Remote job
Senior Cloud Infrastructure Engineer
Job details
About this role
Role overview Senior individual contributor role on a CloudOps team responsible for the foundational cloud infrastructure that lets engineering teams build, deploy, and operate products at scale. The work centers on a multi-account AWS environment spanning hundreds of accounts and is being extended into Azure and GCP, with heavy use of Infrastructure as Code and AI-assisted engineering tools.
Responsibilities - Own and evolve a multi-account AWS Landing Zone, including organizations, control-tower services, account factory patterns, service control policies, tagging standards, and permission boundaries. - Extend governance, operational standards, security controls, observability, and backup capabilities across AWS, Azure, and GCP. - Strengthen cloud identity and access management using least-privilege principles, including SSO federation, identity-center permission sets, group design, credential handling, and reduction of standing privileged access. - Design and operate cloud networking, including IP address management, VPC architecture, routing, transit connectivity, egress design, and public/private DNS. - Build self-service infrastructure capabilities for engineering teams, such as account provisioning, environment provisioning, access requests, lifecycle management, and inventory. - Design backup, restore, and disaster recovery capabilities across regions, accounts, and business units, including immutable and ransomware-resistant strategies for cloud-native and managed data platforms.
Requirements - Hands-on experience building reusable Terraform modules and infrastructure patterns consumed by other engineering teams. - Experience with cloud IAM, including SSO, SAML federation, SCIM provisioning, IAM policies, roles, permission boundaries, and least-privilege models. - Strong cloud networking fundamentals, including IP planning, VPC/VNet design, routing, transit architectures, DNS, private connectivity, and network security. - Experience designing or maintaining CI/CD pipelines using tools such as GitHub Actions or Jenkins. - Scripting or programming experience with Python, Go, Bash, or similar languages, plus solid Linux fundamentals. - Working knowledge of Kubernetes and cloud-native infrastructure. - Practical experience with AI coding agents or AI-assisted development tools, with the judgment to validate generated code and flag risk. - Ability to independently own complex infrastructure projects from design through production. - Advanced English proficiency and a bachelor's degree in computer science, software engineering, information technology, or a related field; must reside in Brazil.
Nice to have - Familiarity with AWS Control Tower and Account Factory for Terraform, AWS IPAM, Transit Gateway, or Cloud WAN. - Multi-cloud governance experience across Azure and/or GCP, plus cross-account immutable backup and ransomware protection. - Exposure to managed data platforms such as MongoDB Atlas or Elastic Cloud, and cloud security tools like Wiz, GuardDuty, or CrowdStrike. - Zero-trust technologies, Cloudflare WAF and DNS, and certificate or PKI lifecycle management. - Agentic automation pipelines, MCP servers, reusable AI agent skills, FinOps cost optimization, and SOC 2 or comparable compliance work. - GitHub organization administration and cloud, Terraform, or Kubernetes certifications.