Senior Cloud Platform Architect – AWS

Jobtailor

California (MO)

On-site

USD 180,000 - 240,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Jobtailor seeks a seasoned Platform Engineer to lead containerization of a large-scale API estate for a financial services client. You will convert an approved AWS EKS reference into a secure, repeatable production platform with multi-AZ Auto Mode and golden path using VPC CNI, Karpenter, KEDA, Terraform, Helm, and Kustomize.

You will own Flux as the production delivery path with continuous reconciliation, signed digest-pinned images, and GitLab CI integration.

Qualifications

  • 12+ years in software, infrastructure, or platform engineering.
  • 5+ years of hands-on production Kubernetes on AWS, including EKS architecture, operations, networking, upgrades, scaling, and incident troubleshooting
  • Proven track record of standing up EKS platforms end to end and containerizing existing API workloads at enterprise scale
  • Strong Terraform, Helm, and Kustomize skills
  • Reusable platform-module design experience
  • Defensible architecture decisions and cross-team leadership in a regulated environment
  • Production service mesh ownership, including Istio architecture, policy, rollout, performance, and troubleshooting; Ambient mode especially relevant
  • Deep GitOps experience with continuous reconciliation, drift management, environment promotion, and Flux implementation
  • Practical Kubernetes and AWS security knowledge: PSS, policy as code, NetworkPolicy, IAM, KMS, certificate management, image signing, and SBOMs
  • API gateway and regulated audit/event-ingestion design experience; direct Tyk experience strongly preferred
  • Working knowledge of gRPC, HTTP/2, and Protobuf
  • Enough Java 21 / Spring Boot familiarity to review the reference runtime pattern
  • Observability depth across metrics, logs, traces, SLOs, and rollout analysis with OpenTelemetry
  • Performance validation at tens of thousands of TPS
  • Requires US Pacific hours overlap
  • Requires an escalation rotation during build-out
  • Requires client background screening
  • Nice to have: Tyk Operator/Pump and custom Go or gRPC plugins; Flux image automation; Flagger progressive delivery; Kinesis/Firehose/S3 Object Lock compliance-grade event capture; Graviton; Kubecost/OpenCost and cloud-cost optimization; Fluent Bit, AMP, Splunk, Honeycomb, Grafana; PCI-scoped, SOC 2, or fintech platform engineering; AWS Solutions Architect Professional; CKA/CKS

Responsibilities

  • Lead containerization and production platform initiatives for an enterprise client.
  • Architect and operate a secure, scalable EKS-based API platform across multiple AZs.
  • Oversee Flux as the production GitOps path with automated reconciliation and canaries.
  • Define and enforce security, observability, and compliance across the platform.
  • Coach platform, SRE, and application engineers and represent Opplane in client reviews.
  • Collaborate on architecture decisions and threat modeling for the fintech environment.
  • Maintain close alignment with code, pipelines, and operational data to validate platform operation

Skills

Kubernetes Architecture
AWS EKS Operations
Terraform
Helm
Kustomize
Istio Service Mesh
GitOps with Flux
Tyk
gRPC
Protobuf
OpenTelemetry
Production Troubleshooting
Security Policy Implementation
Multi-AZ EKS
Rate Limiting
Cross-Team Leadership
Coaching

Education

AWS Solutions Architect Professional
CKA
CKS

Tools

Flux
Kubernetes
Terraform
Helm
Kustomize
Tyk
GitLab CI
Artifactory
Kinesis
Ambiant mode Istio

