Senior Devops Engineer (AWS)

Read-A-Thon

United States

On-site

USD 120,000 - 170,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Read-A-Thon is seeking its first dedicated AWS/DevOps engineer to own infrastructure, reliability, and deployment tooling across several live products. You’ll manage multi-account AWS architecture, modernize compute and databases, and lead security posture improvements while coordinating with in-house engineers and external partners.

You will build resilient deployment pipelines, implement zero-trust networking with Tailscale, and drive observability and incident response.

Qualifications

  • 5+ years in a DevOps/SRE/Infrastructure role with deep AWS experience and hands-on configuration.
  • Experience with real production incidents and RCA delivery across teams.
  • Strong Linux systems administration fundamentals.
  • Experience designing CI/CD pipelines and secrets management.
  • Ability to modernize legacy codebases while building reliability tooling.

Responsibilities

  • Own multi-account AWS architecture and IAM hygiene.
  • Manage EC2/LB/ASG and deployment pipelines with a modern app stack.
  • Administer Aurora/MySQL clusters, read replicas, and data pipelines.
  • Operate a zero-trust network and modern DNS/CDN infrastructure.
  • Lead CI/CD and secrets management migration across environments.
  • Improve observability with CloudWatch, alarms, and incident response runbooks.
  • Strengthen security posture including TLS and certificate lifecycle management.
  • Collaborate with in-house engineers and MSPs to support sibling properties.

Skills

AWS expertise
Incident response
Linux administration
CI/CD design
Secrets management
Multi-account AWS

Tools

GitLab CI/CD
Terraform
CloudFormation
SSM
Cloudflare

Job description

We're looking for our first dedicated, in-house AWS/DevOps engineer to own infrastructure, reliability, and deployment tooling across a portfolio of live, revenue-generating products. You'll be the technical owner for cloud infrastructure spanning multiple AWS accounts, supporting several distinct applications with their own architectures and audiences —plus the shared services that cut across all of them.


What you'll own


  • Multi-account AWS architecture — administer and harden a multi-account AWS Organization (production, development, and monitoring accounts) with least‑privilege IAM, proper root/administrative credential hygiene, and durable secrets management (moving us off ad-hoc password storage and onto a real secrets manager).

  • Compute & sizing — manage EC2 fleets behind Application Load Balancers, Auto Scaling Groups, and launch templates backed by a golden-AMI deployment pipeline; modernize legacy standalone instances toward containerized (ECR/ECS) or otherwise more resilient patterns where it makes sense.

  • Databases — administer Amazon Aurora MySQL clusters (multi-database, multi-tenant schemas) including read replica strategy, credential scoping (moving application traffic off shared/master-level database users onto least-privilege service accounts), and CDC-based real‑time data pipelines (Epsio) feeding BI and marketing systems.

  • Networking & access — operate a Tailscale-based zero‑trust network (ACLs, subnet routers, tagged service identities) as our primary access layer, including migrating legacy DNS off a legacy registrar onto modern DNS/CDN infrastructure (Cloudflare / Route 53).

  • CI/CD — own and improve GitLab CI/CD pipelines (OIDC-based AWS role assumption, environment‑scoped deploys, secrets‑as‑CI‑variables) across a PHP monolith and a Laravel application; drive the migration of hardcoded application secrets into properly managed CI/CD variables and parameter stores.

  • Observability & incident response — build out real monitoring where gaps exist today (CloudWatch Logs/Alarms/Synthetics, external uptime monitoring, WAF logging), define on‑call/runbook practices, and lead incident response for production issues, including root‑cause writeups.

  • Security posture — manage AWS WAF rules, resolve longstanding dependency/composer security advisories, own certificate lifecycle management (TLS, Apple Pay/payment‑processing certs), and generally reduce the accumulated operational risk of a fast‑growing, historically under‑resourced infrastructure.

  • Cross‑team support — work directly with a small in‑house engineering team and outside contractors, and interface with third‑party MSPs supporting sibling properties.


