freehire launches on Product Hunt on 26 August.

Follow →

Senior Staff Engineer - Cloud Engineer

Summary

Leads cloud and access-platform engineering, designing secure AWS/Azure networks and deploying HashiCorp Boundary for zero-trust access, while automating with Terraform and Python.

Required qualifications:

  • 8+ years of software/platform engineering, with demonstrated technical leadership of a team or major workstream
  • Expert in HashiCorp Boundary: both deployment (controllers/workers, SSH/RDP/database brokering, session recording, Entra ID OIDC, on-prem AD over ExpressRoute) and the operational access model (scopes, roles, grants, principal mapping, user onboarding)
  • Deep AWS networking experience and a working understanding of enterprise cross-cloud network engineering: AWS Cloud WAN, AWS Network Firewall, AWS Transit Gateway, IPAM; and the routing path from AWS to Azure
  • Strong Azure networking: VNet routing, Private Endpoint/Private DNS, NSG and route-table design for Boundary worker-to-target paths
  • Production Terraform/Terragrunt against an established enterprise IaC module pattern; familiarity with azurerm, azapi, and azuread providers
  • Strong in Python for lifecycle automation and pipeline tooling
  • Solid grounding in DevSecOps: SAST/SCA tooling (Veracode, SonarQube, or CodeQL), dependency and vulnerability remediation, secrets management
  • Comfortable in Linux/shell, Docker, and operating production services (on-call, incident/change management)
  • Excellent written communication: pattern documentation, runbooks, and onboarding guides that future organizations will use to adopt this platform

AI skills

  • Daily, fluent use of Claude Code and/or GitHub Copilot for implementation, refactoring, test generation, and code review
  • Ability to establish team standards for AI-assisted development: effective prompting, trust-vs-verify discipline on generated code, security/IP guardrails, and reviewing AI-authored changes
  • Working understanding of LLM fundamentals: context windows, tokens, model selection, and prompt/context engineering
  • Experience integrating AI into developer workflows and agentic/automation tooling (MCP servers, AI-driven CI steps, codegen and doc-generation pipelines)
  • Able to evaluate AI tooling pragmatically: measuring real productivity and quality impact, not hype

Nice to have

  • Experience with RDP session recording compensating controls or supplementary tooling
  • Azure VM domain-join and on-prem DNS troubleshooting at depth
  • GitHub Actions and CI/CD pipeline authoring

Must have skills: Azure VNet routing Private Endpoint Private DNS NSG ROUTETABLE DESIGN, Python (Strong), Terraform (Strong), aws cloud wan aws network firewall aws transit gateway IPAM, hashiCorp Boundary Expert

See also