Engineering Systems Engineer - Azure DevOps Administration & Governance

Job Locations US-Remote
ID
2026-4353
Category
Engineering/Development
Type
Full Time

Overview

The Engineering Systems Engineer, Azure DevOps is the hands-on technical owner of Azure DevOps across the Engineering organization — the project and organization structure, boards, work item process, and access model that every engineer depends on every day, including the integration points that connect Azure DevOps to our GitHub-hosted repos (our source code lives in GitHub, not Azure Repos). Pipeline authoring and CI/CD ownership sit with the engineering teams that build them; this role owns everything else about how Azure DevOps is organized, governed, and accessed. This individual contributor owns Azure DevOps administration, governance, and continuous improvement end-to-end, and is the organization's go-to expert when Azure DevOps issues need to be diagnosed and resolved with authority.

 

This engineer is a proactive platform operator who identifies configuration drift and fragmented workflows before they become embedded patterns, closes governance gaps before they accumulate into technical debt, and automates manual administration work before it creates toil. When a team asks for a workaround, this person diagnoses the actual problem behind the request rather than bolting on a quick fix that adds to the fragmentation.

 

Beyond Azure DevOps, this role also supports the broader Engineering Systems platform portfolio — including LaunchDarkly feature flag operations, Flyway database migration standards, AI-assisted development tools like Cursor and Claude Code, and other tools the team takes on as needed — working alongside teammates who own those platforms and building the working knowledge needed to contribute to cross-platform initiatives. Azure DevOps ownership is the primary responsibility in this role; the rest of the portfolio is secondary and grows with tenure, and the specific list of “other tools” is expected to change over time.

 

This engineer leverages AI throughout their own workflow — using it to accelerate Azure DevOps platform analysis, generate automation scripts, produce enablement documentation, and surface insights from platform data that would take hours to find manually.

 

Starting base pay for this role is between $100,000 and $122,000. The actual base pay is dependent upon many factors, such as transferable skills, work experience, business needs, training, location, and market demands. The base pay range is subject to change and may be modified in the future. This role will be eligible for a bonus as well as competitive medical, dental, and vision benefits, wellness reimbursement, life insurance, and a 401(k) with company match. We offer vacation and sick leave benefits (under a flexible time off policy in most states).

Responsibilities

Azure DevOps Administration & Governance (45%)
• Owns day-to-day administration of Azure DevOps across the Engineering organization — managing
organizations, projects, teams, boards, area paths, iteration cadences, and access controls with the
consistency, precision, and configuration hygiene that a multi-team Engineering organization depends on.
Pipeline authoring and CI/CD configuration are owned by the engineering teams themselves, not this role.
• Takes command of ADO governance and standardization — establishing and enforcing project structure
standards, naming conventions, board configurations, and workflow approaches that prevent the
fragmentation that comes from ad hoc, admin-by-admin configuration choices.
• Reviews and manages workflow configuration requests from Engineering teams — diagnosing the actual
business problem behind each request, identifying root causes, and proposing better solutions rather than
band-aid fixes like unnecessary fields or workaround processes.
• Owns the administrative side of the Azure DevOps ↔ GitHub integration — repository links, GitHub
Apps/OAuth connections, and work item linking — that connect Azure DevOps Boards to our GitHub-
hosted repos, since our source code lives in GitHub rather than Azure Repos. Configuring pipeline-specific
service connections and triggers is owned by the teams that build those pipelines.
• Manages Azure DevOps user provisioning, permission models, and access reviews — ensuring access is
scoped to least-privilege principles, regularly audited, promptly revoked when no longer needed, and
documented to support compliance evidence requirements.
• Monitors Azure DevOps platform health, usage patterns, adoption metrics, and configuration drift —
proactively identifying workflow anomalies, over-provisioned permissions, and opportunities to
standardize before those gaps create friction or risk.
• Serves as the primary escalation point for Azure DevOps configuration issues — diagnosing platform-level
incidents, working with Microsoft support when required, and resolving disruptions with the urgency that a
platform used by every engineer in the organization demands.
• Leverages AI tools to accelerate platform analysis and administration work — including AI-assisted
workflow and governance configuration audits, AI-generated access audit summaries, and LLM-assisted
platform documentation that keeps governance records current and discoverable.


Automation & Scripting (15%)
• Continuously identifies and eliminates manual administration toil across Azure DevOps — building
PowerShell scripts, REST API automations, and workflow integrations that replace repetitive manual steps
with reliable, auditable automated processes.
• Develops and maintains monitoring and alerting for Azure DevOps platform health — including permission
anomalies, configuration drift detection, and provisioning issues — so that platform degradation is
detected and resolved proactively rather than reactively.
• Automates access review processes, provisioning workflows, and compliance documentation generation
— using scripting and AI tooling to maintain audit-ready governance records without proportional manual
overhead.
• Builds automation to enforce ADO standards — naming-convention checkers, board/process-template
validation scripts, and configuration-compliance automations that prevent non-standard workflows from
being deployed without a deliberate override.


