Quick Overview
Seniority
Mid Senior
Work mode
Hybrid
Location
Toronto, ON, United States
Posted
23 hours ago
SOC 2AgileCDNCSSCloudflareDNSGitJavaJavaScriptPythonWAF
Job Description
We are looking for Senior Site Reliability Engineer for our client in Toronto, ON
Job Title: Senior Site Reliability Engineer
Job Location: Toronto, ON
Job Type: Contract
Job Overview:
The successful candidate will be the reliability engineer for a public-facing banking website in a regulated environment, working across Adobe vendor, InfoSec, Network and CDN, Privacy, Production Support and a lean full-stack development team.
Responsibilities:
- Own end-to-end monitoring of the client-controlled surface: CDN and edge configuration, DNS, certificates, cache and invalidation health, and every third-party integration on the page - Search, Consent Management, Analytics, Personalization and AI services, and more to come.
- Build and run synthetic monitoring from outside the bank network, per template and per language, because internal-only monitoring cannot see the CDN, DNS, and certificate failures this architecture is most exposed to.
- Run smoke testing of dependent interfaces on every change and maintain the automation packs that do it.
- Participate in the shared on-call rotation as the platform s subject-matter escalation, and lead incident management for customer-facing events.
- Own the vendor s escalation path into Adobe: severity mapping between Adobe and client incident scales, named contacts, evidence capture, and holding the vendor to its commitment during an event.
- Handle a class of incident that does not exist on traditional platforms - content published but not visible, invalidation failure, and authoring-source outages - and make those issues diagnosable by the service desk rather than by the successful candidate.
- Design and operate change management for the platform where the Git repository is production: reconcile a merge-to-main deployment model with client change control, so that every production change carries an approved record without stalling delivery.
- Own the release pipeline as a production control - branch protection, required checks, lint, performance, and secret-screening gates - and the evidence that they are enforced.
- Own rollback: revert, republish and purge, rehearsed end to end with a measured recovery time and a named authority who can call it without convening a meeting.
- Treat content publishing as a routine process: hundreds of production changes made by content authors, needing approval evidence, attribution and retention trail.
- Represent the platform at the change advisory board, and own the freeze calendar interaction and release notes.
- Own the recovery obligation that sits with the client. Adobe operates delivery resiliently, but customers restore their own content from source version history rather than vendor backups - so the content source, the Git repository and the CDN configuration are the client s recovery surface, each needs a tested restore.
- Hold CDN and edge configuration as code so that a lost or corrupted property is a redeploy rather than an outage with no runbook.
- Define RTO and RPO with the business against the application criticality tier, document the DR exercise plan, and execute the testing - including failure modes that can actually be caused: certificate expiry, invalidation failure, WAF misconfiguration, content source unavailability, and repository compromise.
- Maintain the operational resilience evidence a regulator expects for a material third-party technology arrangement, and keep the platform exit and portability plan current.
- Set and defend service level objectives for both availability and page performance. Define Core Web Vitals thresholds per template, run them on an error budget, and report against them.
- Build the observability practice from the telemetry that exists; real user monitoring on the production domains, CDN access logs streamed to enterprise SIEM as the log source of record, and external synthetics. There is no origin server log - designing around that constraint is part of the job.
- Own third-party scripts and tag governance as a reliability control. Tags are the dominant cause of performance regressions and are added by teams outside engineering change control; the candidate will define the approval route, measure each tag s cost and enforce the budget.
- Own capacity and cost where they still exist: CDN egress, asset storage and processing, media delivery and any client-hosted APIs behind the page. Capacity planning here is a financial operations discipline, not a server-sized one.
- Publish the reliability and performance reporting that the business, risk and technology leadership use.
- Evidence controls on a platform the client does not operate - which is harder than evidencing the candidate s own, and is where a meaningful share of the role s effort sits.
- Own log ingestion into SIEM with the agreed retention, access recertification across the repository, Adobe Admin Console, content source and CDN, and the audit evidence pack.
- Support privacy, operational risks, control assessment and third-party risk processes with operational evidence and maintain alignment to regulatory expectations for technology, cyber and third-party risks.
- Keep the configuration management database, support model and assignment groups accurate as the platform estate grows.
What will you do?:
- This is a build-then-run role. Roughly half of the first year is establishing a reliability practice that does not exist yet.
- The observability stack: Real User Monitoring, Core Web Vitals dashboards and alerting, CDN log ingestion, and external synthetics.
- CDN and edge configuration as code, with a tested restore.
- The operations runbook, incident playbook, operational level agreement and vendor escalation matrix.
