The Engineering Systems Engineer, Azure DevOps is the hands-on technical owner of Azure DevOps across the Engineering organization — the project and organization structure, boards, work item process, and access model that every engineer depends on every day, including the integration points that connect Azure DevOps to our GitHub-hosted repos (our source code lives in GitHub, not Azure Repos). Pipeline authoring and CI/CD ownership sit with the engineering teams that build them; this role owns everything else about how Azure DevOps is organized, governed, and accessed. This individual contributor owns Azure DevOps administration, governance, and continuous improvement end-to-end, and is the organization's go-to expert when Azure DevOps issues need to be diagnosed and resolved with authority.
This engineer is a proactive platform operator who identifies configuration drift and fragmented workflows before they become embedded patterns, closes governance gaps before they accumulate into technical debt, and automates manual administration work before it creates toil. When a team asks for a workaround, this person diagnoses the actual problem behind the request rather than bolting on a quick fix that adds to the fragmentation.
Beyond Azure DevOps, this role also supports the broader Engineering Systems platform portfolio — including LaunchDarkly feature flag operations, Flyway database migration standards, AI-assisted development tools like Cursor and Claude Code, and other tools the team takes on as needed — working alongside teammates who own those platforms and building the working knowledge needed to contribute to cross-platform initiatives. Azure DevOps ownership is the primary responsibility in this role; the rest of the portfolio is secondary and grows with tenure, and the specific list of “other tools” is expected to change over time.
This engineer leverages AI throughout their own workflow — using it to accelerate Azure DevOps platform analysis, generate automation scripts, produce enablement documentation, and surface insights from platform data that would take hours to find manually.
Starting base pay for this role is between $100,000 and $122,000. The actual base pay is dependent upon many factors, such as transferable skills, work experience, business needs, training, location, and market demands. The base pay range is subject to change and may be modified in the future. This role will be eligible for a bonus as well as competitive medical, dental, and vision benefits, wellness reimbursement, life insurance, and a 401(k) with company match. We offer vacation and sick leave benefits (under a flexible time off policy in most states).
Azure DevOps Administration & Governance (45%)
• Owns day-to-day administration of Azure DevOps across the Engineering organization — managing
organizations, projects, teams, boards, area paths, iteration cadences, and access controls with the
consistency, precision, and configuration hygiene that a multi-team Engineering organization depends on.
Pipeline authoring and CI/CD configuration are owned by the engineering teams themselves, not this role.
• Takes command of ADO governance and standardization — establishing and enforcing project structure
standards, naming conventions, board configurations, and workflow approaches that prevent the
fragmentation that comes from ad hoc, admin-by-admin configuration choices.
• Reviews and manages workflow configuration requests from Engineering teams — diagnosing the actual
business problem behind each request, identifying root causes, and proposing better solutions rather than
band-aid fixes like unnecessary fields or workaround processes.
• Owns the administrative side of the Azure DevOps ↔ GitHub integration — repository links, GitHub
Apps/OAuth connections, and work item linking — that connect Azure DevOps Boards to our GitHub-
hosted repos, since our source code lives in GitHub rather than Azure Repos. Configuring pipeline-specific
service connections and triggers is owned by the teams that build those pipelines.
• Manages Azure DevOps user provisioning, permission models, and access reviews — ensuring access is
scoped to least-privilege principles, regularly audited, promptly revoked when no longer needed, and
documented to support compliance evidence requirements.
• Monitors Azure DevOps platform health, usage patterns, adoption metrics, and configuration drift —
proactively identifying workflow anomalies, over-provisioned permissions, and opportunities to
standardize before those gaps create friction or risk.
• Serves as the primary escalation point for Azure DevOps configuration issues — diagnosing platform-level
incidents, working with Microsoft support when required, and resolving disruptions with the urgency that a
platform used by every engineer in the organization demands.
• Leverages AI tools to accelerate platform analysis and administration work — including AI-assisted
workflow and governance configuration audits, AI-generated access audit summaries, and LLM-assisted
platform documentation that keeps governance records current and discoverable.
Automation & Scripting (15%)
• Continuously identifies and eliminates manual administration toil across Azure DevOps — building
PowerShell scripts, REST API automations, and workflow integrations that replace repetitive manual steps
with reliable, auditable automated processes.
• Develops and maintains monitoring and alerting for Azure DevOps platform health — including permission
anomalies, configuration drift detection, and provisioning issues — so that platform degradation is
detected and resolved proactively rather than reactively.
• Automates access review processes, provisioning workflows, and compliance documentation generation
— using scripting and AI tooling to maintain audit-ready governance records without proportional manual
overhead.
• Builds automation to enforce ADO standards — naming-convention checkers, board/process-template
validation scripts, and configuration-compliance automations that prevent non-standard workflows from
being deployed without a deliberate override.
