Senior Platform Engineer

ZERO

Denver (CO)

On-site

USD 120,000 - 190,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Competitive salary
Health benefits
Flexible time off
Dynamic team environment
Impact on healthcare industry

Job summary

ZERO is seeking a Sr Platform Engineer to own the AWS estate that powers our healthcare platform. You will define standards, shape architecture, and turn infrastructure into consumable services for internal teams, with close collaboration to leadership.

You will drive production readiness, maintain runbooks, and mentor the team while documenting architecture and technical standards. The role sits in a fast-moving, small team focused on secure, scalable infrastructure for healthcare cost

Qualifications

  • Six or more years in cloud infrastructure engineering with AWS hands-on work.
  • Production experience authoring Terraform modules and IaC standards.
  • Container workloads with ECS, Fargate, or equivalent; multi-architecture builds.
  • Depth in AWS IAM: roles, policies, cross-account access; security mindset.
  • Backup/DR design and experience with failover testing.
  • Strong Linux fundamentals and scripting (Python/Go/Bash).
  • Experience integrating infra work with CI/CD pipelines.
  • Proven technical leadership: setting standards, reviewing work, mentoring.
  • Clear documentation habits and independent work style.

Responsibilities

  • Design, build, and operate AWS multi-account architecture including networking and storage.
  • Author and maintain Terraform modules and IaC standards; ensure reproducibility and version control.
  • Build consumable platform services for internal users; treat platform as a product.
  • Own AWS IAM and Identity Center: roles, policies, federation, permission sets.
  • Manage container base images and multi-architecture builds across workloads.
  • Implement security controls: least privilege, encryption, logging, and network segmentation.
  • Own backup architecture, DR runbooks, RTO/RPO targets, and failover cadence.
  • Monitor and observe via CloudWatch, Sumo Logic, and Datadog; sustain observability.
  • Run production readiness reviews for services transitioning in from Eng/Data.
  • Refactor prototypes into compliant products and own their lifecycle.
  • Write/maintain runbooks, architecture docs, and standards; mentor others.

Skills

AWS
Terraform
CI/CD
Linux scripting
Platform engineering
Documentation
Technical leadership
Security best practices
Multi-account AWS
Observability

Tools

Terraform
AWS
EC2 / ECS / Fargate
IAM
CloudWatch
Datadog
Sumo Logic

Job description

About ZERO

At ZERO, our mission is to simplify healthcare and eliminate financial barriers, ensuring that everyone has access to high-quality care at no cost. We work with self-funded employers and innovative healthcare providers to match members with the best healthcare options, enabling access to care for $0. Our vision is to create a world where healthcare works for everyone, empowering our clients and their employees to access care while reducing healthcare costs.

With offices in downtown Tulsa, OK, downtown Denver, CO, and a growing virtual team around the country, we are solving our country's healthcare cost problems by making healthcare for scheduled care simple, transparent, 100% accessible and affordable.

About the Role

We are looking for a Sr Platform Engineer to take senior technical ownership of the AWS estate that everything at ZERO runs on.

This is a build role with real scope. You will write the standards the platform is built to, shape its architecture, and turn infrastructure into consumable services that the rest of the company can use without filing a ticket. Our architecture is sound and our practices are established; what we do not yet have is a dedicated senior engineer for it. That is the job.

To be straight with you about how decisions get made: you author the standards and give the architectural direction, and the Director approves the standards and holds the final call on architecture this year. You will have close access to that decision and your recommendations will carry weight. If you are looking for unchecked architectural authority on day one, this is not that role yet.

You will also own how internal software becomes real. Our operators build prototypes, our engineering and data teams build services, and this role decides what is ready to run in production and rebuilds what is not. If you have wanted to define a production readiness bar and actually hold it, this role has that authority.

We are a small team, which means you will have unusual latitude and you will not be far from any decision. It also means we care a great deal about documentation, because the standards you write are the standards we work to.

