Job Description
Role Summary:
We are seeking a Cloud Engineer with deep hands-on experience designing and managing scalable, secure cloud environments using Infrastructure as Code (IaC). This role goes beyond basic deployment — you’ll be responsible for architecting multi-region environments, implementing cost optimization strategies, and maintaining strict compliance and observability standards across AWS (primary) and GCP (secondary).
Key Responsibilities:
- Design, implement, and manage infrastructure-as-code (Terraform, Pulumi) across multiple cloud providers, with an emphasis on modular, reusable patterns.
- Own our AWS Organization configuration including Control Tower, SCPs, and centralized logging/Security Hub integrations.
- Build and manage CI/CD pipelines (GitHub Actions preferred) that deploy containerized workloads to EKS and GKE.
- Configure and maintain service mesh architecture (Istio or Linkerd) across Kubernetes clusters.
- Lead cost governance reviews by implementing tools like AWS Cost Explorer, CloudHealth, or custom Prometheus/Grafana dashboards.
- Integrate cloud IAM policies with enterprise identity providers (Okta, Azure AD) using SAML/OIDC and enforce least privilege access.
- Contribute to DR strategy with active-active and active-passive region failover configurations for stateless and stateful workloads.
- Automate security scanning (e.g., with tfsec, Checkov, or Snyk) across IaC and container pipelines.
Required Qualifications:
- 5+ years of cloud engineering experience, with 3+ years on AWS in production environments.
- Proficiency with Terraform (0.14+) using workspaces, remote state, and modules. Experience with CDK or Pulumi a plus.
- Demonstrated ability to deploy and manage EKS clusters, including autoscaling, IAM roles for service accounts (IRSA), and network policy.
- Deep understanding of VPC design, including transit gateways, PrivateLink, NAT Gateways, route tables, and NACLs.
- Solid experience integrating HashiCorp Vault or AWS Secrets Manager with applications in Kubernetes.
- Familiarity with CloudTrail, Config Rules, GuardDuty, and automated response workflows (Lambda, EventBridge).
- Hands-on experience with Helm 3, Kustomize, and GitOps tools such as ArgoCD or FluxCD.
- Competent with Linux system administration, containerization (Docker), and scripting in Bash and Python.
Preferred Qualifications:
- Certification: AWS Certified DevOps Engineer – Professional or equivalent.
- Prior experience in a regulated environment (SOC 2, HIPAA, or FedRAMP).
- Experience using OPA/Gatekeeper or Kyverno to enforce Kubernetes policies.
- Exposure to multi-cloud environments and workload portability strategies.
- Background in site reliability engineering (SRE) or running high-availability systems.
Are you interested in this position?
Apply by clicking on the “Apply Now” button below!
#GraphicDesignJobsOnline#WebDesignRemoteJobs #FreelanceGraphicDesigner #WorkFromHomeDesignJobs #OnlineWebDesignWork #RemoteDesignOpportunities #HireGraphicDesigners #DigitalDesignCareers#Dynamicbrandguru