Cloud Platform Engineer ( 102-08SENG-01 )
OpsBrasil Serviços Cloud LTDAJob Description
This role builds and extends AWS landing zones, account vending and networking for enterprise migrations — the infrastructure and automation specialism, distinct from the Microsoft-workload and data-focused roles on the same program. The scope for year one: 191 applications in the estate being migrated to AWS across 20 business departments, 27 Azure subscriptions and 451 resource groups to map into an AWS account structure, and 5 migration waves to support, each with its own cutover windows and rollback plans. The landing zone itself — account vending, guardrails and centralized networking — is something you'll help build and run, not just consume.
Requirements
What you will do
- Build and extend AWS multi-account landing zones with Control Tower, account vending and service control policies.
- Design and implement hybrid networking — VPC architecture, Transit Gateway, Direct Connect and VPN back to on-premises and Azure.
- Write and maintain Terraform modules that other engineers depend on.
- Automate delivery through CI/CD — GitHub Actions, GitLab CI or CodePipeline.
- Operate containerized workloads on EKS with Helm and Argo CD where in scope.
- Write runbooks and hand over to client engineering teams; knowledge transfer is part of every engagement.
Required
- Production experience writing and maintaining Terraform modules at scale. The single most important skill for this role.
- Strong AWS networking: VPC design, routing, Transit Gateway, VPN and hybrid connectivity.
- Deep AWS platform knowledge: compute, storage and IAM. AWS Solutions Architect Associate or higher expected.
- Comfortable on Linux, with Bash and Python to a working standard.
- Production CI/CD experience: GitHub Actions, GitLab CI, Jenkins or CodePipeline.
- Demonstrated experience building or operating a multi-account AWS landing zone.
- Professional written and spoken English.
Nice to have
AWS Control Tower, Terragrunt, Kubernetes/EKS, Helm, Argo CD, Ansible, Azure, VMware, AWS DevOps Professional, Serverless/Lambda, GuardDuty/Security Hub, PCI-DSS environments.
Engagement details
- Full-time
- Start date: February 2027
- Open to candidates from all LATAM
Highlights
Terraform, AWS (Control Tower, VPC, Transit Gateway, Direct Connect, VPN, IAM, compute, storage), Linux, Bash, Python, CI/CD , Kubernetes/EKS, Helm, Argo CD, Terragrunt, Ansible, Azure, VMware
Originally posted on Himalayas