Engineering Systems Engineer - Azure DevOps Administration & Governance
Overview
The Engineering Systems Engineer, Azure DevOps is the hands-on technical owner of Azure DevOps across the Engineering organization — the project and organization structure, boards, work item process, and access model that every engineer depends on every day, including the integration points that connect Azure DevOps to our GitHub-hosted repos (our source code lives in GitHub, not Azure Repos). Pipeline authoring and CI/CD ownership sit with the engineering teams that build them; this role owns everything else about how Azure DevOps is organized, governed, and accessed. This individual contributor owns Azure DevOps administration, governance, and continuous improvement end-to-end, and is the organization's go-to expert when Azure DevOps issues need to be diagnosed and resolved with authority.
This engineer is a proactive platform operator who identifies configuration drift and fragmented workflows before they become embedded patterns, closes governance gaps before they accumulate into technical debt, and automates manual administration work before it creates toil. When a team asks for a workaround, this person diagnoses the actual problem behind the request rather than bolting on a quick fix that adds to the fragmentation.
Beyond Azure DevOps, this role also supports the broader Engineering Systems platform portfolio — including LaunchDarkly feature flag operations, Flyway database migration standards, AI-assisted development tools like Cursor and Claude Code, and other tools the team takes on as needed — working alongside teammates who own those platforms and building the working knowledge needed to contribute to cross-platform initiatives. Azure DevOps ownership is the primary responsibility in this role; the rest of the portfolio is secondary and grows with tenure, and the specific list of “other tools” is expected to change over time.
This engineer leverages AI throughout their own workflow — using it to accelerate Azure DevOps platform analysis, generate automation scripts, produce enablement documentation, and surface insights from platform data that would take hours to find manually.
Starting base pay for this role is between $100,000 and $122,000. The actual base pay is dependent upon many factors, such as transferable skills, work experience, business needs, training, location, and market demands. The base pay range is subject to change and may be modified in the future. This role will be eligible for a bonus as well as competitive medical, dental, and vision benefits, wellness reimbursement, life insurance, and a 401(k) with company match. We offer vacation and sick leave benefits (under a flexible time off policy in most states).
Responsibilities
Azure DevOps Administration & Governance (45%)• Owns day-to-day administration of Azure DevOps across the Engineering organization — managingorganizations, projects, teams, boards, area paths, iteration cadences, and access controls with theconsistency, precision, and configuration hygiene that a multi-team Engineering organization depends on.Pipeline authoring and CI/CD configuration are owned by the engineering teams themselves, not this role.• Takes command of ADO governance and standardization — establishing and enforcing project structurestandards, naming conventions, board configurations, and workflow approaches that prevent thefragmentation that comes from ad hoc, admin-by-admin configuration choices.• Reviews and manages workflow configuration requests from Engineering teams — diagnosing the actualbusiness problem behind each request, identifying root causes, and proposing better solutions rather thanband-aid fixes like unnecessary fields or workaround processes.• Owns the administrative side of the Azure DevOps ↔ GitHub integration — repository links, GitHubApps/OAuth connections, and work item linking — that connect Azure DevOps Boards to our GitHub-hosted repos, since our source code lives in GitHub rather than Azure Repos. Configuring pipeline-specificservice connections and triggers is owned by the teams that build those pipelines.• Manages Azure DevOps user provisioning, permission models, and access reviews — ensuring access isscoped to least-privilege principles, regularly audited, promptly revoked when no longer needed, anddocumented to support compliance evidence requirements.• Monitors Azure DevOps platform health, usage patterns, adoption metrics, and configuration drift —proactively identifying workflow anomalies, over-provisioned permissions, and opportunities tostandardize before those gaps create friction or risk.• Serves as the primary escalation point for Azure DevOps configuration issues — diagnosing platform-levelincidents, working with Microsoft support when required, and resolving disruptions with the urgency that aplatform used by every engineer in the organization demands.• Leverages AI tools to accelerate platform analysis and administration work — including AI-assistedworkflow and governance configuration audits, AI-generated access audit summaries, and LLM-assistedplatform documentation that keeps governance records current and discoverable.
Automation & Scripting (15%)• Continuously identifies and eliminates manual administration toil across Azure DevOps — buildingPowerShell scripts, REST API automations, and workflow integrations that replace repetitive manual stepswith reliable, auditable automated processes.• Develops and maintains monitoring and alerting for Azure DevOps platform health — including permissionanomalies, configuration drift detection, and provisioning issues — so that platform degradation isdetected and resolved proactively rather than reactively.• Automates access review processes, provisioning workflows, and compliance documentation generation— using scripting and AI tooling to maintain audit-ready governance records without proportional manualoverhead.• Builds automation to enforce ADO standards — naming-convention checkers, board/process-templatevalidation scripts, and configuration-compliance automations that prevent non-standard workflows frombeing deployed without a deliberate override.