Cross-Platform Support — Other Engineering Systems Tooling (15%)
• Administers and supports LaunchDarkly, Flyway, and Cursor/AI tooling operations — assisting with
provisioning, access controls, configuration governance, and platform health monitoring alongside the
teammate(s) who own each platform.
• Maintains unified provisioning standards, least-privilege access principles, and audit-ready access records
across Azure DevOps, LaunchDarkly, Flyway, and AI tooling, so governance discipline doesn't stop at the
ADO boundary.
• Monitors integration health across administered systems — SDK evaluation errors, migration failures, and
tooling provisioning issues — before they impact Engineering operations.
• Builds cross-platform fluency over time, with the expectation of taking on deeper ownership of a second
Engineering Systems platform domain — LaunchDarkly, Flyway, GitHub, or another tool the team adds to
the portfolio — as the role matures. The specific set of “other tools” is not fixed and will shift as the team's
responsibilities evolve.
Engineering Standards Administration (15%)
• Serves as the operational executor of the Engineering standards program — maintaining, publishing,
formatting, and distributing standards documentation for coding conventions, branching strategies, pull
request practices, code review requirements, and tooling usage as directed by the Engineering Systems
Manager.
• Owns the standards repository — ensuring documentation is accurately organized, consistently formatted,
discoverable through the Engineering knowledge base, and immediately updated when standards are
ratified or revised.
• Monitors Engineering standards adherence across teams — identifying non-compliance patterns in code
reviews, board and workflow configurations, branch naming, and tooling usage, and bringing specific, data-
backed observations to the Engineering Systems Manager and relevant Engineering Managers for follow-
through.
• Supports standards retrospectives led by the Engineering Systems Manager — collecting adherence data,
synthesizing engineering team feedback, and preparing materials that make retrospective sessions
productive rather than anecdotal.
Enablement & Documentation (10%)
• Builds and maintains internal enablement resources — ADO configuration guides, workflow standards
references, governance how-tos, and onboarding materials — that empower Engineering teams to work
within established standards correctly and independently, reducing the volume of repetitive support
requests.
• Maintains accurate, current platform configuration documentation and standards repositories — ensuring
governance requirements, workflow patterns, and access policies are clearly documented and accessible
to the Engineering organization.
• Coordinates the onboarding standards experience for new Engineers — maintaining environment setup
guides, tooling provisioning checklists, and standards orientation materials that are current, complete, and
effective enough to be executed without handholding.
• Tracks platform health, adoption metrics, support request trends, and standards compliance across
administered systems — maintaining the operational data the Engineering Systems Manager needs to
report accurately to the Director of Engineering Systems and to make informed investment decisions.
Access Management, Security & Compliance
• Maintains access control governance across all administered platforms — executing provisioning and de-
provisioning requests promptly, enforcing least-privilege access principles, and maintaining accurate
access records that support audit evidence requirements.
• Conducts and documents regular access reviews across Azure DevOps, LaunchDarkly, Flyway, and Cursor
— identifying over-provisioned accounts, stale access grants, and access policy violations, and resolving
them in partnership with the Engineering Systems Manager and Security team.
• Supports SOC 2, ISO/IEC 27001, and NIST 800-53 audit readiness by maintaining accurate, current
platform configuration records, access inventories, and change histories — treating audit evidence as an
ongoing operational discipline rather than a pre-audit scramble.
• Responds to security-related configuration hardening requests with urgency and precision, partnering with
the Security team on access-related incidents and policy enforcement actions.
Engineering Systems Engineer, Azure DevOps — Required Qualifications:
Engineering Systems Engineer, Azure DevOps — Preferred Qualifications:
Origami Risk delivers single-platform SaaS solutions that help organizations best navigate the complexities of risk, insurance, compliance, and safety management.
Founded by industry veterans who recognized the need for risk management technology that was more configurable, intuitive, and scalable, Origami continues to add to its innovative product offerings for managing both insurable and uninsurable risk; facilitating compliance; improving safety; and helping insurers, MGAs, TPAs, and brokers provide enhanced services that drive results.
A singular focus on client success underlies Origami’s approach to developing, implementing, and supporting our award-winning software solutions.
Origami Risk is proud to be an equal opportunity employer. We thrive and benefit from diversity and are committed to creating an inclusive and equitable environment for all employees. We do not discriminate against any individual based upon race, religion, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, color, sex, national origin, age, marital status, military or veteran status, disability, or any other characteristic protected by applicable law.
Caution: Be alert to recruiting scams. We have received reports of individuals impersonating Origami Risk recruiters to deceive candidates into disclosing personal information. These impostors use fake Origami Risk domain names and email addresses. Please double-check that any email address from an Origami Risk recruiter ends with origamirisk.com or talent.icims.com. And to confirm the legitimacy of any recruiting communication, feel free to email transparencycheck@origamirisk.com.
Software Powered by ICIMS
www.icims.com