Platform Engineer Job Description for Offshore Contractor in Cloud Infrastructure and CI/CD Development Role Summary We are looking for a Platform Engineer to join our Platform Engineering team in a supporting capacity. This role focuses on cloud infrastructure automation, CI/CD pipeline development, security remediation, and operational tooling in a regulated financial services (fintech/banking) environment running on AWS. Primary Responsibilities CI/CD Pipeline Development — Build and maintain Jenkins declarative/scripted pipelines (Groovy shared libraries), including deployment orchestration, build validation, and automated approval gates Infrastructure as Code — Write, plan, and apply Terraform modules across multiple AWS accounts, environments, and regions (us-east-1 / us-west-2) AWS Operations — Manage and automate resources across EC2, ECS, S3, CloudFront, DynamoDB, Lambda, IAM, KMS, Secrets Manager, Elastic Cache, Route 53, and ACM Security & Vulnerability Remediation — Triage and resolve Veracode/Qualys scan findings (CVEs in Node.js dependencies), patch Docker base images, rotate secrets, and harden EC2 instances Monitoring & Alerting — Configure Grafana dashboards, Prometheus metrics, CloudWatch alarms, OpsGenie routing, and AWS Synthetic Canaries Disaster Recovery — Support multi-region DR testing, failover/failback automation, database replication validation, and endpoint health checks Environment Management — Manage configurations across dev, QA, CAT, pre-prod, and production stages including DynamoDB config items, ECS task definitions, and CloudFront distributions Required Technical Skills Cloud AWS (EC2, ECS, S3, CloudFront, Lambda, DynamoDB, IAM, KMS, Secrets Manager, ElastiCache, Redshift, Route 53, ACM, SSM, Config) IaC Terraform (modules, state management, multi-backend, workspaces, -replace workflows) CI/CD Jenkins (declarative + scripted pipelines, Groovy shared libraries, Plugin Manager API, build locks) Containers Docker (image builds, ECR, ECS Fargate/EC2 launch types) Scripting Bash/Shell (primary), Python (Lambda functions, automation scripts), Groovy Identity & Auth Auth0, OIDC client configuration, SAML SSO (Entra ID / Okta), secret rotation workflows Monitoring Grafana, Prometheus, CloudWatch, OpsGenie, AWS Synthetic Canaries, Vector Source Control Git, Bitbucket (PRs, pipelines), Nx build system familiarity a plus Networking DNS management, CloudFront distributions, ALB/NLB routing, Akamai CDN, proxy configuration Databases DynamoDB (config management), familiarity with Oracle and Redshift is a plus Security CVE analysis, dependency vulnerability remediation (Node.js/npm ecosystem), iptables, IMDSv2, certificate management Required Experience 3+ years hands-on with AWS infrastructure at scale (multi-account, multi-region) 2+ years writing Terraform for production workloads 2+ years building/maintaining Jenkins pipelines (Groovy) Strong shell scripting (automating deployment, patching, and validation workflows) Experience with Node.js/JavaScript ecosystem (enough to triage dependency vulnerabilities and upgrade packages) Working knowledge of multi-environment promotion models (dev QA CAT prod) Comfortable working in a regulated environment (financial services, PCI awareness is a plus) Preferred / Nice-to-Have Experience with mobile CI/CD (Xcode builds, Fastlane, Appdome, CocoaPods) Familiarity with Auth0 tenant management, Terraform Auth0 provider and Azure Entra. AMI baking and patching automation (Packer or equivalent) WordPress hosting operations DR runbook execution experience Work Style Expectations Process-driven: follow documented runbooks, checklists, and standard operating procedures Produce clear documentation for any new automation or process All work is documented and code changes always linked to Jira task. Work independently once given context, escalate when blocked Comfortable with on-call rotation support (investigation, restarts, escalation) Coordinate with on-shore Platform Engineering leads for prioritization and review