AWS Cloud Platform Engineering
•Design, build, and maintain AWS cloud infrastructure supporting highly available event-driven workloads.
•Work across AWS services including Lambda, API Gateway, EC2, EKS/ECS, S3, RDS/Aurora PostgreSQL, DynamoDB, SQS, SNS, EventBridge, IAM, CloudWatch, and VPC .
•Ensure cloud infrastructure is reliable, scalable, secure, resilient, and cost-efficient.
•Support business-critical workloads across APIs, databases, messaging platforms, serverless applications, and enterprise integrations.
Infrastructure-as-Code & Automation
•Design and implement Infrastructure-as-Code (IaC) using Terraform .
•Build reusable automation frameworks for repeatable, secure, and scalable platform provisioning.
•Standardize infrastructure deployment practices across environments.
•Maintain infrastructure modules, templates, automation scripts, and configuration standards.
CI/CD & DevSecOps
•Build and maintain secure CI/CD pipelines for application, infrastructure, and platform deployments.
•Implement deployment automation, release strategies, automated testing, quality checks, and environment management.
•Drive DevSecOps practices by integrating: - Security scanning
•Policy enforcement
•Infrastructure validation
•Container security
•Dependency management
•Compliance checks
•Work with tools such as GitLab CI, Jenkins, GitHub Actions , or similar platforms.
AWS Networking & Traffic Management
•Design, implement, and manage AWS networking architecture including: - VPCs
•Subnets
•Route tables
•NAT Gateways
•Transit Gateway
•PrivateLink
•Security Groups
•VPNs
•Hybrid connectivity
•Manage application ingress, routing, and content delivery using: - Route53
•API Gateway
•Application Load Balancers
•Network Load Balancers
•CloudFront
Cloud Security & Identity Management
•Implement cloud security controls using: - AWS WAF
•AWS Shield
•IAM
•Encryption
•Secrets management
•Vulnerability management
•Audit logging
•Compliance frameworks
•Configure and support enterprise identity integrations using: - Microsoft Entra ID / Azure AD
•SAML
•OAuth2
•OpenID Connect
•Single Sign-On
•Ensure secure-by-design practices across infrastructure, deployment, networking, and application layers.
Kafka / MSK Platform Operations
•Support Kafka / AWS MSK platform operations including: - Topic management
•Access controls
•Capacity planning
•Monitoring
•Scaling
•Disaster recovery
•Partner with engineering teams to improve event-driven workload reliability, availability, and operational supportability.
Observability, Monitoring & Operations
•Implement and manage observability solutions covering: - Monitoring
•Centralized logging
•Distributed tracing
•Alerting
•Dashboarding
•Operational analytics
•Work with tools such as: - CloudWatch
•Grafana
•Datadog
•Prometheus
•OpenTelemetry
•ClickHouse
•Create operational dashboards and alerts to support real-time platform visibility.
Reliability, Resiliency & FinOps
•Perform platform performance tuning, capacity planning, backup validation, recovery testing, and disaster recovery readiness.
•Drive business continuity and operational resilience activities.
•Lead FinOps initiatives by monitoring cloud usage, optimizing resource utilization, reducing wastage, and improving cost efficiency.
•Implement tagging strategies, budget governance, and cost reporting.
Production Support & Continuous Improvement
•Troubleshoot production issues and perform root-cause analysis for business-critical systems.
•Drive corrective and preventive actions to improve platform stability.
•Contribute to platform standards, operational runbooks, automation initiatives, and engineering best practices.
•Work closely with Engineering, Architecture, Security, Product, and DevOps teams.