Cross-Platform Support — Other Engineering Systems Tooling (15%)• Administers and supports LaunchDarkly, Flyway, and Cursor/AI tooling operations — assisting withprovisioning, access controls, configuration governance, and platform health monitoring alongside theteammate(s) who own each platform.• Maintains unified provisioning standards, least-privilege access principles, and audit-ready access recordsacross Azure DevOps, LaunchDarkly, Flyway, and AI tooling, so governance discipline doesn't stop at theADO boundary.• Monitors integration health across administered systems — SDK evaluation errors, migration failures, andtooling provisioning issues — before they impact Engineering operations.• Builds cross-platform fluency over time, with the expectation of taking on deeper ownership of a secondEngineering Systems platform domain — LaunchDarkly, Flyway, GitHub, or another tool the team adds tothe portfolio — as the role matures. The specific set of “other tools” is not fixed and will shift as the team'sresponsibilities evolve.
Engineering Standards Administration (15%)• Serves as the operational executor of the Engineering standards program — maintaining, publishing,formatting, and distributing standards documentation for coding conventions, branching strategies, pullrequest practices, code review requirements, and tooling usage as directed by the Engineering SystemsManager.• Owns the standards repository — ensuring documentation is accurately organized, consistently formatted,discoverable through the Engineering knowledge base, and immediately updated when standards areratified or revised.• Monitors Engineering standards adherence across teams — identifying non-compliance patterns in codereviews, board and workflow configurations, branch naming, and tooling usage, and bringing specific, data-backed observations to the Engineering Systems Manager and relevant Engineering Managers for follow-through.• Supports standards retrospectives led by the Engineering Systems Manager — collecting adherence data,synthesizing engineering team feedback, and preparing materials that make retrospective sessionsproductive rather than anecdotal.
Enablement & Documentation (10%)• Builds and maintains internal enablement resources — ADO configuration guides, workflow standardsreferences, governance how-tos, and onboarding materials — that empower Engineering teams to workwithin established standards correctly and independently, reducing the volume of repetitive supportrequests.• Maintains accurate, current platform configuration documentation and standards repositories — ensuringgovernance requirements, workflow patterns, and access policies are clearly documented and accessibleto the Engineering organization.• Coordinates the onboarding standards experience for new Engineers — maintaining environment setupguides, tooling provisioning checklists, and standards orientation materials that are current, complete, andeffective enough to be executed without handholding.• Tracks platform health, adoption metrics, support request trends, and standards compliance acrossadministered systems — maintaining the operational data the Engineering Systems Manager needs toreport accurately to the Director of Engineering Systems and to make informed investment decisions.
Access Management, Security & Compliance• Maintains access control governance across all administered platforms — executing provisioning and de-provisioning requests promptly, enforcing least-privilege access principles, and maintaining accurateaccess records that support audit evidence requirements.• Conducts and documents regular access reviews across Azure DevOps, LaunchDarkly, Flyway, and Cursor— identifying over-provisioned accounts, stale access grants, and access policy violations, and resolvingthem in partnership with the Engineering Systems Manager and Security team.• Supports SOC 2, ISO/IEC 27001, and NIST 800-53 audit readiness by maintaining accurate, currentplatform configuration records, access inventories, and change histories — treating audit evidence as anongoing operational discipline rather than a pre-audit scramble.• Responds to security-related configuration hardening requests with urgency and precision, partnering withthe Security team on access-related incidents and policy enforcement actions.
Qualifications
- Bachelor's Degree in Computer Science, Information Systems, Business Analysis, or a related field
Engineering Systems Engineer, Azure DevOps — Required Qualifications:
- 2–4 years of hands-on Azure DevOps administration experience — including project configuration, access controlgovernance, and multi-team organizational structures — with Azure DevOps as a primary, hands-onresponsibility, not just usage as an end user.
- Deep hands-on experience administering Azure DevOps — including project/org configuration, access controland permission models, and board/area path structure — at a depth sufficient to independently resolve platformconfiguration issues and act as an internal escalation point.
- Strong scripting and automation skills — proficiency with PowerShell and/or REST APIs, and the ability to writereliable, maintainable automation scripts that other engineers can understand and modify.
- Working knowledge of Git branching strategies, and familiarity with how Azure DevOps Boards and accesscontrols connect to GitHub-hosted repositories — repository links, GitHub Apps/OAuth connections, branchpolicies, and status checks. Our source code lives in GitHub, not Azure Repos, so comfort bridging the two isimportant. Hands-on pipeline/YAML authoring is not required — pipelines are owned by the engineering teamsthemselves.
