Senior Cloud / AWS Infrastructure Engineer

Reflex Media Inc

Las Vegas (NV)

Hybrid

USD 130,000 - 180,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Reflex Media Inc (Seeking.com) is hiring a Senior Cloud / AWS Infrastructure Engineer to build, operate, and secure our AWS environment. The role focuses on multi-account architecture, secure IAM, and robust disaster recovery across regions, with Terraform-driven workflows and containerized workloads.

Remote work options available across the USA; occasional travel to Las Vegas for planning and team weeks. Compensation ranges from $130,000 to $180,000 base, with comprehensive benefits and growth

Qualifications

  • Five+ years building and operating production AWS infrastructure.
  • Strong Terraform with module design and remote state management.
  • Experience with AWS Organizations or Control Tower including SCPs.
  • Deep IAM design and least-privilege practice.
  • Production container experience on ECS or Kubernetes and relational databases.
  • Python or Bash for automation.
  • Experience migrating legacy infrastructure without downtime.
  • Clear writing and risk/cost judgment.
  • Daily use of Claude/Cowork in engineering workflow.

Responsibilities

  • Extend Terraform module library and AFT customization layers for secure, consistent account landing.
  • Design VPC, cross-account networking, and hub-and-spoke topologies.
  • Migrate legacy brand infra into current account structure and module standards.
  • Design cross-region disaster recovery and define RPO/RTO targets.
  • Standardize backup policy and run DR tests; write durable runbooks.
  • Define IAM boundary policies, SSO, and federated access strategies.
  • Operate monitoring, alerting, and cost visibility across the stack.
  • Improve CI/CD for infrastructure and keep landing zone current.

Skills

Five+ years AWS infra
Terraform
AWS Organizations/Control Tower
IAM least privilege
ECS/Kubernetes
Python or Bash
Clear writing
AI tooling (Claude)

Education

Bachelor's degree in CS/Engineering

Tools

Terraform
ECS
Kubernetes
Cloudflare

Job description

Senior Cloud / AWS Infrastructure Engineer

IT / Infrastructure | Full-Time, Salaried, Individual Contributor | Reports to Director of IT

Company Seeking.com (Reflex Media)

Location Remote, anywhere in the USA.

Compensation $130,000 to $180,000 base.

Schedule Three evenings per week (5:30 to 7:30 PM US Pacific) to overlap with our Singapore Dev and DevOps partners. Flexed time available during the day.

Travel Occasional travel to Las Vegas for planning, incident postmortems, and team weeks.

About the Role

Seeking.com is the world's largest premium dating platform, founded and led by an MIT alumnus and headquartered in Las Vegas. We are hiring a Senior Cloud / AWS Infrastructure Engineer to build, operate, and secure the AWS environment that runs our products.

The environment is AWS Organizations with Control Tower, accounts vended through Account Factory for Terraform, and governance applied through global and per-account customization layers. Infrastructure is Terraform, delivered through a versioned in-house module library. Workloads run across ECS Fargate, Aurora MySQL and PostgreSQL, ElastiCache, EFS, Lambda, OpenSearch, Redshift, MWAA, and Bedrock, with Cloudflare at the edge.

Disaster recovery. We are building cross-region DR for a flagship platform, essentially from the ground up. Today the platform is regionally concentrated. You will define the DR plan against real RPO and RTO targets, design and build the replication and failover path, and prove it with real exercises.

Security engineering. Identity hardening, replacing static credentials with federated and role-based access, extending preventive and detective controls, and turning findings into engineering fixes.

