[Job- 31345]Senior DevOps Engineer (Cloud Network Foundation), Brazil

Ciandt

Brasil

Presencial

BRL 180 000 - 260 000

Tempo integral

Há 7 dias
Torna-te num dos primeiros candidatos

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Vantagens oferecidas por esta oferta de emprego

Health and dental insurance
Meal and food allowance
Childcare assistance
Extended paternity leave
Wellness program

Resumo da oferta

CI&T is seeking an experienced AWS networking engineer in Brazil to co-own a multi-account AWS network foundation with a focus on Transit Gateway, VPC design, and centralized inspection. You will work closely with client cloud architects to justify network decisions and drive end-to-end implementation across accounts.

The role emphasizes hands-on design, testing, and drift-free delivery of secure, scalable cloud networking, including GRE/BGP, IPAM, and Network Firewall.

Qualificações

  • Hands-on with hub-and-spoke network design and centralized inspection.

Responsabilidades

  • Own the network foundation end to end: Transit Gateway with separated inspected and uninspected route tables, VPC design across inspection, egress, ingress, shared services, and workload tiers
  • Define and enforce the routing posture that makes traffic pass a firewall rather than merely sit near one
  • Verify that posture by test, not by reading your own plan
  • Design and implement Transit Gateway Connect over GRE with BGP, two peers for availability
  • Extract precise inputs from third-party SD-WAN vendors who are not on your team and do not share your deadline
  • Manage AWS IPAM with a delegated organisation administrator, pool hierarchy mapped to accounts, RAM shares to spoke accounts
  • Justify every prefix — 'it looked tidy' is not an answer
  • Implement AWS Network Firewall with stateful rule groups, default drop posture, domain allowlisting, and managed threat signatures
  • Be the person who knows whether an application failing to reach the internet is the firewall working correctly
  • Write and maintain Terraform across multiple accounts with per-phase state separation, deployed through GitHub OIDC
  • Implement drift detection, static validation, and a pipeline that a client can inherit
  • Manage log delivery into governance accounts, resource policies, KMS key policies, and service-linked roles
  • Understand that these accept broken configurations silently — and prove delivery by watching a log arrive
  • Write down why: why a prefix is what it is, why an option was rejected, what a deviation is
  • Prevent the next engineer from reversing a deliberate choice because nobody recorded the reasoning

Conhecimentos

AWS networking
Transit Gateway
Hub and spoke design
Network firewall
Terraform
GRE/BGP
GitHub OIDC
AWS IPAM
Direct Connect
Portuguese/English fluency

Ferramentas

Transit Gateway
VPC design
AWS Network Firewall
Terraform
GitHub OIDC
AWS RAM
KMS policies
Direct Connect

Descrição da oferta de emprego

At CI&T, we help large enterprises transform the potential of AI into real business impact with AI Deployment, AI-native execution, and tech-integrated business solutions.


With 30 years of experience in technological transformation, we accelerate innovation with expertise in Agentic SDLC, Application modernization, Data & AI, Martech and Business strategy.


We are 8,000 CI&Ters across more than 25 countries, collaborating to build solutions with real impact. AI is already part of how we work, evolve, and innovate every day.


You willco-own a multi-account AWS network foundation: hub and spoke on Transit Gateway, centralised inspection, controlled egress, hybrid connectivity into a client's SD-WAN estate through a third-party vendor. You will be in the room when the client's cloud architect asks why a subnet is a /25 and not a /24 —and the answer has to be yours.


The work is unglamorous in the way that matters. Most of what goes wrong in a landing zone does not go wrong in a module — it goes wrong at the seams.We want someone who has been burned by those and now checks for them by reflex.


Responsabilidades:


  • Own the network foundationend to end: Transit Gateway with separated inspected and uninspected route tables, VPC design across inspection, egress, ingress, shared services, and workload tiers

  • Define and enforce therouting posturethat makes traffic pass a firewall rather than merely sit near one

  • Verify that postureby test, not by reading your own plan

  • Design and implementTransit Gateway Connect over GRE with BGP, two peers for availability, ASNs agreed in advance

  • Extract precise inputs fromthird-party SD-WAN vendorswho are not on your team and do not share your deadline

  • ManageAWS IPAMwith a delegated organisation administrator, pool hierarchy mapped to accounts, RAM shares to spoke accounts

  • Justifyevery prefix— "it looked tidy" is not an answer

  • ImplementAWS Network Firewallwith stateful rule groups, default drop posture, domain allowlisting, and managed threat signatures

  • Be the person who knows whether an application failing to reach the internet isthe firewall working correctly

  • Write and maintainTerraform across multiple accountswith per-phase state separation, deployed throughGitHub OIDC

  • Implement drift detection, static validation, and a pipeline thata client can inherit

  • Manage log delivery into governance accounts, resource policies,KMS key policies, and service-linked roles

  • Understand that these accept broken configurations silently — andprove delivery by watching a log arrive

  • Write downwhy: why a prefix is what it is, why an option was rejected, what a deviation is

  • Prevent the next engineer from reversing a deliberate choicebecause nobody recorded the reasoning

  • Write downwhy: why a prefix is what it is, why an option was rejected, what a deviation is

