Cloud Platform Engineer ( 102-08SENG-01 )
Summary
Designs and maintains AWS multi-account landing zones, hybrid networking, and Terraform modules for enterprise migrations, automating deployments via CI/CD and supporting cutover/rollback plans for 191 applications across 20 business units.
This role builds and extends AWS landing zones, account vending and networking for enterprise migrations — the infrastructure and automation specialism, distinct from the Microsoft-workload and data-focused roles on the same program. The scope for year one: 191 applications in the estate being migrated to AWS across 20 business departments, 27 Azure subscriptions and 451 resource groups to map into an AWS account structure, and 5 migration waves to support, each with its own cutover windows and rollback plans. The landing zone itself — account vending, guardrails and centralized networking — is something you'll help build and run, not just consume.
What you will do
Build and extend AWS multi-account landing zones with Control Tower, account vending and service control policies.
Design and implement hybrid networking — VPC architecture, Transit Gateway, Direct Connect and VPN back to on-premises and Azure.
Write and maintain Terraform modules that other engineers depend on.
Automate delivery through CI/CD — GitHub Actions, GitLab CI or CodePipeline.
Operate containerized workloads on EKS with Helm and Argo CD where in scope.
Write runbooks and hand over to client engineering teams; knowledge transfer is part of every engagement.
Required
Production experience writing and maintaining Terraform modules at scale. The single most important skill for this role.
Strong AWS networking: VPC design, routing, Transit Gateway, VPN and hybrid connectivity.
Deep AWS platform knowledge: compute, storage and IAM. AWS Solutions Architect Associate or higher expected.
Comfortable on Linux, with Bash and Python to a working standard.
Production CI/CD experience: GitHub Actions, GitLab CI, Jenkins or CodePipeline.
Demonstrated experience building or operating a multi-account AWS landing zone.
Professional written and spoken English.
Nice to have
AWS Control Tower, Terragrunt, Kubernetes/EKS, Helm, Argo CD, Ansible, Azure, VMware, AWS DevOps Professional, Serverless/Lambda, GuardDuty/Security Hub, PCI-DSS environments.
Engagement details
Full-time
Start date: February 2027
Open to candidates from all LATAM
As published by recruitee
Full name, Email, CV, Cover letter, Phone
- What's your English level? choose any
- What's your salary expectation? (contractor - dolar)
- Availability to start?