Responsibilities
  • Design, build, and operate our AWS multi-account architecture: account structure, networking, compute on EC2 and ECS/Fargate, and storage.
  • Author and maintain Terraform modules and write the infrastructure-as-code standards that keep the estate reproducible, reviewable, and version controlled.
  • Build and operate consumable platform services for internal consumers, treating the platform as a product with users rather than a queue with tickets.
  • Own AWS IAM and AWS IAM Identity Center: roles, policies, permission boundaries, federation, permission sets, and cross-account access patterns.
  • Manage container base images across engineering and infrastructure workloads, including multi-architecture builds.
  • Implement security controls across the estate: least privilege, encryption and key management, network segmentation, and complete logging coverage. Build paved paths so the secure option is also the easiest one.
  • Own backup architecture, disaster recovery runbooks, RTO and RPO targets, and failover testing on a documented cadence.
  • Own capacity planning, monitoring, and observability coverage across CloudWatch, Sumo Logic, and Datadog.
  • Run the production readiness review for services transitioning in from Engineering or Data & Analytics, including the authority to send one back.
  • Rebuild validated internal prototypes into supportable, compliant products, and own their lifecycle afterward.
  • Author technical standards, review infrastructure changes and Terraform contributions, and provide technical direction and mentorship to the Platform Engineer.
  • Write and maintain runbooks, architecture documentation, and standards.
Qualifications
  • Six or more years in cloud infrastructure engineering, the majority of it hands-on with AWS.
  • Production experience authoring Terraform modules and setting IaC standards, not only consuming them.
  • Container workload experience with ECS, Fargate, or equivalent, including image lifecycle and multi-architecture builds.
  • Depth in AWS IAM: roles, policies, permission boundaries, and cross-account access patterns.
  • Backup and disaster recovery design experience, including having personally run a failover or recovery test.
  • Strong Linux fundamentals and scripting in Python, Go, or Bash.
  • Experience integrating infrastructure work with CI/CD pipelines.
  • Demonstrated technical leadership: setting standards others follow, reviewing others' work, and developing less experienced engineers.
  • Clear written documentation habits. This role produces the standards the team is held to.
  • Thrive in a small team environment and possess a strong ability to independently manage and prioritize work with minimal supervision, while collaborating effectively when needed.
Bonus Points
  • Experience in Healthcare or another heavily regulated industry, particularly HIPAA, SOC 2, or HITRUST.
  • Go development experience.
  • Observability tooling at scale.
  • Internal developer platform or platform-as-a-product experience.
  • Secrets management and KMS-based key management.
  • Relevant certifications such as AWS Solutions Architect Professional or AWS DevOps Engineer Professional.
What We Offer
  • Competitive salary and performance-based bonuses
  • Comprehensive health benefits package
  • Flexible time off policy
  • A supportive and dynamic team environment
  • The opportunity to make a meaningful impact on the healthcare industry
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Platform Engineer: AWS Platform as a Product
Senior Platform Engineer: AWS Platform as a Product

ZERO • Denver (CO)

On-site
USD 120,000 - 190,000
Competitive salary
Health benefits
Flexible time off
+2
IT Support Specialist
IT Support Specialist

ZERO • Denver (CO)

Hybrid
USD 60,000 - 80,000
Competitive salary
Comprehensive health benefits
Flexible time off
+1
Senior Platform Engineer (Python/AWS) - HealthTech
Senior Platform Engineer (Python/AWS) - HealthTech

Evolution USA • Boston (MA)

On-site
USD 150,000 - 210,000
Senior DevOps / Platform Engineer
Senior DevOps / Platform Engineer

Flexhire • United States

On-site
USD 140,000 - 190,000
Senior Platform Engineer
Senior Platform Engineer

LifeMD • Huntington Beach (CA)

On-site
USD 102,000 - 170,000
Health Care Plan
Retirement Plan
Life Insurance
+4
Senior Platform Engineer
Senior Platform Engineer

Epsilon ASI • Denver (CO), Northern (KY)

Hybrid
USD 130,000 - 180,000
Senior Platform Engineer
Senior Platform Engineer

Ours Privacy • Northern (KY)

Hybrid
USD 140,000 - 210,000
Senior Platform Engineer
Senior Platform Engineer

Epsilon ASI • United States

On-site
USD 130,000 - 180,000
AWS DevOps Engineer
AWS DevOps Engineer

Decca Consulting LLC • Norwalk (CT)

On-site
USD 120,000 - 160,000
Infrastructure Engineer
Infrastructure Engineer

Sabenza IT & Recruitment • Mayville (ND)

Hybrid
USD 130,000 - 170,000
Flexible hours
Remote/on-site flexibility
Modern offices
+1