Position : Principal Cloud Platform Architect / Engineering Lead - AWS DevOps Resource
Location : Remote
Duration : 12 months
AWS | Amazon EKS | Kubernetes | Platform Engineering
Position Overview
We are seeking a highly experienced Principal Cloud Platform Architect / Engineering
Lead to support a major enterprise cloud modernization initiative for a leading
organization.
This is not a traditional DevOps position. The successful candidate must be capable of
architecting, implementing, securing, and operationalizing an enterprise-grade AWS and
Kubernetes platform. This individual will serve as the technical lead and work closely with
Cyber Security, Infrastructure, Networking, Application Engineering, and Operations teams.
The organization is consolidating a portfolio of applications currently hosted across AWS
Amplify, Amazon ECS, AWS Lambda, and on-premises environments onto a standardized
Amazon EKS platform.
This is a highly visible, hands-on leadership role requiring deep technical expertise, strong
architectural judgment, and the ability to translate enterprise security and governance
requirements into practical platform capabilities.
Target Platform Architecture
The platform environment includes:
• Amazon EKS with a multi-account architecture
• AWS Organizations
• Separate Development, UAT, and Production accounts
• AWS Transit Gateway
• AWS PrivateLink
• Akamai CDN and Web Application Firewall
• Bitbucket-based CI/CD pipelines
• OpenTelemetry instrumentation
• SigNoz observability
• Secure hybrid connectivity with on-premises systems
• Zero Trust and least-privilege security architecture
The platform is being designed as an enterprise-grade, cyber-reviewable solution with a
strong emphasis on security, governance, observability, scalability, resilience, and
operational excellence.
Key Responsibilities
• Lead the architecture, design, and hands-on implementation of a multi-account
AWS EKS platform.
• Define and implement enterprise Kubernetes standards, governance models,
security controls, and operational practices.
• Design secure cloud and hybrid networking patterns using Transit Gateway,
PrivateLink, VPN, Direct Connect, VPC routing, and private connectivity.
• Establish a Zero Trust architecture and least-privilege access model across AWS
and Kubernetes.
• Design and implement a comprehensive observability framework using
OpenTelemetry, SigNoz, Prometheus, Grafana, logging, metrics, and distributed
tracing.
• Architect secure CI/CD capabilities using Bitbucket Pipelines, self-hosted runners,
OIDC authentication, and automated security controls.
• Lead the migration of applications from AWS Amplify, Amazon ECS, AWS Lambda,
and on-premises environments to Amazon EKS.
• Develop reusable Terraform modules, Helm charts, GitOps patterns, and platform
automation.
• Establish Kubernetes multi-tenancy, RBAC, network policies, ingress standards,
secrets management, and workload isolation.
• Partner with Cyber Security teams during architecture assessments, threat
modeling, security reviews, and compliance evaluations.
• Support platform operational readiness, resiliency testing, disaster recovery
planning, and production support processes.
• Produce high-quality architecture diagrams, technical standards, implementation
roadmaps, runbooks, and operational documentation.
• Mentor engineers and provide technical leadership across cloud, platform,
infrastructure, and application teams.
• Evaluate technical risks, recommend architectural decisions, and drive issues
through resolution.
• Operate independently while maintaining strong collaboration across multiple
technical and business teams.
Required Technical Experience
AWS – Expert Level
Candidates must have deep, hands-on experience with:
• Amazon EKS
• AWS Organizations and multi-account architecture
• VPC architecture and routing
• Transit Gateway
• AWS PrivateLink
• Route 53
• IAM and least-privilege access design
• IAM Roles for Service Accounts
• Amazon ECR
• AWS Lambda
• Application and Network Load Balancers
• AWS CloudTrail
• Amazon GuardDuty
• AWS Key Management Service
• AWS Secrets Manager
• Hybrid cloud connectivity
• VPN and AWS Direct Connect
• Cloud security, governance, and compliance controls
Kubernetes – Expert Level
• Production-scale Kubernetes and Amazon EKS implementation
• Kubernetes architecture, administration, and troubleshooting
• Ingress controllers
• Kubernetes RBAC
• Network policies
• Multi-tenant Kubernetes environments
• Helm
• GitOps operating models
• Container security
• Secrets and configuration management
• Cluster upgrades, scaling, resiliency, and lifecycle management
• Service mesh experience with Istio or AWS App Mesh is preferred
Platform Engineering and DevOps
• Bitbucket Pipelines
• Self-hosted CI/CD runners
• OIDC-based authentication
• Enterprise CI/CD architecture
• Docker and containerization
• Infrastructure as Code
• Advanced Terraform experience
• Policy-as-code and automated governance
• Secure software supply-chain practices
• Platform automation and reusable engineering standards
Security Architecture
• Zero Trust architecture
• Least-privilege IAM
• Kubernetes security
• Cloud security architecture
• Workload identity
• Network segmentation
• Secrets and encryption management
• Enterprise governance and compliance
• Security architecture and cyber-review processes
• Experience working in regulated or security-sensitive environments
Observability
• OpenTelemetry
• SigNoz
• Prometheus
• Grafana
• Centralized logging
• Metrics and alerting
• Distributed tracing
• Application and platform monitoring
• Service-level indicators and operational dashboards
Required Qualifications
• 10 or more years of infrastructure, cloud engineering, or platform engineering
experience.
• At least 5 years of hands-on AWS architecture and engineering experience.
• At least 5 years of hands-on Kubernetes experience, including production EKS
environments.
• Demonstrated experience leading enterprise cloud-platform architecture and
implementation.
• Strong hands-on Terraform, Kubernetes, AWS networking, and security experience.
• Proven ability to lead complex cloud migrations and platform-modernization
programs.
• Experience partnering with Cyber Security, Networking, Infrastructure, Operations,
and Application Engineering teams.
• Strong troubleshooting, problem-solving, and architectural decision-making
capabilities.
• Excellent written and verbal communication skills.
• Ability to create clear technical documentation and present architecture decisions
to technical and executive stakeholders.
• Ability to work independently and lead initiatives with limited supervision.
• Must be available to work during U.S. East Coast business hours.
Preferred Certifications
• AWS Certified Solutions Architect – Professional
• Certified Kubernetes Administrator
• Certified Kubernetes Security Specialist
• HashiCorp Certified: Terraform Associate or equivalent Terraform expertise