Role description
Position Overview
We are looking for a highly skilled Infrastructure Engineer with strong expertise in AWS Cloud Infrastructure, Platform Engineering, DevOps, Cloud Security, and Infrastructure Automation. The ideal candidate will be responsible for designing, implementing, securing, and optimizing highly available, scalable, and cloud-native infrastructure on AWS.
This role will play a key part in building secure enterprise platforms supporting modern cloud applications, containerized workloads, and next-generation AI/GenAI services powered by Amazon Bedrock and AWS AgentCore. You will collaborate closely with Platform Engineering, DevOps, Security, Architecture, and Application teams to deliver resilient, compliant, and automated cloud environments aligned with enterprise standards.
Key Responsibilities 1. AWS Cloud Infrastructure & Networking
- Design, implement, and manage scalable AWS infrastructure following Well-Architected Framework best practices.
- Configure and maintain AWS networking services including:
- Amazon VPC
- Public & Private Subnets
- Route Tables
- Security Groups
- Network ACLs
- Internet Gateway
- NAT Gateway
- AWS Transit Gateway
- VPC Endpoints / AWS PrivateLink
- Amazon Route 53
- Application & Network Load Balancers (ALB/NLB)
- AWS WAF
- Amazon CloudFront
- Build highly available, fault-tolerant, and disaster recovery-ready cloud environments.
- Optimize network performance, security, and connectivity across multi-account AWS environments.
2. Infrastructure as Code (IaC) & Automation
- Develop reusable Infrastructure-as-Code modules using:
- Terraform
- AWS CDK
- AWS CloudFormation
- Automate infrastructure provisioning and lifecycle management.
- Implement infrastructure versioning, modularization, and reusable deployment patterns.
- Enforce governance through Policy-as-Code and automated compliance validation.
3. Platform Engineering & Container Services
- Deploy and manage cloud-native applications using:
- Kubernetes
- Amazon EKS
- Amazon ECS/Fargate
- Docker
- Build scalable and secure container platforms.
- Support application modernization initiatives and cloud-native platform adoption.
- Improve platform reliability, scalability, and operational efficiency.
4. AI / GenAI Infrastructure
- Provision and manage secure infrastructure supporting:
- Amazon Bedrock
- AWS AgentCore
- Design secure networking and access controls for AI workloads.
- Implement monitoring, logging, and operational controls for AI platform services.
- Collaborate with AI engineering teams to deliver scalable GenAI infrastructure.
5. Cloud Security & Compliance
- Design and implement AWS cloud security best practices.
- Configure and manage:
- AWS IAM
- AWS KMS
- AWS Secrets Manager
- Implement enterprise-grade security controls including:
- Mutual TLS (mTLS)
- OAuth 2.0 / OpenID Connect (OIDC)
- API Security
- Rate Limiting
- PHI Data Protection & Tokenization
- Ensure cloud infrastructure complies with organizational security standards and regulatory requirements.
6. Observability & Reliability Engineering
- Implement enterprise observability using:
- Amazon CloudWatch
- OpenTelemetry
- Develop dashboards, s, and operational runbooks.
- Perform production troubleshooting, root cause analysis (RCA), and incident remediation.
- Improve platform reliability through proactive monitoring and automation.
7. FinOps & Cloud Cost Optimization
- Monitor cloud resource utilization and infrastructure spend.
- Recommend and implement cost optimization strategies.
- Support cloud budgeting, forecasting, and governance initiatives.
- Optimize compute, storage, networking, and managed service costs without compromising performance.
8. DevOps & Collaboration
- Maintain Infrastructure-as-Code repositories using Git/GitHub.
- Integrate infrastructure deployments into CI/CD pipelines.
- Collaborate with Security, DevOps, SRE, Platform Engineering, and Application teams to deliver secure and automated cloud solutions.
- Promote DevSecOps best practices across engineering teams.
Required Technical Skills
- Amazon VPC
- Route 53
- Transit Gateway
- AWS PrivateLink
- ALB / NLB
- AWS WAF
- CloudFront
- IAM
- AWS KMS
- AWS Secrets Manager
- Amazon Bedrock
- AWS AgentCore
- Terraform
- AWS CDK
- AWS CloudFormation
- Kubernetes
- Amazon EKS
- Amazon ECS/Fargate
- Docker
- Amazon CloudWatch
- OpenTelemetry
- IAM
- mTLS
- OAuth 2.0 / OIDC
- API Security
- Rate Limiting
- PHI Tokenization
- Encryption & Key Management
- Git
- GitHub
- CI/CD Pipelines
- Infrastructure Automation
- Incident Management
- Root Cause Analysis
- Reliability Engineering
- Disaster Recovery
- High Availability
- FinOps / Cloud Cost Optimization
Preferred Qualifications
- Experience supporting Healthcare, Life Sciences, or other regulated industries.
- Good understanding of HIPAA, HITRUST, and cloud compliance frameworks.
- Hands-on experience with Amazon Bedrock, GenAI, and AI platform infrastructure.
- Exposure to Platform Engineering, Site Reliability Engineering (SRE), and DevSecOps practices.
- Experience implementing Policy-as-Code, cloud governance, and security automation.
- AWS certifications such as AWS Certified Solutions Architect – Associate/Professional, AWS Certified Security – Specialty, or AWS Certified DevOps Engineer – Professional are highly desirable.
Required Experience
- 5–9 years of hands-on experience in AWS Cloud Infrastructure, Platform Engineering, DevOps, Cloud Security, and Infrastructure Automation.
- Proven experience designing and managing enterprise-scale AWS environments using Infrastructure as Code.
- Strong knowledge of container orchestration, cloud networking, cloud security, monitoring, and automation.
- Experience supporting mission-critical, highly available production environments with a focus on security, scalability, and operational excellence.
AWS • Terraform • Kubernetes • Amazon EKS • Docker • AWS Networking • IAM • Cloud Security • CloudFormation • AWS CDK • CloudWatch • OpenTelemetry • Git • CI/CD • FinOps • Amazon Bedrock • AgentCore • DevSecOps • Platform Engineering • SRE
Skills
Infrastructure as Code, AWS, Kubernetes, Amazon Bedrock
About UST
UST is a global digital transformation solutions provider. For more than 20 years, UST has worked side by side with the world’s best companies to make a real impact through transformation. Powered by technology, inspired by people and led by purpose, UST partners with their clients from design to operation. With deep domain expertise and a future-proof philosophy, UST embeds innovation and agility into their clients’ organizations. With over 30,000 employees in 30 countries, UST builds for boundless impact—touching billions of lives in the process.