA bundle management.
Background in container security: SBOM generation, CVE lifecycle management, image scanning tools (AWS Inspector, Prisma Cloud, or equivalent), and remediation SLA programs.
Familiarity with supply-chain security concepts: provenance, signing, SLSA frameworks, or similar.
Kubernetes experience is a plus; experience with multi-account, multi-region AWS organization management is particularly valuable.
AI will not be used to screen, assess or select applicants other than as set out in the details in the application below.