Senior DevOps Engineer (Cloud Network Foundation), Brazil

CI&T

Brasil

Presencial

BRL 180 000 - 240 000

Tempo integral

Há 4 dias
Torna-te num dos primeiros candidatos

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Vantagens oferecidas por esta oferta de emprego

Health insurance
Dental insurance
Meal allowance
Paternity leave
Wellbeing programs
Gym/Wellness partnerships

Resumo da oferta

CI&T is seeking a senior AWS network engineer to own the end-to-end network foundation in a multi-account AWS environment. You will design and enforce routing postures, implement Transit Gateway Connect and GRE/BGP peering, and manage IPAM, RAM, and log delivery for governance.

You will work hands-on with Terraform, GitHub OIDC, and ensure delivery is proven by logs. Fluency in Portuguese and English is required for client conversations and team collaboration.

Qualificações

  • Hands-on experience building hub-and-spoke network with Transit Gateway

Responsabilidades

  • Own the network foundation end to end including Transit Gateway and VPC design
  • Define and enforce routing posture to ensure traffic passes through a firewall
  • Verify posture by testing rather than relying on plans
  • Design and implement Transit Gateway Connect with GRE and BGP
  • Manage AWS IPAM and RAM sharing across accounts
  • Implement AWS Network Firewall with stateful rules and threat signatures
  • Write Terraform across multiple accounts with GitHub OIDC
  • Provide delivery proof via logs rather than reports
  • Document rationale for prefixes and decisions
  • Work with SD-WAN vendors and third-party integrations
  • Ensure governance through policy, drift detection and phase-based state layouts
  • Explain routing issues and firewall paths to clients

Conhecimentos

Hub-and-spoke networking
Transit Gateway
VPC design
AWS Network Firewall
Terraform across accounts
GitHub OIDC
SD-WAN on AWS
Portuguese and English

Formação académica

AWS Advanced Networking Specialty certification

Ferramentas

Terraform
Direct Connect

Descrição da oferta de emprego

At CI&T, we help large enterprises transform the potential of AI into real business impact with AI Deployment, AI-native execution, and tech-integrated business solutions.

With 30 years of experience in technological transformation, we accelerate innovation with expertise in Agentic SDLC, Application modernization, Data & AI, Martech and Business strategy.

We are 8,000 CI&Ters across more than 25 countries, collaborating to build solutions with real impact. AI is already part of how we work, evolve, and innovate every day.

You willco-own a multi-account AWS network foundation: hub and spoke on Transit Gateway, centralised inspection, controlled egress, hybrid connectivity into a client's SD-WAN estate through a third-party vendor. You will be in the room when the client's cloud architect asks why a subnet is a /25 and not a /24 —and the answer has to be yours.

The work is unglamorous in the way that matters. Most of what goes wrong in a landing zone does not go wrong in a module — it goes wrong at the seams.We want someone who has been burned by those and now checks for them by reflex.

  • Own the network foundationend to end: Transit Gateway with separated inspected and uninspected route tables, VPC design across inspection, egress, ingress, shared services, and workload tiers
  • Define and enforce therouting posturethat makes traffic pass a firewall rather than merely sit near one
  • Verify that postureby test, not by reading your own plan
  • Design and implementTransit Gateway Connect over GRE with BGP, two peers for availability, ASNs agreed in advance
  • Extract precise inputs fromthird-party SD-WAN vendorswho are not on your team and do not share your deadline
  • ManageAWS IPAMwith a delegated organisation administrator, pool hierarchy mapped to accounts, RAM shares to spoke accounts
  • Justifyevery prefix— "it looked tidy" is not an answer
  • ImplementAWS Network Firewallwith stateful rule groups, default drop posture, domain allowlisting, and managed threat signatures
  • Be the person who knows whether an application failing to reach the internet isthe firewall working correctly
  • Write and maintainTerraform across multiple accountswith per-phase state separation, deployed throughGitHub OIDC
  • Implement drift detection, static validation, and a pipeline thata client can inherit
  • Manage log delivery into governance accounts, resource policies,KMS key policies, and service-linked roles
  • Understand that these accept broken configurations silently — andprove delivery by watching a log arrive
  • Write downwhy: why a prefix is what it is, why an option was rejected, what a deviation is
  • Prevent the next engineer from reversing a deliberate choicebecause nobody recorded the reasoning
  • Write downwhy: why a prefix is what it is, why an option was rejected, what a deviation is
  • Prevent the next engineer from reversing a deliberate choicebecause nobody recorded the reasoning
  • Transit Gateway: association vs. propagation (no hedging), appliance mode, and why it exists
  • VPC design: Network Firewall, NAT and egress control, PrivateLink, Route 53 Resolver
  • Hands-on withhub and spoke and centralised inspection— built it, broke it, and fixed it(non-negotiable)
  • Ability to describe arouting asymmetry you diagnosedor a firewall you had to prove was in the path
  • Organizations, Control Tower, OUs, SCPs, delegated administrators, RAM
  • Module design,state layout across accounts and phases
  • Read a plan and know before applying whether you are renaming ordestroyinga resource
  • Site-to-site VPN or Direct Connect, GRE, BGP peering, route advertisement, ASN allocation
  • Default tochecking the environmentrather than trusting a report — including your own
  • Every serious problem was found by someonequerying the accountinstead of reading a summary
  • Clear, precise, unhedged prose — adelivery skill, not a nice-to-have
  • AWS Advanced Networking Specialty certification— or the equivalent scar tissue
  • Experience withSD-WAN platforms on AWS(Cisco, Fortinet, Palo Alto) and Transit Gateway Connect
  • Exposure tomanufacturing or industrial environments
  • Familiarity withAWS Account Factory for Terraform (AFT)
  • Working fluency in both Portuguese and English— client conversations in English; team works in Portuguese
  • Health and dental insurance
  • Meal and food allowance
  • Extended paternity leave
  • Partnership with gyms and health and wellness professionals via Wellhub (Gympass) TotalPass;
  • Profit Sharing and Results Participation (PLR);
  • Life insurance
  • Continuous learning platform (CI&T University);
  • Discount club
  • Free online platform dedicated to physical, mental, and overall well-being
  • Pregnancy and responsible parenting course
  • Partnerships with online learning platforms
  • Language learning platform

