Cloud DevOps Automation
Summary
A Cloud DevOps Automation Engineer who builds and operates automation-first AWS platforms day to day: provisioning infrastructure via IaC (Terraform, CloudFormation, AFT, CFCT), running EKS/Kubernetes clusters, maintaining CI/CD and GitOps pipelines, and enabling self-service onboarding through Backstage.
Jora Malaysia will close on 16th September 2026. Thank you for being with us, we are cheering you on as you continue your career journey.
The Cloud DevOps Automation Engineer is responsible for building and operating automation-first cloud platforms across AWS environments. This role unifies cloud infrastructure, DevOps practices, and scaffolding frameworks through robust automation to enable scalable, secure, and efficient service delivery.
Acting as the bridge between infrastructure, platform engineering, and developer experience, the engineer will design systems where automation is the primary control plane—powering infrastructure provisioning, EKS operations, CI/CD pipelines, and self-service service onboarding.
The role emphasizes eliminating manual operations, standardizing workflows, and enabling repeatable, production-grade deployments using tools such as CloudFormation, Terraform, AWS AFT, CFCT, Kubernetes (EKS), and Backstage.
Accountabilities
- Design and implement end-to-end automation frameworks for AWS infrastructure, EKS platforms, and application delivery.
- Own and operate AWS multi-account environments using AFT and CFCT, driven by automation.
- Build and maintain automated CI/CD pipelines and GitOps workflows.
- Develop reusable scaffolds and templates that are fully automation-enabled.
- Ensure all infrastructure, deployments, and operations are:
- Automated
- Repeatable
- Version-controlled and auditable
Drive operational excellence through automation of monitoring, recovery, and scaling. Enable self-service capabilities via Backstage and automation pipelines. Reduce manual intervention and improve deployment speed, consistency, and reliability.
Responsibilities
- Design and automate AWS infrastructure provisioning:
- VPCs, EC2s, EKS, subnets, routing, and security groups
- AWS Control Tower, AFT, and CFCT
Build and maintain:
- AFT pipelines for account provisioning and lifecycle automation
- CFCT pipelines for automated baseline configuration and governance
Automate:
- Account bootstrapping (IAM, logging, security baselines)
- Environment provisioning across dev, staging, and production
Ensure infrastructure is deployed and managed exclusively via IaC and automation pipelines
- Automate lifecycle management of Amazon EKS clusters
- Helm and GitOps (ArgoCD/Flux)
- Configuration and secrets management
Build automated workflows for:
- Cluster upgrades and patching
- Performance tuning and optimization
- Failure recovery and resilience
3. Infrastructure as Code & Automation Frameworks
- Develop and maintain IaC-driven automation frameworks using:
- Terraform and AWS CloudFormation
- Terraform modules for infrastructure and AFT customization
- CFCT configuration packages for governance enforcement
Integrate IaC into CI/CD pipelines for fully automated provisioning Enforce:
- Version control
- Auditability
- Security and compliance through automation
4. DevOps Automation & CI/CD
- Design and implement fully automated CI/CD pipelines using Bitbucket Pipelines
- Automate:
- Build, test, security scanning, and deployment workflows
Containerize applications using Docker and manage images in Amazon ECR Integrate:
- SAST, DAST, and container security scanning
- IaC validation and policy enforcement
Enable zero-touch or low-touch deployments for engineering teams
5. Scaffolding & Self-Service Enablement (Secondary Focus)
- Infrastructure templates (Terraform/CloudFormation)
- Application boilerplates
Integrate scaffolds into Backstage Software Templates Ensure scaffolds:
- Automatically provision infrastructure
- Deploy services with minimal manual steps
Align scaffolds with:
- AFT-provisioned accounts
- CFCT-enforced baselines
Promote standardized golden paths powered by automation
6. Observability, Security & Compliance Automation
- Automate observability:
- Logging, metrics, and alerting (CloudWatch, Splunk, Prometheus)
Embed security via automation:
- IAM provisioning and least privilege enforcement
- IRSA for Kubernetes workloads
- Secrets management (AWS Secrets Manager, SSM)
Implement policy-as-code and automated compliance checks Ensure all environments are continuously monitored and compliant by default
7. Cloud Operations & Reliability Engineering
- Operate AWS environments with a focus on automation-driven operations
- Automate:
- Incident detection and alerting
- Recovery workflows where possible
Perform advanced troubleshooting:
- Networking (BGP, routing, hybrid connectivity)
- Kubernetes and application-level issues
- On-call rotations
- Incident response and root cause analysis
Continuously improve reliability by eliminating repetitive manual tasks through automation
Key Skills & Experience
- Strong experience with AWS (EKS, IAM, VPC, Control Tower)
- AWS Account Factory for Terraform (AFT)
- Customizations for AWS Control Tower (CFCT)
Deep hands-on experience with Kubernetes (EKS and Helm Advanced proficiency in Terraform and CloudFormation Strong experience in building automation frameworks and CI/CD pipelines Knowledge of AWS networking and hybrid connectivity (Direct Connect, VPN, BGP) Experience with Docker and Amazon ECR Solid Linux system administration and troubleshooting skills Familiarity with observability tools (CloudWatch, Splunk, Prometheus, Grafana) Experience with Backstage or developer platforms (preferred) Strong mindset toward automation-first engineering and operational efficiency
Skills
- Argo CD
- Automation
- AWS
- BGP
- Bitbucket
- CI/CD
- Cloud
- CloudFormation
- CloudWatch
- Container Security
- DAST
- Developer Experience
- DevOps
- Docker
- EKS
- Flux
- GitOps
- Grafana
- Helm
- IAM
- Infrastructure as Code
- Kubernetes
- Linux
- Networking
- Observability
- Prometheus
- SAST
- Secrets Management
- Splunk
- Terraform
- Version Control
- VPC
- VPN