Senior Cloud Infrastructure Engineer ( Governance )

Platform Science, Inc.

Londrina

Presencial

BRL 180 000 - 360 000

Tempo integral

Há 9 dias
Gerador de candidaturas

Destaca-te nesta função — gera um currículo e uma carta de apresentação personalizados em cerca de um minuto.

Ultrapassa os filtros ATS

Resumo da oferta

Platform Science, Inc. is seeking a Senior Cloud Infrastructure Engineer to join our CloudOps team. This hands-on senior IC will own infrastructure end-to-end, focus on foundational infrastructure, and drive guardrails for secure, scalable cloud platforms across AWS, Azure, and GCP.

You will build reusable IaC modules, manage identity and networking, and collaborate with Security and FinOps to optimize costs and reduce risk. This role requires strong English and residing in Brazil.

Qualificações

  • 7–10+ years of professional experience in Cloud Infrastructure or related field.
  • 4–5+ years hands-on with AWS or other major clouds, strong AWS experience preferred.
  • 3+ years Infrastructure as Code, Terraform/Terragrunt experience.
  • Experience with multi-account AWS, Control Tower or landing-zone architectures.
  • Production experience with Azure or GCP beyond a single workload.
  • Strong design of reusable IaC modules for other teams.
  • Experience with IAM, least-privilege, SSO/SAML and policy boundaries.
  • Strong Linux fundamentals and cloud networking knowledge.

Responsabilidades

  • Own and evolve multi-account AWS Landing Zone including governance and security guardrails.
  • Extend cloud governance, security controls, observability, and backup across AWS/Azure/GCP.
  • Design and operate cloud networking including VPC/VNet and private connectivity.
  • Build self-service infrastructure and CI/CD automation for engineering teams.
  • Partner with Security and FinOps to address findings and optimize costs.

Conhecimentos

Cloud infrastructure
AWS
IaC (Terraform/Terragrunt)
Kubernetes
Linux
CI/CD tooling
Python/Go/Bash scripting
Security & IAM
English proficiency

Formação académica

Bachelor’s degree in Computer Science / Software Engineering / IT

Ferramentas

Terraform
Terragrunt
GitHub Actions
Jenkins

Descrição da oferta de emprego

Platform Science is looking for a Senior Cloud Infrastructure Engineer to join our CloudOps team.

CloudOps owns the foundational cloud infrastructure that enables our engineering teams to build, deploy, and operate products at scale. The team manages identity, networking, governance, security guardrails, backup, disaster recovery, and shared cloud services across a multi-account AWS environment spanning hundreds of accounts and multiple business units. We are also extending this operating model across Azure and GCP.

This is a hands‑on senior individual contributor role for an engineer who enjoys building foundational infrastructure and solving complex cloud problems. You will own infrastructure and platform capabilities end to end, work primarily through Infrastructure as Code, and create guardrails and self‑service capabilities that allow engineering teams to move quickly without sacrificing security or reliability. We are looking for engineers with experience in and around Governance

The scope is intentionally broad. You may work on cloud identity and permissions, private networking, multi‑cloud governance, backup and disaster recovery, security remediation, or developer self‑service capabilities.

AI‑assisted engineering is also part of how the team operates. We use AI coding agents to accelerate implementation and automation while maintaining rigorous engineering review, security, and production standards.

