We are seeking a highly skilled Cloud Lead Engineer to design, implement, and continuously improve cloud solutions and services in a multi-tenant cloud environment using AWS native services.
Requirements
- Design, implement, and manage secure, scalable, and cost-efficient AWS cloud infrastructure using AWS native services.
- Build new cloud services and enhance existing platforms based on evolving business and operational requirements.
- Implement and enforce account governance using AWS control tower, SCPs, RCPs, AWS organizations, AWS config, firewall manager, and security hub.
- Architect secure, scalable, and resilient network topologies using VPC, subnets, NAT, VPN, Transit Gateway, Direct Connect, and PrivateLink.
- Manage hybrid connectivity between on-premises and cloud environments with a focus on performance, availability, and security.
- Familiar with AWS network firewall, VPC traffic mirroring, and other advanced networking services in AWS.
- Familiar with identity and access controls using IAM, SCPs, AWS SSO, and IAM Identity Center.
- Monitor, investigate, and remediate security findings from AWS Security Hub, GuardDuty, Inspector, Config, Firewall Manager, Shield Advanced, and IAM Access Analyzer.
- Secure workloads by enforcing least privilege access and enabling encryption with AWS KMS and Secrets Manager.
- Provide technical advisory on cloud application design, network, and security architecture or other cloud related technologies
- Establish centralized logging, detection, monitoring, and incident response capabilities across accounts and regions.
- Utilize observability tools such as CloudWatch, OpenSearch, QuickSight, Grafana, or similar solutions to monitor cloud resources effectively.
- Develop operational dashboards and reporting mechanisms to support infrastructure monitoring, performance analysis, and compliance requirements.
- Able to automate provisioning and configuration management using AWS CloudFormation, AWS CDK, or Terraform.
- Able to monitor and troubleshoot cloud environments using CloudWatch, X-Ray, CloudTrail, and AWS Config.
- Maintain comprehensive documentation covering infrastructure architecture, account structure, and governance policies.