Who Should Apply
  • Senior Cloud or Platform Engineers at consumer subscription, marketplace, or SaaS companies who have run AWS Organizations at scale.
  • Site Reliability Engineers with a heavy IaC and security bias who have taken a regionally concentrated platform to cross-region DR.
  • DevOps Engineers from a Terraform-first shop who own module libraries other teams depend on.
  • Cloud Security Engineers who built the guardrails, the SCPs, and the federated access patterns their org runs on today.
What You Will Do
Cloud Architecture and Infrastructure as Code
  • Extend the Terraform module library and the AFT customization layers (VPC and IPAM allocation, private hosted zones, SSM access, backup vaults, account baselines) so new accounts land secure and consistent by default.
  • Design VPC architecture, cross-account networking, and shared services in a hub-and-spoke configuration model.
  • Migrate legacy brand infrastructure into the current account structure, state backend model, and module standards.
Disaster Recovery
  • Design and build cross-region recovery for a flagship platform: Aurora replication topology, cross-region backup copy, S3 and EFS replication, container image distribution, DNS failover, and region-parity IaC.
  • Establish RPO and RTO targets with the business, map dependencies into recovery tiers, and define restoration order.
  • Standardize backup policy and retention across the estate, including organization-level backup policy and centralized vaults.
  • Run scheduled DR tests and game days, and write runbooks that make recovery repeatable by anyone on call.
Security
  • Design least-privilege IAM policy and IAM Identity Center permission sets. Reduce standing access and direct assignments.
  • Replace long-lived IAM access keys with federated SSO, OIDC, and assumed-role access, including in CI/CD.
  • Author and maintain SCPs and organization controls, plus automated remediation where prevention is not possible.
  • Extend detective controls: AWS Config rules and conformance packs, Security Hub standards coverage, GuardDuty feature coverage, and consistent finding handling across regions.
  • Own secrets management on Secrets Manager and SSM Parameter Store, including rotation.
  • Support incident response and CloudTrail forensics, and convert findings into durable engineering fixes.
Reliability and Automation
  • Operate core infrastructure: monitoring, alerting, AWS Backup, and patch and lifecycle management.
  • Improve our Prometheus, Grafana, and Alertmanager stack and its CloudWatch alarm coverage so real issues page quickly.
  • Debug production issues across compute, storage, networking, and databases.
  • Automate operational work in Python and Bash, and improve CI/CD for infrastructure.
  • Keep Control Tower and the landing zone current, and contribute to cost visibility and optimization.
Required Qualifications
  • Five or more years building and operating production AWS infrastructure.
  • Strong Terraform in a team setting: module design and versioning, remote state, drift, and PR-based workflows.
  • Multi-account AWS Organizations or Control Tower experience, including SCPs and cross-account IAM.
  • Deep IAM: policy and trust-policy design, permission boundaries, and least privilege in practice.
  • Production container experience on ECS or Kubernetes, and managed relational databases.
  • Python or Bash for automation and tooling.
  • Experience migrating or consolidating legacy infrastructure without downtime, and the judgement to sequence that work safely.
  • Clear writing, and the judgement to weigh risk, cost, and delivery speed against each other.
  • Daily use of Claude, Claude Code, and Cowork in your engineering workflow.
Preferred Qualifications
  • AFT, Landing Zone Accelerator, or similar account-vending automation.
  • IAM Identity Center or SAML / OIDC federation with an external IdP.
  • Designing and testing cross-region DR against defined RPO and RTO targets.
  • Aurora operations at scale: replication topology, failover, and backup and restore.
  • Security Hub, GuardDuty, AWS Config, or SIEM-style CloudTrail analysis. EDR tooling such as CrowdStrike.
  • AWS Backup at organization scale, including cross-region and cross-account copy.
  • Cloudflare or a comparable CDN and WAF at the edge.
  • Data or AI workloads on AWS (Redshift, MWAA, Bedrock).
  • Working with distributed teams across time zones.
  • AWS certifications (Solutions Architect, SysOps, Security Specialty).
  • Bachelor's degree in Computer Science, Engineering, or a related field, or an equivalent operational track record.
How We Work
  • Infrastructure is code, reviewed in pull requests.
  • Human access to AWS is federated through SSO, short-lived, and least privilege by default.
  • Security, reliability, and cost are design inputs, not afterthoughts.
  • We fix the cause rather than automate around it.
  • Engineering work is tracked in Jira. Decisions and runbooks live in Confluence.
Why This Role Matters

Seeking.com serves more than 50 million members across more than 130 countries. The AWS environment behind that experience is what keeps the promise. This role is the senior engineer who makes sure a region-wide event does not become a member-facing event, and that our security posture matches the trust our members place in us. The work is consequential, the mandate is real, and the person who does it well earns more scope every quarter.