- Demonstrated ability to diagnose the root cause behind a workflow request rather than implementing a band-aidfix — comfort proposing a better solution instead of the workaround that was asked for.
- Experience managing access controls and user provisioning across engineering platforms with an understandingof least-privilege principles and compliance evidence requirements.
- Strong organizational discipline and attention to detail — able to manage a high-traffic platform used by everyengineer in the organization, maintain configuration hygiene, and track open items without dropping anything.
- Clear written communication skills — able to produce platform documentation, enablement guides, andconfiguration records that are accurate and usable by engineering teams without requiring significant clarification.
Engineering Systems Engineer, Azure DevOps — Preferred Qualifications:
- Exposure to, or willingness to learn, adjacent Engineering Systems platforms — feature flag management(LaunchDarkly), database migration tooling (Flyway), AI-assisted development tools (Cursor, Claude Code), orwhatever other tools the team administers.
- Demonstrated use of AI development tools such as Cursor or Claude Code in day-to-day technical work.Senior Engineering Systems Engineer, Azure DevOps — Required Qualifications:
- 4–7 years of experience in Engineering Systems Administration, Platform Engineering, or DevOps, withdemonstrated ownership of Azure DevOps at scale across multiple teams and projects.
- Deep hands-on expertise in Azure DevOps — including complex multi-project/multi-org configurations, customprocess templates, REST API/CLI-based automation, and integration with third-party tools such as GitHub.
- Demonstrated experience building and owning Azure DevOps–centric automation — including workflow andprocess-template automation, access governance automation, and configuration drift detection — using Python,PowerShell, Bash, or equivalent scripting languages.
- Demonstrated ability to design and enforce platform governance at scale — experience identifying configurationdrift, preventing fragmentation, and establishing standards that teams adopt voluntarily because they solve realproblems.
- Experience contributing to Engineering standards programs — including drafting standards documentation,identifying standards gaps, and influencing adoption across multi-team engineering organizations.
- Experience mentoring or coaching junior Platform Engineers — able to review Azure DevOps configurations,give structured technical feedback, and develop less experienced engineers into independently effective platformoperators.
- Strong familiarity with compliance requirements under SOC 2, ISO/IEC 27001, and NIST 800-53 in anengineering systems context — able to maintain audit-ready platform records and support evidence collectionwithout requiring significant guidance.
- A personal operating standard where the Azure DevOps environment they administer is better documented, moreautomated, and more reliably governed after six months of their ownership than it was when they took it on.
Benefits
- Medical and Dental coverage available for employees, dependents, domestic partners, and spouses
- Paid Time Off – Flexible options plus 10 paid company holidays where available**
- All full-time positions are hybrid, with many eligible to be completely remote
- Fully Paid by Origami Risk – Vision insurance, Short & Long-Term Disability Insurance, and Basic Life Insurance
- Generous family leave options—including adoption and foster care placements
- Pre-Tax Savings Accounts – Flexible Spending Account, Health Savings Account, Commuter Benefits, Dependent Care Savings Account
- Retirement Savings – 401(k) with company match up to 4%
- Employee Assistance Program (EAP) – Confidential & Free support offered to colleagues facing personal or work-related complications
- Education Assistance Program – to help colleagues pursue industry/role-specific certifications
- Wellness Benefits – reimbursement program to invest in healthy habits as well as support better colleague productivity and stress management
- Additional coverages available – Pet Insurance, Critical Illness Insurance, and Voluntary Life & AD&D coverage
Who We Are
Origami Risk delivers single-platform SaaS solutions that help organizations best navigate the complexities of risk, insurance, compliance, and safety management.
Founded by industry veterans who recognized the need for risk management technology that was more configurable, intuitive, and scalable, Origami continues to add to its innovative product offerings for managing both insurable and uninsurable risk; facilitating compliance; improving safety; and helping insurers, MGAs, TPAs, and brokers provide enhanced services that drive results.
A singular focus on client success underlies Origami’s approach to developing, implementing, and supporting our award-winning software solutions.
Origami Risk is proud to be an equal opportunity employer. We thrive and benefit from diversity and are committed to creating an inclusive and equitable environment for all employees. We do not discriminate against any individual based upon race, religion, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, color, sex, national origin, age, marital status, military or veteran status, disability, or any other characteristic protected by applicable law.
Caution: Be alert to recruiting scams. We have received reports of individuals impersonating Origami Risk recruiters to deceive candidates into disclosing personal information. These impostors use fake Origami Risk domain names and email addresses. Please double-check that any email address from an Origami Risk recruiter ends with origamirisk.com or talent.icims.com. And to confirm the legitimacy of any recruiting communication, feel free to email transparencycheck@origamirisk.com.