Staff Platform Engineer

First American (India)

India

On-site

INR 2,800,000 - 5,000,000

Full time

31 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

First American (India) Private Limited seeks a senior platform engineer to own AWS architecture, drive security-by-default, and shape IaC patterns across AWS and Azure. You will coordinate with Azure Platform Engineering to align landing zones, governance, and cost controls while mentoring engineers and advancing multi-cloud guardrails.

The role emphasizes leadership in kubernetes data services, Terraform module standards, and a product-minded approach to deliver secure, scalable platform

Qualifications

  • 12+ years in platform/cloud engineering with enterprise-scale AWS experience.
  • Proven multi-cloud exposure with Azure platform engineering in regulated environments.
  • Expertise in Terraform modules, IaC governance, and CI/CD pipelines.

Responsibilities

  • Own end-to-end AWS platform architecture including orgs, Control Tower, and security posture.
  • Coordinate with Azure Platform Engineering to align landing-zone designs and cost governance.
  • Define and enforce platform principles: security-by-default, IaC-only deployments, least privilege.
  • Lead multi-cloud networking patterns (Direct Connect, ExpressRoute, Private Endpoints).
  • Drive policy-as-code, IAM policies, and Well-Architected reviews across AWS and Azure.
  • Mentor engineers and collaborate with multiple platform teams to unify guardrails.

Skills

Cloud platforms
Terraform IaC
Security & compliance

Tools

GitHub
CloudPlatform tooling

Job description

First American ( India) Private Limited (“FAI”) is a Global Capability Centre (GCC) of the First American Financial Corporation (FAF: NYSE) a leading provider of title insurance, settlement services and risk solutions for real estate transactions since 1889. FAI delivers Software Development, IT Infrastructure, Data & Analytics, back-office, and knowledge-processing operations to support First American's global operations across the US, UK, Australia & Canada. We build technology that powers millions of real-estate transactions, with a people-first culture that encourages innovation, collaboration, and solving real-world problems at scale.

ABOUT THE ROLE

You will be the technical lead for First American’s enterprise AWS platform powering application modernization, with strong multi-cloud exposure across AWS and Azure. You will define strategy and reference architectures with a strong product mindset, lead complex designs (networking, security, identity, observability, centralized root account management, and org-wide Config and GuardDuty on AWS; Management Groups, Azure Policy and Entra ID RBAC/PIM on Azure), and guide multiple squads building a secure, compliant, self-service platform. You will take end-to-end ownership, hold yourself accountable for outcomes, communicate clearly across stakeholders, mentor engineers, and collaborate with AWS, Azure, and GCP Platform Engineering teams and our centralized point of presence to align guardrails and shared patterns across clouds.