Compensation and Benefits

Base salary: $130,000 to $180,000, commensurate with experience.

99 percent coverage of medical, dental, and vision insurance. 65 percent coverage for qualified dependents. 100 percent coverage of short-term disability, long-term disability, and life insurance. 50 percent 401(k) match up to 6 percent per month. Flexible Spending Account. Flexible paid time off. Professional development budget covering AWS certifications and conferences.

Equal Opportunity Employer

Reflex Media is an equal opportunity employer committed to diversity and inclusion in the workplace. We strictly prohibit discrimination of any kind. Candidates are encouraged to apply for qualified positions regardless of race, color, sex, religion, sexual orientation, national origin, disability, genetic information, or any other protected characteristics as outlined by federal, state, or local laws. Hiring decisions are based solely on qualifications, merit, and the needs of the company. All offers of employment are contingent upon the completion of a full background and reference check.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cloud / AWS Infrastructure Engineer
Senior Cloud / AWS Infrastructure Engineer

Reflex Media, Inc. • United States

Remote
USD 130,000 - 180,000
Medical, dental, and vision insurance
Disability insurance
Life insurance
+4
Software Development Engineer, ADC2S
Software Development Engineer, ADC2S

Amazon Web Services (AWS) • Seattle (WA)

On-site
USD 144,000 - 194,000
Health insurance
Restricted Stock Units (RSUs)
401(k) matching
Sr Staff Cloud Engineer
Sr Staff Cloud Engineer

Versant Media, LLC • New York (NY)

On-site
USD 180,000 - 240,000
Sr. Security Services SA, AWS Industries - Customer Acceleration Team - Security Specialists
Sr. Security Services SA, AWS Industries - Customer Acceleration Team - Security Specialists

Amazon Web Services (AWS) • Austin (TX)

On-site
USD 177,000 - 239,000
Sr. Security Services SA, AWS Industries - Customer Acceleration Team - Security Specialists
Sr. Security Services SA, AWS Industries - Customer Acceleration Team - Security Specialists

Amazon Web Services (AWS) • Chicago (IL)

On-site
USD 177,000 - 239,000
Senior Solutions Architect, Strategic Accounts, Strategic Accounts
Senior Solutions Architect, Strategic Accounts, Strategic Accounts

Amazon Web Services (AWS) • East Palo Alto (CA)

On-site
USD 177,000 - 239,000
Health insurance
RSUs
401(k) matching
+1
Software Development Manager, Management Plane (AWS)
Software Development Manager, Management Plane (AWS)

Amazon • Seattle (WA)

On-site
USD 184,900 - 250,200
Health insurance
RSUs
Paid time off
+2
AMS Cloud Architect III, AWS Managed Services (AMS)
AMS Cloud Architect III, AWS Managed Services (AMS)

Amazon Web Services (AWS) • Herndon (VA)

On-site
USD 154,000 - 208,000
Sr. Systems Development Engineer , Secure Connection Services (SCS), Tactical Edge Mission Engineering Group (TEMEG)
Sr. Systems Development Engineer , Secure Connection Services (SCS), Tactical Edge Mission Engineering Group (TEMEG)

Amazon Web Services (AWS) • Herndon (VA)

On-site
USD 151,000 - 205,000
Senior Cloud Engineer
Senior Cloud Engineer

Pointwest Technologies Corp • Roseville (MN)

On-site
USD 120,000 - 150,000