And many more!

More details about our benefits here: https://ciandt.com/br/pt-br/carreiras

At CI&T, inclusion starts at the first contact. If you are a person with a disability, it is important to present your assessment during the selection process. See which data needs to be included in the report by clicking here. This way, we can ensure the support and accommodations that you deserve. If you do not yet have the assessment, don't worry: we can support you in obtaining it.

We have a dedicated Health and Well-being team, inclusion specialists, and affinity groups who will be with you at every stage. Count on us to make this journey side by side.

Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

[Job- 31345]Senior DevOps Engineer (Cloud Network Foundation), Brazil
[Job- 31345]Senior DevOps Engineer (Cloud Network Foundation), Brazil

CI&T • Brasil

Híbrido
BRL 180 000 - 260 000
Seguro de saúde
Vale refeição
Vale alimentação
+5
[Job- 31345]Senior DevOps Engineer (Cloud Network Foundation), Brazil
[Job- 31345]Senior DevOps Engineer (Cloud Network Foundation), Brazil

Ciandt • Brasil

Presencial
BRL 180 000 - 260 000
Health and dental insurance
Meal and food allowance
Childcare assistance
+2
Master Backend Developer / Tech Lead — Java, Go & AWS, Brazil
Master Backend Developer / Tech Lead — Java, Go & AWS, Brazil

CI&T • Brasil

Híbrido
BRL 280 000 - 420 000
Health and dental insurance
Meal and food allowance
Extended paternity leave
+1
Sr. Developer FullStack (.Net/React) , Brazil
Sr. Developer FullStack (.Net/React) , Brazil

CI&T • Brasil

Presencial
BRL 180 000 - 300 000
Health and dental insurance
Meal and food allowance
Extended paternity leave
+9
Software Architect Midlevel, Brazil
Software Architect Midlevel, Brazil

CI&T • Brasil

Presencial
BRL 200 000 - 320 000
Health and dental insurance
Meal and food allowance
Extended paternity leave
+9
[Job- 31398]Senior Full Stack Developer, Brazil
[Job- 31398]Senior Full Stack Developer, Brazil

CI&T • Brasil

Presencial
BRL 180 000 - 240 000
Health and dental insurance
Meal and food allowance
Childcare assistance
+2
[Job - 30994] Senior Business Analyst
[Job - 30994] Senior Business Analyst

Ciandt • Brasil

Presencial
BRL 120 000 - 180 000
Health and dental insurance
Meal and food allowance
Childcare assistance
+8
[Job- 31398]Senior Full Stack Developer, Brazil
[Job- 31398]Senior Full Stack Developer, Brazil

Ciandt • Brasil

Presencial
BRL 180 000 - 360 000
Health insurance
Dental insurance
Meal allowance
+4
Senior QA (SDET), Brazil
Senior QA (SDET), Brazil

CI&T • Campinas

Presencial
BRL 60 000 - 80 000
Health and dental insurance
Meal and food allowance
Extended paternity leave
+9
AI Engineer, Brazil
AI Engineer, Brazil

CI&T • Brasil

Presencial
BRL 150 000 - 230 000
Health and dental insurance
Meal and food allowance
Extended paternity leave
+9