RESPONSIBILITIES

  • Own the end-to-end AWS platform architecture (Organizations/OU model, Control Tower and AVM account vending, identity, network, security, observability, cost) and its roadmap.
  • Partner with Azure Platform Engineering to align landing-zone design: Azure Management Groups, subscription vending/Enterprise Scale, identity, network, security, observability, and cost governance.
  • Set and enforce platform principles across AWS and Azure: security-by-default, IaC-only (Terraform with CloudFormation/Bicep/ARM where appropriate), least privilege, and defense-in-depth for workloads.
  • Lead AWS hub-and-spoke networking: Direct Connect/Partner connectivity, centralized DNS, policy-based routes, Palo Alto security inspection, and centralized VPC interface endpoints.
  • Align Azure hub-and-spoke networking patterns: ExpressRoute/Partner connectivity, Azure Virtual WAN, centralized DNS, policy-based routing, Palo Alto inspection, and centralized Private Link/Private Endpoints.
  • Define and govern AWS SCPs, IAM policies, and permission boundaries; drive policy-as-code, exception processes, and AWS Well-Architected reviews.
  • Align Azure governance: Azure Policy, deny assignments, RBAC least-privilege design, policy-as-code, exception processes, and Azure Well-Architected reviews.
  • Own centralized AWS root account management strategy: no routine root access, secured credentials, activity monitoring, and audited break-glass aligned with InfoSec and compliance requirements.
  • Support Azure tenant/subscription break-glass controls: secured privileged access, PIM/JIT governance, activity monitoring, and audited emergency access aligned with InfoSec.
  • Define org-wide AWS Config and GuardDuty architecture (delegated admin, aggregators, conformance packs, auto-remediation, threat detection baselines) integrated with Security Hub and operational response.
  • Align Azure security posture: Microsoft Defender for Cloud, Azure Policy compliance, auto-remediation, threat detection baselines, and integration with Security Hub-equivalent operational response.
  • Direct AWS identity architecture: IAM Identity Center with Entra ID (SAML), workload roles and OIDC for keyless auth across CI/CD and services; break-glass model with hardware MFA.
  • Align Azure identity architecture: Entra ID (Azure AD) federation, group-based RBAC, PIM/JIT access, managed identities, workload OIDC for keyless CI/CD, and AKS workload identity.
  • Own AWS observability architecture: org-level CloudTrail and log aggregation → streaming → Splunk/Elastic; ensure coverage for management, data, VPC flow, DNS, firewall, Config, GuardDuty, and Security Hub findings.
  • Align Azure observability: Activity Log, Diagnostic Settings, Azure Monitor, VNet flow logs, DNS/firewall logs → streaming → Splunk/Elastic; ensure Defender for Cloud and policy compliance coverage.
  • Partner with InfoSec on unified posture management across AWS (Security Hub, Config, GuardDuty) and Azure (Defender for Cloud, Azure Policy), plus Prisma Cloud and Qualys; define controls, SLAs, and drift remediation.
  • Drive multi-cloud patterns and guardrails consistent across AWS, Azure, and GCP; harmonize landing-zone, identity, networking, and security models and shared Blueprint/Modules standards.
  • Define modernization paths for AWS (EKS, ECS, RDS, data services) and Azure (AKS, Container Apps, Azure SQL, data services) with consistent platform patterns.
  • Champion AI-assisted engineering (Claude, Cursor) and agentic automations for platform delivery, documentation, and operational excellence across AWS and Azure.
  • Lead Terraform IaC migration strategy, module standards, and pipeline governance (GitHub; Spacelift where adopted) for AWS and Azure workloads.
  • Apply a strong product mindset: prioritize platform capabilities that deliver measurable value to application teams, balance roadmap trade-offs, and translate technical work into clear outcomes and adoption.
  • Mentor and develop senior and mid-level engineers through design reviews, pairing, and career guidance; model accountability, ownership, and high-quality delivery.
  • Collaborate across Platform Engineering teams (AWS, Azure, GCP, Blueprint and Modules, DNA Enablement) to align standards, shared patterns, and multi-cloud guardrails.
  • Design and manage AWS multi-account strategy using AWS Organizations with OU hierarchy aligned to environment, business unit, and workload classification.
  • Implement and maintain AWS Control Tower or a custom landing zone for account vending and baseline configuration.
  • Define and execute strategic roadmaps for AWS and Azure cloud platforms, aligning cloud adoption with business objectives, optimizing cost and performance, and ensuring scalability, security, and compliance across environments.
  • Communicate effectively with engineering, InfoSec, operations, and leadership; represent the AWS platform and multi-cloud alignment in architecture councils, CAB, and executive updates.

QUALIFICATIONS

  • 12+ years in platform/cloud engineering with 6+ on AWS at enterprise scale; proven multi-cloud exposure with hands-on Azure platform engineering in regulated environments.
  • Expert in Terraform (modules, workspaces), IaC governance (policy-as-code/OPA), and CI/CD (GitHub
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Azure Cloud Platform Engineering AM
Azure Cloud Platform Engineering AM

Promaynov Advisory Services Pvt. Ltd • Hyderabad

On-site
INR 2,400,000 - 4,200,000
AWS Platform Engineer
AWS Platform Engineer

SRS Infoway • Pune District

On-site
INR 900,000 - 1,300,000
Senior Cloud Engineer
Senior Cloud Engineer

Engg • Bengaluru

On-site
INR 3,500,000 - 6,500,000
Senior Cloud Platform Engineer - CL
Senior Cloud Platform Engineer - CL

Endava • Karnataka

On-site
INR 2,000,000 - 3,000,000
Platform Manager
Platform Manager

ACG • Mumbai

On-site
INR 3,500,000 - 7,000,000
Cloud Platform Engineer -(Terraform | Azure | AKS | Networking)
Cloud Platform Engineer -(Terraform | Azure | AKS | Networking)

Qnity • Hyderabad

On-site
INR 1,500,000 - 3,000,000
Senior Cloud Platform Engineer - EN
Senior Cloud Platform Engineer - EN

Endava plc • India

On-site
INR 1,500,000 - 2,500,000
Senior Platform Engineer – AWS / Kubernetes / DevOps
Senior Platform Engineer – AWS / Kubernetes / DevOps

Inadev India • Kolkata District

On-site
INR 350,000 - 600,000
Cloud/Platform Engineer (AWS)
Cloud/Platform Engineer (AWS)

Sutherland • Chennai District

On-site
INR 1,500,000 - 2,500,000
DevOps Engineer
DevOps Engineer

EXL • Gurugram District

On-site
INR 4,500,000 - 9,000,000