- Design, build, and evolve multi-account AWS infrastructure using automation and infrastructure as code
- Own production infrastructure changes from design through implementation, validation, documentation, and operational support
- Build and operate Kubernetes and EKS platforms, including cluster lifecycle management, container image security, runtime controls, observability, and workload onboarding
- Modernize network architecture and connectivity using VPCs, Transit Gateway, PrivateLink, VPC endpoints, Route 53, network firewalls, and secure egress controls
- Strengthen AWS identity and organization governance through account provisioning, IAM roles, permission boundaries, service control policies, access-key hygiene, and secrets rotation
- Improve production visibility and stability through Grafana, Prometheus, distributed tracing, logging improvements, proactive monitoring, incident response, and root-cause analysis
- Advance CI/CD and software supply-chain practices, including GitHub Actions, OIDC, secure runners, artifact management, package controls, and retirement of legacy delivery tooling
- Improve resiliency, compliance, and operational efficiency through backup and recovery controls, vulnerability remediation, Terraform drift management, audit evidence, and responsible AI-assisted automation
- Serve as a trusted technical escalation point for complex infrastructure issues
- Explain infrastructure decisions and tradeoffs to technical and non-technical partners
- Help colleagues apply AI tools responsibly
Requirements
- 4+ years of experience designing, building, and operating production cloud infrastructure
- Deep hands-on expertise in AWS
- Bachelor's degree or higher, or equivalent combination of education and work experience
- Extensive experience owning complex, multi-account AWS environments
- Deep knowledge of AWS networking, identity, security, compute, storage, databases, organizations, and governance
- Experience with Terraform or comparable infrastructure-as-code tools
- Production experience with Kubernetes or EKS
- Experience with cluster lifecycle management, upgrades, workload delivery, container security, observability, and runtime controls
- Ability to diagnose complex infrastructure issues across networking, DNS, IAM, Kubernetes, CI/CD, security controls, and application delivery
- Experience owning production changes through implementation, validation, documentation, incident support, and operational maintenance
- Hands-on experience using AI tools for infrastructure work with appropriate security, validation, and human oversight
- Local hours (PT or MT)
- Nice to have: regulated financial-services infrastructure experience
- Nice to have: PCI DSS, CIS controls, security audits, evidence collection, or remediation programs
- Nice to have: data center to AWS migrations
- Nice to have: managed file transfer, SFTP, secure partner integrations, or high-volume data-processing platforms
- Nice to have: GitHub Actions, Jenkins, Argo CD, JFrog Artifactory, Splunk, Grafana, Prometheus, Tempo, Wiz, or CrowdStrike
- Nice to have: Python, Bash, or another infrastructure automation language
- Nice to have: AWS certification or equivalent demonstrated cloud expertise
Core Competencies
Demonstrates expertise in designing and operating multi-account AWS infrastructure, with a strong focus on automation, security, and compliance. Proficient in Kubernetes and EKS management, along with a solid understanding of CI/CD practices and infrastructure as code.
Highest-signal resume keywords
- AWS Expertise
- Kubernetes Management
- Infrastructure As Code (Terraform)
- CI/CD Practices (GitHub Actions)
- Network Architecture Modernization
ATS Optimization Keywords
Hard Skills
- AWS
- Kubernetes
- EKS
- Terraform
- CI/CD
- Networking
- IAM
- Container Security
- Observability
- Incident Response
Soft Skills
- Technical Communication
- Problem Solving
- Collaboration
Certifications & Qualifications
Industry Keywords
- PCI DSS
- CIS Controls
- Security Audits
- Regulated Financial-Services Infrastructure
Tools & Technologies
- GitHub Actions
- Grafana
- Prometheus
- Splunk
- Jenkins
- Argo CD
- JFrog Artifactory