  • Prevent the next engineer from reversing a deliberate choicebecause nobody recorded the reasoning


Requisitos:


  • Transit Gateway: association vs. propagation (no hedging), appliance mode, and why it exists

  • VPC design: Network Firewall, NAT and egress control, PrivateLink, Route 53 Resolver

  • Hands-on withhub and spoke and centralised inspection— built it, broke it, and fixed it(non-negotiable)

  • Ability to describe arouting asymmetry you diagnosedor a firewall you had to prove was in the path

  • Organizations, Control Tower, OUs, SCPs, delegated administrators, RAM

  • Experienceinheriting a landing zonesomeone else deployed

  • Module design,state layout across accounts and phases

  • Read a plan and know before applying whether you are renaming ordestroyinga resource

  • Site-to-site VPN or Direct Connect, GRE, BGP peering, route advertisement, ASN allocation

  • Default tochecking the environmentrather than trusting a report — including your own

  • Every serious problem was found by someonequerying the accountinstead of reading a summary

  • Clear, precise, unhedged prose — adelivery skill, not a nice-to-have

  • Inglês Avançado/Fluente é obrigatório


Diferencial:


  • AWS Advanced Networking Specialty certification— or the equivalent scar tissue

  • Experience withSD-WAN platforms on AWS(Cisco, Fortinet, Palo Alto) and Transit Gateway Connect

  • Exposure tomanufacturing or industrial environments

  • Familiarity withAWS Account Factory for Terraform (AFT)

  • Working fluency in both Portuguese and English— client conversations in English; team works in Portuguese


#LI-AM2


Our benefits:


  • Health and dental insurance

  • Meal and food allowance

  • Childcare assistance

  • Extended paternity leave

  • Partnership with gyms and health and wellness professionals via Wellhub (Gympass) TotalPass;

  • Profit Sharing and Results Participation (PLR);

  • Life insurance

  • Continuous learning platform (CI&T University);

  • Discount club

  • Free online platform dedicated to physical, mental, and overall well-being

  • Pregnancy and responsible parenting course

  • Partnerships with online learning platforms

  • Language learning platform


And many more!


More details about our benefits here: https://ciandt.com/br/pt-br/carreiras


At CI&T, inclusion starts at the first contact. If you are a person with a disability, it is important to present your assessment during the selection process. See which data needs to be included in the report by clicking here.


If you do not yet have the assessment, don't worry: we can support you in obtaining it.


We have a dedicated Health and Well-being team, inclusion specialists, and affinity groups who will be with you at every stage. Count on us to make this journey side by side.

Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

[Job- 31345]Senior DevOps Engineer (Cloud Network Foundation), Brazil
[Job- 31345]Senior DevOps Engineer (Cloud Network Foundation), Brazil

CI&T • Brasil

Híbrido
BRL 180 000 - 260 000
Seguro de saúde
Vale refeição
Vale alimentação
+5
Senior DevOps Engineer (Cloud Network Foundation), Brazil
Senior DevOps Engineer (Cloud Network Foundation), Brazil

CI&T • Brasil

Presencial
BRL 180 000 - 240 000
Health insurance
Dental insurance
Meal allowance
+3
Master Backend Developer / Tech Lead — Java, Go & AWS, Brazil
Master Backend Developer / Tech Lead — Java, Go & AWS, Brazil

CI&T • Brasil

Híbrido
BRL 280 000 - 420 000
Health and dental insurance
Meal and food allowance
Extended paternity leave
+1
Sênior DevOps (AWS), Brazil
Sênior DevOps (AWS), Brazil

CI&T Software S.A. • Brasil

Presencial
BRL 180 000 - 320 000
Health and dental insurance
Meal and food allowance
Childcare assistance
+9
[Job- 31334]Principal Architect, Brazil
[Job- 31334]Principal Architect, Brazil

Ciandt • Brasil

Presencial
BRL 350 000 - 520 000
Health and dental insurance
Meal and food allowance
Childcare assistance
+7
Sr. Developer FullStack (.Net/React) , Brazil
Sr. Developer FullStack (.Net/React) , Brazil

CI&T • Brasil

Presencial
BRL 180 000 - 300 000
Health and dental insurance
Meal and food allowance
Extended paternity leave
+9
[Job- 31398]Senior Full Stack Developer, Brazil
[Job- 31398]Senior Full Stack Developer, Brazil

Ciandt • Brasil

Presencial
BRL 180 000 - 360 000
Health insurance
Dental insurance
Meal allowance
+4
[Job- 31398]Senior Full Stack Developer, Brazil
[Job- 31398]Senior Full Stack Developer, Brazil

CI&T • Brasil

Presencial
BRL 180 000 - 240 000
Health and dental insurance
Meal and food allowance
Childcare assistance
+2
[Job-31000] Senior Data Engineer, Brazil
[Job-31000] Senior Data Engineer, Brazil

CI&T • Brasil

Presencial
BRL 180 000 - 300 000
Health and dental insurance
Meal and food allowance
Childcare assistance
+3
Senior QA (SDET), Brazil
Senior QA (SDET), Brazil

CI&T • Campinas

Presencial
BRL 60 000 - 80 000
Health and dental insurance
Meal and food allowance
Extended paternity leave
+9