Role Summary
The Cloud Engineer provides day-to-day support for Cigna's cloud estate, covering existing application VMs and containers along with the additional cloud services that will be onboarded to the team over time. AWS is the primary platform, but the estate is multi-cloud and hybrid, so we are looking for someone whose interest goes beyond AWS alone.
This is a support role rather than a project delivery role, but while the support workload is still low there is scope to work alongside the architecture team on more than just onboarding - helping with design input, build work, proof of concepts and testing. The balance will shift back towards support as more services transfer to the team.
The role also upskills and coaches the existing infrastructure operations team so cloud knowledge is shared rather than held by one person, and works alongside on-premises engineering colleagues across the wider hybrid estate.
Key Responsibilities
- Provide second- and third-level support for AWS workloads, and for Azure and other cloud platforms as they come into support, covering compute, storage, networking, identity, serverless and monitoring services.
- Support existing application VMs and containerised workloads, including EKS, covering patching, backup, monitoring and routine operational tasks.
- Respond to incidents, carry out root cause analysis and see resolution through to a high standard.
- Build the support model for new workloads as they are onboarded, covering runbooks, monitoring, alerting, operational controls and handover criteria. This is the main focus of the first few months.
- Work closely with the architecture and project teams so new services are secure, supportable and genuinely production ready before they transfer to the team.
- During quieter periods, support the architecture team more broadly - design input, build work, proof of concepts and testing - rather than onboarding activity alone.
- Support the security of cloud assets - patching, vulnerability remediation, hardening and audit evidence - in line with Cigna standards and regulatory requirements.
- Support backup and data protection for cloud workloads, including recovery testing and resilience of supported services.
- Maintain and extend infrastructure as code in Terraform, and automate repeatable operational tasks using Python, Bash or PowerShell, making use of AI and automation tooling where it removes manual effort.
- Manage accounts, RBAC and policy compliance in line with global standards, and keep an eye on cloud cost and usage, flagging and progressing optimisation opportunities.
- Support the migration of traditional on-premises services to cloud and take them into stable support afterwards.
- Upskill and coach the existing infrastructure operations team so cloud workloads can be supported across the wider team.
- Produce and maintain documentation, runbooks and knowledge articles for supported services.
- Act as the escalation point to cloud vendor support and take part in the on-call rota and coverage across international time zones.
- Identify and progress service improvement opportunities and take part in post-incident reviews.
Key Working Relationships
- Infrastructure Operations and Infrastructure Engineering - day-to-day operational delivery, escalation, coverage and knowledge sharing.
- Architecture, project and application teams - onboarding of new services and agreement of support requirements before handover.
- Security, compliance and cloud vendor support - controls, vulnerability remediation, audit evidence and vendor escalation.
Skills, Experience & Requirements
Essential
- Strong AWS experience from an infrastructure support perspective in a large enterprise environment, including troubleshooting, patching and day-to-day operation of cloud-hosted services.
- Azure experience is heavily preferred, but not essential for the right candidate. We are looking for someone with a genuine interest in more than one cloud platform.
- Hands-on support of Windows and Linux servers, both cloud-hosted and on-premises.
- Terraform experience is a must, including maintaining and extending existing infrastructure as code.
- Scripting in Python, Bash or PowerShell.
- Containerisation experience, including EKS or an equivalent managed Kubernetes service in production. EKS is one of the services due to be offered by the team, so this is a must.
- Good understanding of cloud security, identity and access management, patching and vulnerability management.
- Backup and data protection experience in an enterprise environment, with a good general understanding of recovery and resilience, rather than any one product or approach.
- Experience of migrating traditional on-premises services to cloud.
- Experience with monitoring and logging tools.
- Cloud financial acumen - understanding cloud billing and licensing models, tracking spend against budget and identifying savings.
- Practical use of AI and automation tooling in a cloud context, for example scripting assist