Job description

  • Lead containerization of a large-scale API estate for an enterprise financial services client
  • Turn an approved AWS EKS reference architecture into a secure, repeatable production platform
  • Implement a multi-AZ EKS Auto Mode foundation and golden path using VPC CNI, Karpenter, KEDA, Terraform, Helm, and Kustomize
  • Implement Flux as the sole production delivery path with continuous reconciliation, signed digest-pinned images, GitLab CI, Artifactory, and Flagger SLO-gated canaries
  • Build and operate Istio Ambient service mesh with workload identity, strict mTLS, authorization, network policy, and measured latency and overhead
  • Govern north-south ingress through Tyk Self-Managed for authentication, rate limits, routing, REST-to-gRPC transcoding, and API migration
  • Implement security and audit capabilities using Pod Security Standards, Kyverno, EKS Pod Identity, Secrets Manager/CSI, KMS, cert-manager, image signing, SBOMs, Kinesis, Firehose, and S3 Object Lock
  • Establish gRPC/Protobuf east-west contracts with buf breaking-change checks
  • Build SLOs, error budgets, and OpenTelemetry metrics, logs, and traces into the platform
  • Write and review Terraform, Helm, Kustomize, Flux, and Istio policy
  • Produce architecture decision records, threat models, and standards
  • Coach platform, SRE, and application engineers
  • Represent Opplane in client architecture reviews
  • Keep close to code, pipelines, and operational data to validate platform operation
Requirements
  • 12+ years in software, infrastructure, or platform engineering
  • 5+ years of hands-on production Kubernetes on AWS, including EKS architecture, operations, networking, upgrades, scaling, and incident troubleshooting
  • Proven track record of standing up EKS platforms end to end and containerizing existing API workloads at enterprise scale
  • Strong Terraform, Helm, and Kustomize skills
  • Reusable platform-module design experience
  • Defensible architecture decisions and cross-team leadership in a regulated environment
  • Production service mesh ownership, including Istio architecture, policy, rollout, performance, and troubleshooting; Ambient mode especially relevant
  • Deep GitOps experience with continuous reconciliation, drift management, environment promotion, and Flux implementation
  • Practical Kubernetes and AWS security knowledge: PSS, policy as code, NetworkPolicy, IAM, Pod Identity, KMS, certificate management, image signing, and SBOMs
  • API gateway and regulated audit/event-ingestion design experience; direct Tyk experience strongly preferred
  • Working knowledge of gRPC, HTTP/2, and Protobuf
  • Enough Java 21 / Spring Boot familiarity to review the reference runtime pattern
  • Observability depth across metrics, logs, traces, SLOs, and rollout analysis with OpenTelemetry
  • Performance validation at tens of thousands of TPS
  • Requires US Pacific hours overlap
  • Requires an escalation rotation during build-out
  • Requires client background screening
  • Nice to have: Tyk Operator/Pump and custom Go or gRPC plugins; Flux image automation; Flagger progressive delivery; Kinesis/Firehose/S3 Object Lock compliance-grade event capture; Graviton; Kubecost/OpenCost and cloud-cost optimization; Fluent Bit, AMP, Splunk, Honeycomb, Grafana; PCI-scoped, SOC 2, or fintech platform engineering; AWS Solutions Architect Professional; CKA/CKS
Core Competencies

Demonstrates extensive expertise in Kubernetes and AWS EKS architecture, with a strong focus on containerization, security, and observability. Proven ability to lead cross-team initiatives and implement robust production platforms in regulated environments.

Highest-signal resume keywords
  • Kubernetes Architecture
  • AWS EKS Operations
  • Terraform, Helm, Kustomize
  • Istio Service Mesh
  • GitOps with Flux
ATS Optimization Keywords
Hard Skills
  • Containerization
  • API Design
  • Production Troubleshooting
  • Security Policy Implementation
  • Observability with OpenTelemetry
  • GRPC and Protobuf
  • Performance Validation
  • Multi-AZ EKS Auto Mode
  • Continuous Reconciliation
  • Rate Limiting
Soft Skills
  • Cross-Team Leadership
  • Coaching and Mentoring
  • Client Representation
Certifications & Qualifications
  • AWS Solutions Architect Professional
  • CKA
  • CKS
Industry Keywords
  • Financial Services
  • Regulated Environment
  • PCI Compliance
  • SOC 2
  • Event Ingestion
Tools & Technologies
  • AWS
  • Terraform
  • Helm
  • Kustomize
  • Istio
  • Flux
  • Tyk
  • GitLab CI
  • Artifactory
  • Kinesis
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Software Development Engineer – Platform & Infrastructure
Principal Software Development Engineer – Platform & Infrastructure

Jobtailor • California (MO)

On-site
USD 180,000 - 280,000
DevOps Engineer
DevOps Engineer

Jobtailor • San Antonio (TX)

On-site
USD 140,000 - 190,000
Cloud Architect, Solution Design Engineer
Cloud Architect, Solution Design Engineer

Jobtailor • California (MO)

On-site
USD 150,000 - 230,000
Platform Engineer
Platform Engineer

APN Consulting, Inc. • Jersey City (NJ)

On-site
USD 130,000 - 160,000
DevOps Engineer
DevOps Engineer

Jobtailor • Fort Meade (MD)

On-site
USD 120,000 - 180,000
Director – Technologies
Director – Technologies

Jobtailor • Arizona

On-site
USD 200,000 - 280,000
Senior Software Engineer, Infrastructure
Senior Software Engineer, Infrastructure

Jobtailor • California (MO)

On-site
USD 180,000 - 260,000
DevOps Engineer
DevOps Engineer

duPont REGISTRY • Miami (FL)

On-site
USD 120,000 - 180,000
Senior Infrastructure Engineer
Senior Infrastructure Engineer

Jobtailor • Arizona

On-site
USD 120,000 - 190,000
Senior Staff Engineer – DevOps
Senior Staff Engineer – DevOps

Jobtailor • California (MO)

On-site
USD 140,000 - 180,000