Our stack (what you'll actually touch)


  • AWS: EC2, Aurora MySQL (RDS), Application Load Balancer, Auto Scaling Groups, S3, Storage Gateway, ElastiCache (Memcached), CloudWatch (Logs, Alarms, Synthetics, Internet Monitor), Systems Manager (Session Manager, Parameter Store), IAM & AWS Organizations, SES, WAFv2, CloudFormation

  • Application layers: Legacy PHP (no framework) and Laravel (PHP framework); Apache/PHP‑FPM and nginx; Composer dependency management

  • Networking: Tailscale (zero‑trust mesh VPN, ACL policy management), Cloudflare (DNS/CDN), legacy DNS providers (migration in progress)

  • CI/CD & tooling: GitLab CI/CD, OIDC-based cloud role assumption, PhpStorm/JetBrains tooling, LastPass (transitional— a real secrets manager is part of the roadmap)

  • Third‑party integrations: Payment processing (CardPointe/CardConnect, Apple Pay, Google Pay, PayPal), SMS/messaging (Twilio, Plivo), CRM/marketing (HubSpot), accounting exports


What you bring


  • 5+ years in a DevOps/SRE/Infrastructure role with deep, hands‑on AWS experience (not just \"used AWS\" — configured IAM policies, debugged Aurora replication, tuned Auto Scaling, written CloudFormation/Terraform from scratch).

  • Real production incident experience: you've diagnosed a live outage under pressure, found the actual root cause (not just the symptom), and closed every downstream copy of the fix (config, image/AMI, and CI/CD source of truth) — not just the first thing that unblocked traffic.

  • Strong Linux systems administration fundamentals — filesystems, systemd, log management, disk/volume operations, recovering access to a box when the \"normal\" path (SSH key, SSM agent) isn't available.

  • Experience with CI/CD pipeline design (GitLab CI/CD strongly preferred) and secrets management done right.

  • Comfort working across old and new: you can support and gradually modernize a 10+ year old PHP codebase while also building out reliability tooling for a newer Laravel application, without treating either as beneath you.

  • Excellent judgment around production risk — knowing when to move fast, when to get a second pair of eyes, and how to communicate a live incident clearly to non‑technical stakeholders.


Nice to have


  • Experience with CDC/real‑time data replication tools (Debezium, Epsio, or similar).

  • Experience with Tailscale or another zero‑trust/mesh VPN platform.

  • Prior experience being the first dedicated DevOps hire at a company — you like building the practices, not just following them.

  • Experience using AI coding/ops tools (e.g., Claude Code or similar) as part of your actual workflow — for infrastructure investigation, incident diagnosis, or accelerating day‑to‑day DevOps work, not just general familiarity with AI chatbots.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevOps Engineer
DevOps Engineer

OMW Consulting • United States

On-site
USD 120,000 - 180,000
DevOps Engineer
DevOps Engineer

Worky • Norwalk (CT)

On-site
USD 140,000 - 200,000
DevOps Engineer
DevOps Engineer

Oxbridge Health, Inc. • Norwalk (CT)

On-site
USD 120,000 - 160,000
Senior Software Engineer, Platform (Developer Experience)
Senior Software Engineer, Platform (Developer Experience)

Ecp123 • Chicago (IL), Northern (KY)

Hybrid
USD 140,000 - 210,000
Sr. Site Reliability Engineer
Sr. Site Reliability Engineer

Staffing Science • Arizona

On-site
USD 180,000 - 240,000
Senior Software Engineer, Platform (Developer Experience)
Senior Software Engineer, Platform (Developer Experience)

ECP • Chicago (IL)

On-site
USD 130,000 - 190,000
DevOps Engineer
DevOps Engineer

fullthrottle.ai® • United States

On-site
USD 120,000 - 180,000
DevOps Manager
DevOps Manager

Mills Thomas • United States

On-site
USD 100,000 - 130,000
Senior CloudOps & Site Reliability Engineer
Senior CloudOps & Site Reliability Engineer

MangoApps • Seattle (WA)

On-site
USD 110,000 - 150,000
Junior Full Stack Developer
Junior Full Stack Developer

re-zoo-me • Northern (KY)

Hybrid
USD 60,000 - 70,000