What You’ll Do
  • Own and evolve our multi‑account AWS Landing Zone, including AWS Organizations, Control Tower, Account Factory for Terraform (AFT), organizational structures, Service Control Policies, tagging standards, and permission boundaries.
  • Extend cloud governance, operational standards, security controls, observability, and backup capabilities across AWS, Azure, and GCP.
  • Improve cloud identity and access management using least‑privilege principles, including Okta federation, AWS IAM Identity Center, permission sets, group design, credential management, and reduction of standing privileged access.
  • Design and operate cloud networking capabilities, including IP address management, VPC architecture, routing, transit connectivity, Cloud WAN, egress architecture, and public/private DNS.
  • Help transition workloads from public‑internet exposure to private and zero‑trust networking models, including Kubernetes control planes, databases, and internal platforms.
  • Build self‑service infrastructure capabilities for engineering teams, including account provisioning, environment provisioning, access requests, account lifecycle management, and infrastructure inventory.
  • Design and maintain backup, restore, and disaster recovery capabilities across cloud regions, accounts, and business units with different recovery requirements.
  • Implement immutable and ransomware‑resistant backup strategies for cloud‑native and managed third‑party data platforms.
  • Build reusable Terraform/Terragrunt modules and infrastructure patterns that can be safely consumed by engineering teams across the organization.
  • Develop and maintain CI/CD automation for cloud infrastructure.
  • Partner with Security teams to investigate and remediate cloud security findings.
  • Partner with FinOps teams to identify cloud cost optimization opportunities that can be implemented broadly across the organization.
  • Build and maintain documentation, cloud standards, operating procedures, and shared responsibility models.
  • Use AI coding agents as part of the engineering workflow while maintaining ownership for requirements, architecture, testing, security, code review, and production outcomes.
  • Develop reusable prompts, context, workflows, and agent capabilities that improve the CloudOps team's productivity.
Required Experience
  • 7–10+ years of professional experience in Cloud Infrastructure, DevOps, Site Reliability Engineering, Platform Engineering, Systems Engineering, or a related infrastructure discipline.
  • 4–5+ years of hands‑on experience with AWS or another major public cloud, with significant AWS experience strongly preferred.
  • 3+ years of Infrastructure as Code experience, preferably using Terraform and/or Terragrunt.
  • Experience operating AWS at organizational scale, including AWS Organizations, multi‑account architecture, and Control Tower or a comparable landing‑zone architecture.
  • Production experience with at least one additional major cloud platform — Azure or GCP — beyond managing a single workload.
  • Strong experience designing reusable Infrastructure as Code modules and patterns consumed by other engineering teams.
  • Hands‑on experience with cloud identity and access management, including SSO, SAML federation, SCIM provisioning, IAM policies, roles, permission boundaries, and least‑privilege access models.
  • Strong cloud networking fundamentals, including IP address planning, VPC/VNet design, routing, transit architectures, DNS, private connectivity, and network security.
  • Experience designing or maintaining CI/CD pipelines using tools such as GitHub Actions, Jenkins, or similar technologies.
  • Experience scripting or programming with Python, Go, Bash, or similar languages.
  • Strong Linux fundamentals.
  • Working knowledge of Kubernetes and cloud‑native infrastructure.
  • Experience using AI coding agents or AI‑assisted development tools such as Claude Code, Cursor, Codex, or similar tools. Candidates should understand how to define requirements, establish success criteria, validate generated code, and identify situations where AI‑generated infrastructure may introduce security or operational risk.
  • Ability to independently own complex infrastructure projects from design through production implementation.
  • Strong written and verbal communication skills with the ability to collaborate across Engineering, Security, FinOps, and other technical teams.
  • Advanced English proficiency.
  • Bachelor’s degree in Computer Science, Software Engineering, Information Technology, or a related technical field.
  • Must reside in Brazil.
Preferred Qualifications:
Experience with one or more of the following is highly desirable:
  • AWS Control Tower and Account Factory for Terraform (AFT)
  • AWS IPAM, Transit Gateway, or Cloud WAN
  • Multi‑cloud governance across AWS, Azure, and/or GCP
  • Cross‑account immutable backup and ransomware protection
  • MongoDB Atlas, Elastic Cloud, or similar managed data platforms
  • Wiz, GuardDuty, CrowdStrike, or other cloud security posture/security platforms
  • Zero‑trust networking technologies such as Zscaler ZPA
  • Cloudflare WAF and DNS
  • Certificate and PKI lifecycle management using ACM, Private CA, cert‑manager, or Let’s Encrypt
  • Agentic automation pipelines or automated remediation workflows
  • MCP servers or reusable AI agent skills
  • Secure access patterns and permission boundaries for AI‑driven automation
  • Cloud cost optimization and FinOps
  • SOC 2 or comparable security/compliance frameworks
  • GitHub organization administration, including teams, apps, rulesets, and Actions runners
  • AWS, Azure, GCP, Terraform, Kubernetes, or related technical certifications
Obtém a tua avaliação gratuita e confidencial do currículo.

ou arrasta e larga o ficheiro aqui.

Similar jobs

Ofertas semelhantes que vale a pena comparar

Senior Cloud Infrastructure Engineer
Senior Cloud Infrastructure Engineer

Platform Science • Brasil

Presencial
BRL 280 000 - 420 000
Cloud Infrastructure Engineer
Cloud Infrastructure Engineer

Platform Science • Brasil

Presencial
BRL 180 000 - 360 000
Senior Cloud Engineer
Senior Cloud Engineer

WEX • São Paulo

Presencial
BRL 180 000 - 280 000
Delivery Tech Lead (DTL) – AWS Landing Zone & Cloud Governance
Delivery Tech Lead (DTL) – AWS Landing Zone & Cloud Governance

Avenue Code • Brasil

Presencial
BRL 240 000 - 360 000
Cloud Architect
Cloud Architect

Espire Infolabs (Singapore) Pte Ltd • Região Norte

Híbrido
BRL 180 000 - 320 000
Staff DevOps Engineer
Staff DevOps Engineer

WEX • São Paulo

Presencial
BRL 300 000 - 420 000
ICT Infrastructure Engineer
ICT Infrastructure Engineer

USER EXPERIENCE RESEARCHERS PTE. LTD • Região Norte

Presencial
BRL 180 000 - 300 000
Cloud Engineer AWS/ GCP
Cloud Engineer AWS/ GCP

Tata Consultancy Services • Brasil

Presencial
BRL 150 000 - 230 000
Cloud Platform Technical Lead ID92209
Cloud Platform Technical Lead ID92209

AgileEngine, LLC. • Sorocaba

Híbrido
BRL 731 000 - 1 044 000
Professional growth
Competitive USD pay
Exciting projects
+1
Cloud Platform Technical Lead ID92209
Cloud Platform Technical Lead ID92209

AgileEngine, LLC. • Porto Alegre

Teletrabalho
BRL 939 000 - 1 461 000
Professional growth
Competitive compensation
Exciting projects
+1