- The change model that reconciles Git-based deployments and continuous content publishing with the client s change controls.
- The first disaster recovery exercise and the first rehearsed, measured rollback.
- Service level objectives agreed with the business, and the reporting that holds the platform to them.
Requirements:
- Substantial hands-on experience operating a high-traffic public website behind an enterprise content delivery network. Depth in CDN configuration - origin and cache behaviour, invalidation, edge logic, TLS and DNS - is the single most important qualification. Akamai and Cloudflare experience is an advantage.
- Practical web application firewall experience, including tuning false positives against production-like traffic before enforcement, and bot management that protects the site without blocking the crawlers needed.
- A real observability practice: defining service level objectives and error budgets, and building monitoring from log, real-user and synthetic sources rather than from an agent on a server.
- Web performance engineering - Core Web Vitals, load and rendering behaviour, and the ability to read a waterfall and attribute a regression to a specific script.
- Comfortable with front-end technology: this platform ships JavaScript and CSS to the browser with no server tier; the candidate cannot reason about its reliability without reading and understanding it.
- Git-based release engineering and CI/CD as a production control, including infrastructure and configuration as code.
- Incident command on customer-facing services, and the discipline to produce evidence during an event, not after it.
- Working effectively in a regulated environment - change control, audit evidence, access management and third-party risk - without treating it as an obstacle.
Nice-to-have:
- Experience operating a vendor-run or SaaS-delivered platform, where reliability means instrumenting, escalating and holding a supplier accountable rather than fixing the tier yourself.
- Adobe Experience Manager exposure, particularly Edge Delivery Services and Assets as a Cloud Service.
- Financial services or another regulated sector.
- Bilingual delivery - operating a site that must meet the same standard in English and French.
- Accessibility and Search Engine Optimization sufficient to recognize when a reliability decision creates a compliance or discoverability problem.
- Automation in Python, Java or JavaScript, and a preference for encoding a runbook rather than writing one.
== ==
Benefits
Our Benefits Include:
- Medical, Dental, and Vision Insurance
- 401(k) Retirement Plan
- Health Savings Account (HSA)
- Disability Insurance (Short-Term and Long-Term)
- Life and AD&D Insurance
- Paid Sick Leave (where required by applicable state or local law)
- Supplemental Insurance Plans
- Identity Theft Protection
- Pet Insurance
- Employee Wellness Programs
- Employee Assistance Program (EAP)
- Career Growth and Professional Development Opportunities
Disclaimer: Benefits eligibility, accrual rates, and usage limits may vary based on employment status, length of service, and work location. Paid Sick Leave is provided in strict accordance with applicable state and municipal mandates. Cynet Systems Inc. reserves the right to modify, amend, or terminate any benefit plans at any time in accordance with applicable laws.
About Cynet Systems
Founded in 2010 and headquartered in the Washington, DC metro area, Cynet Systems Inc. is a leading technology staffing and workforce solutions company serving Fortune 500 companies, government agencies, and enterprise organizations across the United States and Canada. We deliver agile, scalable talent solutions across IT, engineering, life sciences, clinical, and professional staffing, powered by a high-performing recruitment engine operating across North America and Asia.
As a nationally and locally certified Minority Business Enterprise (MBE), Cynet Systems is committed to helping organizations build high-performing teams while empowering professionals to grow rewarding careers. Our organization is certified to ISO 9001, ISO 14001, ISO 27001, and SOC 2 Type II standards, reflecting our commitment to quality, security, operational excellence, and customer success.
Similar jobs
- SN
Sr. Devops Engineer
NewShree Narayani Networking Solutions LLC
Berkeley Heights, NJ🇺🇸Hybrid23 hours agoDockerAzureBash+3Technology - BA
DevOps Cloud Engineer
Booz Allen Hamilton
California, MD🇺🇸$77.6k - $176k/yrOn-site3 days agoDockerShellAWS+4Technology - RD
Platform Engineer
NewRandstad Digital
Columbus, OH🇺🇸$75 - $82/hrHybrid23 hours agoAgileAnsibleAzure+2Technology - DE
DevSecOps Engineer
NewDelviom LLC
Washington, DC🇺🇸On-site23 hours agoEngineering - NE
DevOps Engineer
NewNET2ASPIRE LLC
United States🇺🇸Hybrid23 hours agoDockerAWSELK+21Technology - CD
devops Architect
NewCosmic-I LLC DBA Northern Base
Raritan, NJ🇺🇸Hybrid23 hours agoDockerMicroservicesSQL+14Technology