Turn this role into an interview — a resume and cover letter built around what this employer wants.
Anthill Agency in Copenhagen is looking for a platform-oriented Cloud/DevOps Engineer who will own the AWS-based infrastructure across a multi-account setup. You’ll work with Terraform, IAM, secrets, guardrails, observability, reliability and cost, and empower product teams to deploy themselves.
You’ll contribute to security/compliance, champion standardization, and help connect AI agents to internal systems with auditable, logged operations. This is an on-site role in our Copenhagen office.
Think you might be the one? Scroll down to find out what we're looking for and see if it's a match.
Our product teams own their own infrastructure. They write their own Terraform, run their own pipelines and deploy themselves, and we intend to keep it that way.
This role owns the platform layer they build on: the AWS account model, identity and access, secrets, agent infrastructure, guardrails, observability, reliability and cost across a multi-account AWS organisation serving regulated customers.
Deep AWS rather than broad cloud, including Organizations and service control policies. Infrastructure as code in production: Terraform, CloudFormation, Pulumi or similar, we use Terraform. Containers in production, Docker and orchestration on AWS. Real experience with identity and single sign-on, Auth0 in particular if you have it. Infrastructure hardening and vulnerability management as an operational discipline rather than a report you forward. Comfort in Node.js or Bash, because this role automates manual work away rather than absorbing it. Observability tooling such as CloudWatch, Better Stack or Datadog, with enough judgement to standardise on one and defend the choice. CI systems: Buildkite, GitHub Actions, GitLab CI, Jenkins or similar, we use Buildkite. And comfort defining standards that other teams build against.
We also want someone who has thought seriously about agent infrastructure. We are connecting AI agents to internal systems, and the hard problems there are credential scoping, audit and blast radius rather than prompts. If you have opinions about what a non-human identity should and should not be allowed to hold, we want to hear them.
Having supported a compliance or certification effort, ISO 27001 or similar, is a strong plus. So is being able to explain an infrastructure trade-off and what it costs to someone who does not work in infrastructure. Experience with regulated customers is useful but not required.
The AWS account model: provisioning, service control policies, region policy, tagging and naming conventions across the organisation
Identity and access across the full lifecycle, creation, review and removal, and the move to single sign-on
Secrets management: one place secrets live, with automated rotation for service credentials
Vulnerability management and hardening of the infrastructure itself: baselines, image and runtime currency, segregation and isolation, and the scanning and enforcement point for container and dependency findings
Agent infrastructure: secure, reliable infrastructure connecting AI agents to internal systems, balancing autonomy with control. You control who can invoke what and that it is logged, not what is asked
One observability standard across products for logging, alerting, monitoring and tracing, and an alerting model where cost, security and infrastructure alerts have a named owner and a defined action
Reliability and continuity: backup policy, scheduled restore testing, disaster recovery, infrastructure and container health monitoring, and the escalation path when something breaks
Cost: visibility per account and service, anomaly response, and the budgets and spending limits that prevent a surprise rather than report one
Cross-product services outside application code: CI, DNS, certificates and domains. The CI platform decision sits with this role. We run Buildkite today
Our services all cater to the Pharma and healthcare space with multiple SaaS services and a set of upcoming LLM based solutions.
Anthill is on an ambitious growth path and is an exciting place to work. If you have the right experience and is looking for a dynamic workplace, great colleagues and an international environment, please contact us.
In our centrally located Copenhagen office, you will be part of a close-knit team where designers and copywriters work side by side with strategists, medical writers, communication architects, developers and project managers. You will have many opportunities to apply your expertise and experience while developing your professional skills.
You will be part of an international team of more than 15 nationalities, where English is both the official and the colloquial language in our office.
A transformational content excellence company dedicated to the pharma sector
Enabling global healthcare companies to access the full potential of digital technology
Building content ecosystems that power HCP engagements around the world
Optimising content supply chains and removing complexity to speed MLR and increase production volume
Providing fully-supported technology products that unlock new opportunities for pharma marketers
Enabling companies to provide high quality, personalised engagements at scale
Shaping the future of marketing in life science.