Cloud Infrastructure Engineer (L2 - L4)
Summary
Designs, builds, and operates secure, scalable cloud infrastructure across AWS, Azure, and GCP using IaC, GitOps, and CI/CD pipelines while enforcing cost and security governance.
Job details:
We are seeking L2 and L4 Cloud Infrastructure Engineers to design, build and operate cloud infrastructure across major public cloud platforms. The role covers the full cloud stack — from account setup, identity management and networking through to virtual compute, managed platform services, container workloads and GitOps deployment pipelines.
You will manage infrastructure using code-based tools, build CI/CD pipelines and maintain cloud security and cost governance standards.
Responsibilities:
- Provision and manage cloud accounts and environments following security and governance standards
- Design and maintain cloud IAM and RBAC across all providers — roles, policies, service accounts and key rotation
- Build and manage cloud networking — virtual networks, routing, VPN, DNS, WAF and cloud firewall rules
- Provision and scale IaaS compute instances with auto-scaling, load balancing and cost governance
- Manage PaaS services — deployment, scaling, access control and cost monitoring across all cloud providers
- Provision and maintain Kubernetes clusters; manage workloads, namespaces, RBAC and network policies
- Implement and operate Argo CD GitOps pipelines for application and infrastructure deployment
- Build and maintain CI/CD pipelines in GitHub Actions and Jenkins for build, hardening and promotion
- Manage cloud VM patching and golden image pipelines to maintain security compliance
- Monitor and respond to cloud security posture findings and privilege governance alerts
- Maintain cost governance dashboards and respond to budget threshold alerts
- Contribute to infrastructure as code repositories and participate in code review
Job requirements:
- 2-5 years of relevant experience for L2 cloud infra engineer.
- 8-10+ years and above of relevant experience for L4 cloud infra engineer.
- Public cloud platforms — AWS, Microsoft Azure and Google Cloud Platform
- Cloud IAM and RBAC — roles, policies, service accounts, key rotation, MFA and SSO federation
- IaaS provisioning — compute instances, auto-scaling, load balancing and security groups
- PaaS management — managed databases, application services and serverless platforms
- Cloud networking — virtual networks, subnets, routing, VPN gateways, DNS and web application firewalls
- Cloud network virtual appliance firewalls and cloud-native security group management
- Kubernetes — EKS, AKS or GKE with Rancher; cluster management, namespaces, RBAC and network policies
- GitOps and continuous deployment — Argo CD; app-of-apps patterns, drift remediation and rollback
- CI/CD pipelines — GitHub Actions and Jenkins; build, test, lint, image pipeline and promotion workflows
- Infrastructure as code — Terraform for cloud resource provisioning across multiple providers
- AWS, Azure and GCP management — multi-cloud operations, governance and compliance
- Cloud security — posture management, CIS benchmarks, vulnerability scanning and privilege governance
- Cost governance — monitoring, alerting, right-sizing and tagging policy enforcement
- Cloud VM patching — cloud-native patch management services and image pipeline automation
- Observability integration — log forwarding, metrics ingestion and cloud-native monitoring
Interested applicants please send your resume to venessagoh@recruitexpress.com.sg
Venessa Goh Wee Ni
R24124686
Recruit Express Pte Ltd
EA License No: 99C4599
We regret that only shortlisted candidates will be contacted.