Project Role : Cloud Platform Engineer
Project Role Description : Designs, builds, tests, and deploys cloud application solutions that integrate cloud and non-cloud infrastructure. Can deploy infrastructure and platform environments, creates a proof of architecture to test architecture viability, security and performance.
Must have skills : AWS Application Integration
Good to have skills : NA
Minimum 5 year(s) of experience is required
Educational Qualification : 15 years full time education
Job Summary
We are seeking an experienced AWS Platform Engineer with strong expertise in building, automating, and operating cloud infrastructure on AWS using Infrastructure as Code (IaC). The ideal candidate will design secure, scalable AWS platform components, automate provisioning using Terraform/CloudFormation, and implement best practices around networking, IAM, security, observability, and cloud governance.
Key Responsibilities
AWS Platform Engineering
Design, deploy, and maintain AWS foundational infrastructure including:
o VPC architecture – multi AZ, subnets, routing, NAT Gateway, Transit Gateway
o Networking – NACLs, Security Groups, Route 53, VPC Peering, PrivateLink
o Load Balancing – ALB, NLB, API Gateway
Provision and manage AWS compute and data services:
o EC2, ECS/EKS, Lambda
o S3, EFS, FSx
o RDS, DynamoDB, Redshift (as required)
Implement secure hybrid connectivity using VPN, Direct Connect, and private endpoints.
Infrastructure as Code (IaC)
Build reusable IaC modules using Terraform (preferred) or AWS CloudFormation.
Automate provisioning of VPCs, IAM, compute, storage, networking, logging, and security controls.
Implement policy-as-code using tools such as Checkov, OPA, AWS Config Rules, or Terraform Sentinel.
Manage IaC pipelines with plan/apply validation, drift detection, and controlled rollouts.
Security, Identity & Governance
Implement IAM governance: Roles, Policies, STS, permission boundaries, SCPs (Organizations).
Enforce AWS security best practices including encryption (KMS), rotation, MFA, and least privilege.
Apply organization-wide governance using AWS Organizations, Control Tower, Landing Zone, AWS Config, and Security Hub.
Manage secrets and certificates using AWS Secrets Manager or AWS Systems Manager Parameter Store.
Automation & DevOps Integration
Implement CI/CD pipelines for infrastructure and application deployments using:
o AWS CodePipeline, CodeBuild, CodeDeploy or
o GitHub Actions / GitLab CI / Jenkins
Automate patching, configuration, scaling, and system updates using SSM automations.
Integrate image pipelines (AMI baking) and container pipelines for ECS/EKS workloads.
Monitoring, Logging & Reliability
Implement observability using:
o CloudWatch metrics, logs, alarms
o CloudTrail, AWS Config, GuardDuty, Inspector
o Centralized logging (OpenSearch/Splunk/ELK optional)
Define performance KPIs, SLOs/SLIs, and build dashboards for platform health.
Support incident response, problem management, and root cause analysis.
Required Skills
Strong hands on experience with AWS core services (VPC, EC2, IAM, S3, RDS, Lambda, ELB, CloudWatch).
Expert-level experience in Terraform (preferred) or CloudFormation.
Solid knowledge of AWS networking: VPC, subnets, routing, Security Groups, NACLs, Direct Connect/VPN.
Proficiency with AWS security frameworks & IAM governance.
Experience with CI/CD pipelines (CodePipeline, GitHub Actions, Jenkins, GitLab CI).
Understanding of containerization (Docker) and orchestration basics (ECS/EKS).
Scripting skills in Python, Bash, or PowerShell.
Nice to Have
Experience with AWS EKS, Helm, Kubernetes networking.
Hands-on with AWS Landing Zone / Control Tower deployments.
Knowledge of monitoring stacks (Prometheus/Grafana) integrated with AWS.
Experience with cost optimization, tagging strategies, and FinOps practices.
Certifications: AWS Solutions Architect, AWS SysOps, AWS DevOps Engineer, Terraform Associate.
15 years full time education