Remote job
Senior Software Engineer, AWS Cloud Infrastructure
Job details
About this role
Role overview
A senior-level engineering role focused on shaping how a clinical-stage organization designs, governs, secures, and operates AWS at enterprise scale. The position blends hands-on software engineering in TypeScript and Python with cloud architecture, security, and platform ownership, including direct accountability for production operations and on-call work. The role is remote with flexibility to travel as business needs arise.
Responsibilities
- Own and evolve AWS architecture across multi-account foundations, landing zone and Control Tower patterns, networking, security baselines, and shared platforms - Establish and continuously improve AWS governance, including organizational structure, policy guardrails, tagging, cost controls, compliance posture, and audit readiness - Design and operate identity and access across AWS, including IAM, IAM Identity Center, SSO federation, role mapping, access reviews, and least-privilege practices - Build, harden, and operate AWS platforms and full-stack services using TypeScript and Python across compute, containers, serverless, data stores, messaging, and cloud automation - Drive operational excellence via meaningful monitoring, alerting, SLOs/SLIs, runbooks, incident response, and durable fixes for recurring issues, including participation in on-call rotations - Automate infrastructure and delivery with Infrastructure as Code, preferring Pulumi or SST, and CI/CD on Bitbucket Pipelines or GitHub Actions, emphasizing safe incremental rollout and low blast radius
Requirements
- Senior-level software engineering experience with substantial hands-on work building and operating production systems on AWS - Strong full-stack capability in TypeScript and Python, including APIs, services, tooling, and cloud automation - Deep familiarity with core enterprise AWS services such as IAM, Organizations, VPC, EC2, ECS/EKS or Lambda, S3, RDS/DynamoDB, CloudWatch, KMS, Config, and GuardDuty - Proven ability to design and run AWS governance at scale, including multi-account strategy, guardrails, access control, and operational controls - Strong AWS networking fundamentals covering VPNs, peering, Transit Gateway, routing, DNS, and hybrid connectivity - Background in regulated or audit-ready environments with disciplined habits around change control, traceability, and least privilege - Infrastructure as Code experience (Pulumi or SST strongly preferred; Terraform or AWS CDK transferable) and CI/CD using Bitbucket Pipelines and/or GitHub Actions
Nice to have
- Enterprise SSO experience with Microsoft Entra ID federation into AWS, including SAML/OIDC, IAM Identity Center, application and role mapping, and access lifecycle practices - Proficiency with modern AI coding and productivity tools, paired with the judgment to validate outputs and maintain production quality
Benefits and work setup
- Remote-first arrangement with travel flexibility as needed - Medical, dental, and vision plans with the vast majority of premiums covered - Company-paid life insurance, AD&D, and disability coverage, plus voluntary plan options - 401(k) with dollar-for-dollar matching up to 6% of eligible contributions, plus long-term stock incentives and an employee stock purchase plan - Discretionary quarterly bonus, flexible wellness benefit, generous paid time off, paid holidays, and company-wide shutdowns