Salary
Not listed
Posted
2h ago
Source
himalayas
This role builds and extends AWS landing zones, account vending and networking for enterprise migrations — the infrastructure and automation specialism, distinct from the Microsoft-workload and data-focused roles on the same program. The scope for year one: 191 applications in the estate being migrated to AWS across 20 business departments, 27 Azure subscriptions and 451 resource groups to map into an AWS account structure, and 5 migration waves to support, each with its own cutover windows and rollback plans. The landing zone itself — account vending, guardrails and centralized networking — is something you'll help build and run, not just consume.
Requirements
What you will do
Build and extend AWS multi-account landing zones with Control Tower, account vending and service control policies.
Design and implement hybrid networking — VPC architecture, Transit Gateway, Direct Connect and VPN back to on-premises and Azure.
Write and maintain Terraform modules that other engineers depend on.
Automate delivery through CI/CD — GitHub Actions, GitLab CI or CodePipeline.
Operate containerized workloads on EKS with Helm and Argo CD where in scope.
Write runbooks and hand over to client engineering teams; knowledge transfer is part of every engagement.
Required
Production experience writing and maintaining Terraform modules at scale. The single most important skill for this role.
Strong AWS networking: VPC design, routing, Transit Gateway, VPN and hybrid connectivity.
Deep AWS platform knowledge: compute, storage and IAM. AWS Solutions Architect Associate or higher expected.
Comfortable on Linux, with Bash and Python to a working standard.
Production CI/CD experience: GitHub Actions, GitLab CI, Jenkins or CodePipeline.
Demonstrated experience building or operating a multi-account AWS landing zone.
Professional written and spoken English.
Nice to have
AWS Control Tower, Terragrunt, Kubernetes/EKS, Helm, Argo CD, Ansible, Azure, VMware, AWS DevOps Professional, Serverless/Lambda, GuardDuty/Security Hub, PCI-DSS environments.
Engagement details
Full-time
Start date: February 2027
Open to candidates from all LATAM
Highlights
Terraform, AWS (Control Tower, VPC, Transit Gateway, Direct Connect, VPN, IAM, compute, storage), Linux, Bash, Python, CI/CD , Kubernetes/EKS, Helm, Argo CD, Terragrunt, Ansible, Azure, VMware
Before you apply
- Confirm async-friendly culture vs daily standup-heavy expectations
- Ask about on-call rotation and incident expectations
- Check the tech stack matches what you actually want to use day-to-day
Interested in this role?
RemoteTide sends you directly to the source. No account required.