Cross-Platform Support — Other Engineering Systems Tooling (15%)
• Administers and supports LaunchDarkly, Flyway, and Cursor/AI tooling operations — assisting with
provisioning, access controls, configuration governance, and platform health monitoring alongside the
teammate(s) who own each platform.
• Maintains unified provisioning standards, least-privilege access principles, and audit-ready access records
across Azure DevOps, LaunchDarkly, Flyway, and AI tooling, so governance discipline doesn't stop at the
ADO boundary.
• Monitors integration health across administered systems — SDK evaluation errors, migration failures, and
tooling provisioning issues — before they impact Engineering operations.
• Builds cross-platform fluency over time, with the expectation of taking on deeper ownership of a second
Engineering Systems platform domain — LaunchDarkly, Flyway, GitHub, or another tool the team adds to
the portfolio — as the role matures. The specific set of “other tools” is not fixed and will shift as the team's
responsibilities evolve.


Engineering Standards Administration (15%)
• Serves as the operational executor of the Engineering standards program — maintaining, publishing,
formatting, and distributing standards documentation for coding conventions, branching strategies, pull
request practices, code review requirements, and tooling usage as directed by the Engineering Systems
Manager.
• Owns the standards repository — ensuring documentation is accurately organized, consistently formatted,
discoverable through the Engineering knowledge base, and immediately updated when standards are
ratified or revised.
• Monitors Engineering standards adherence across teams — identifying non-compliance patterns in code
reviews, board and workflow configurations, branch naming, and tooling usage, and bringing specific, data-
backed observations to the Engineering Systems Manager and relevant Engineering Managers for follow-
through.
• Supports standards retrospectives led by the Engineering Systems Manager — collecting adherence data,
synthesizing engineering team feedback, and preparing materials that make retrospective sessions
productive rather than anecdotal.


Enablement & Documentation (10%)
• Builds and maintains internal enablement resources — ADO configuration guides, workflow standards
references, governance how-tos, and onboarding materials — that empower Engineering teams to work
within established standards correctly and independently, reducing the volume of repetitive support
requests.
• Maintains accurate, current platform configuration documentation and standards repositories — ensuring
governance requirements, workflow patterns, and access policies are clearly documented and accessible
to the Engineering organization.
• Coordinates the onboarding standards experience for new Engineers — maintaining environment setup
guides, tooling provisioning checklists, and standards orientation materials that are current, complete, and
effective enough to be executed without handholding.
• Tracks platform health, adoption metrics, support request trends, and standards compliance across
administered systems — maintaining the operational data the Engineering Systems Manager needs to
report accurately to the Director of Engineering Systems and to make informed investment decisions.


Access Management, Security & Compliance
• Maintains access control governance across all administered platforms — executing provisioning and de-
provisioning requests promptly, enforcing least-privilege access principles, and maintaining accurate
access records that support audit evidence requirements.
• Conducts and documents regular access reviews across Azure DevOps, LaunchDarkly, Flyway, and Cursor
— identifying over-provisioned accounts, stale access grants, and access policy violations, and resolving
them in partnership with the Engineering Systems Manager and Security team.
• Supports SOC 2, ISO/IEC 27001, and NIST 800-53 audit readiness by maintaining accurate, current
platform configuration records, access inventories, and change histories — treating audit evidence as an
ongoing operational discipline rather than a pre-audit scramble.
• Responds to security-related configuration hardening requests with urgency and precision, partnering with
the Security team on access-related incidents and policy enforcement actions.

Qualifications

  • Bachelor's Degree in Computer Science, Information Systems, Business Analysis, or a related field

 

Engineering Systems Engineer, Azure DevOps — Required Qualifications:

  • 2–4 years of hands-on Azure DevOps administration experience — including project configuration, access control
    governance, and multi-team organizational structures — with Azure DevOps as a primary, hands-on
    responsibility, not just usage as an end user.
  • Deep hands-on experience administering Azure DevOps — including project/org configuration, access control
    and permission models, and board/area path structure — at a depth sufficient to independently resolve platform
    configuration issues and act as an internal escalation point.
  • Strong scripting and automation skills — proficiency with PowerShell and/or REST APIs, and the ability to write
    reliable, maintainable automation scripts that other engineers can understand and modify.
  • Working knowledge of Git branching strategies, and familiarity with how Azure DevOps Boards and access
    controls connect to GitHub-hosted repositories — repository links, GitHub Apps/OAuth connections, branch
    policies, and status checks. Our source code lives in GitHub, not Azure Repos, so comfort bridging the two is
    important. Hands-on pipeline/YAML authoring is not required — pipelines are owned by the engineering teams
    themselves.
  • Demonstrated ability to diagnose the root cause behind a workflow request rather than implementing a band-aid
    fix — comfort proposing a better solution instead of the workaround that was asked for.
  • Experience managing access controls and user provisioning across engineering platforms with an understanding
    of least-privilege principles and compliance evidence requirements.
  • Strong organizational discipline and attention to detail — able to manage a high-traffic platform used by every
    engineer in the organization, maintain configuration hygiene, and track open items without dropping anything.
  • Clear written communication skills — able to produce platform documentation, enablement guides, and
    configuration records that are accurate and usable by engineering teams without requiring significant clarification.

Engineering Systems Engineer, Azure DevOps — Preferred Qualifications:

  • Exposure to, or willingness to learn, adjacent Engineering Systems platforms — feature flag management
    (LaunchDarkly), database migration tooling (Flyway), AI-assisted development tools (Cursor, Claude Code), or
    whatever other tools the team administers.
  • Demonstrated use of AI development tools such as Cursor or Claude Code in day-to-day technical work.
    Senior Engineering Systems Engineer, Azure DevOps — Required Qualifications:
  • 4–7 years of experience in Engineering Systems Administration, Platform Engineering, or DevOps, with
    demonstrated ownership of Azure DevOps at scale across multiple teams and projects.
  • Deep hands-on expertise in Azure DevOps — including complex multi-project/multi-org configurations, custom
    process templates, REST API/CLI-based automation, and integration with third-party tools such as GitHub.
  • Demonstrated experience building and owning Azure DevOps–centric automation — including workflow and
    process-template automation, access governance automation, and configuration drift detection — using Python,
    PowerShell, Bash, or equivalent scripting languages.
  • Demonstrated ability to design and enforce platform governance at scale — experience identifying configuration
    drift, preventing fragmentation, and establishing standards that teams adopt voluntarily because they solve real
    problems.
  • Experience contributing to Engineering standards programs — including drafting standards documentation,
    identifying standards gaps, and influencing adoption across multi-team engineering organizations.
  • Experience mentoring or coaching junior Platform Engineers — able to review Azure DevOps configurations,
    give structured technical feedback, and develop less experienced engineers into independently effective platform
    operators.
  • Strong familiarity with compliance requirements under SOC 2, ISO/IEC 27001, and NIST 800-53 in an
    engineering systems context — able to maintain audit-ready platform records and support evidence collection
    without requiring significant guidance.
  • A personal operating standard where the Azure DevOps environment they administer is better documented, more
    automated, and more reliably governed after six months of their ownership than it was when they took it on.

Benefits

  • Medical and Dental coverage available for employees, dependents, domestic partners, and spouses
  • Paid Time Off – Flexible options plus 10 paid company holidays where available**
  • All full-time positions are hybrid, with many eligible to be completely remote
  • Fully Paid by Origami Risk – Vision insurance, Short & Long-Term Disability Insurance, and Basic Life Insurance
  • Generous family leave options—including adoption and foster care placements
  • Pre-Tax Savings Accounts – Flexible Spending Account, Health Savings Account, Commuter Benefits, Dependent Care Savings Account
  • Retirement Savings – 401(k) with company match up to 4%
  • Employee Assistance Program (EAP) – Confidential & Free support offered to colleagues facing personal or work-related complications
  • Education Assistance Program – to help colleagues pursue industry/role-specific certifications
  • Wellness Benefits – reimbursement program to invest in healthy habits as well as support better colleague productivity and stress management
  • Additional coverages available – Pet Insurance, Critical Illness Insurance, and Voluntary Life & AD&D coverage
**Flexible PTO not available in California or the UK

Who We Are

Origami Risk delivers single-platform SaaS solutions that help organizations best navigate the complexities of risk, insurance, compliance, and safety management.

 

Founded by industry veterans who recognized the need for risk management technology that was more configurable, intuitive, and scalable, Origami continues to add to its innovative product offerings for managing both insurable and uninsurable risk; facilitating compliance; improving safety; and helping insurers, MGAs, TPAs, and brokers provide enhanced services that drive results.

 

A singular focus on client success underlies Origami’s approach to developing, implementing, and supporting our award-winning software solutions. 

 

Origami Risk is proud to be an equal opportunity employer. We thrive and benefit from diversity and are committed to creating an inclusive and equitable environment for all employees. We do not discriminate against any individual based upon race, religion, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, color, sex, national origin, age, marital status, military or veteran status, disability, or any other characteristic protected by applicable law.

 

Caution: Be alert to recruiting scams. We have received reports of individuals impersonating Origami Risk recruiters to deceive candidates into disclosing personal information. These impostors use fake Origami Risk domain names and email addresses. Please double-check that any email address from an Origami Risk recruiter ends with origamirisk.com or talent.icims.com. And to confirm the legitimacy of any recruiting communication, feel free to email transparencycheck@origamirisk.com.

Options

Sorry the Share function is not working properly at this moment. Please refresh the page and try again later.
Share on your newsfeed