Job Role: AWS Devops Engineer
Location: Boston, MA, Arlington, VA, Atlanta, GA,:Austin, TX, Chicago, IL, Cleveland, OH:
Experience: 10 Years
Skills:
This Senior Consultant role builds automation, CI/CD, Infrastructure-as-Code and operational runbooks for AWS delivery. The consultant is expected to operate as an embedded AWS SME, provide hands-on implementation support, and create audit-ready technical documentation aligned to regulated Financial Services delivery expectations.
Role Scope & Key Responsibilities
Primary Responsibilities:
· Security Agent Automation (WS-1): Lead development of automation scripts for integrating AWS Security Agent components with customer CI/CD tools and repositories; assist cloud infrastructure and security consultants with service implementation design
· Automated Account Vending (WS-2): Design and implement automated account vending ensuring new Security Lab accounts inherit baseline security controls, guardrails, and compliance configurations
· IRE & Clean Room Automation (WS-3): Serve as automation design lead for Independent Recovery Environment, including:
· Automate CI/CD pipeline integration for code scanning, artifact validation, artifact hashing, and deployment controls
· Build automated recovery runbooks using AWS Step Functions and Systems Manager
· Develop backup integrity verification canaries and validation testing scripts
· Create automated operational toolchain for data recovery from BitBucket and Nexus repositories
· Amazon EKS Security Lab (WS-4): Assist with design, implementation, and deployment of Amazon EKS initial security baseline and lab environment setup
· Knowledge Transfer: Contribute to automation and IaC templates, operational procedures, and administration guides for all workstreams
Key Deliverables:
· Terraform modules for Security Agent infrastructure and account vending
· Python automation scripts for CI/CD integration and recovery orchestration
· Step Functions state machines for automated recovery workflows
· Backup integrity canaries and validation testing frameworks
· GitOps workflow configurations and integrations
· Operational runbooks and administration guides
Infrastructure as Code & Automation:
· Terraform: Expert-level proficiency in Terraform for AWS infrastructure provisioning, module development, state management, and multi-account deployments
· AWS CloudFormation: StackSets for multi-account deployments, nested stacks, and drift detection
· AWS CDK: Programmatic infrastructure definition for complex automation patterns
· Python: Strong scripting capabilities for automation, AWS SDK (boto3), and integration with CI/CD tools
Compute & Orchestration:
· AWS Step Functions: State machine design for recovery orchestration, error handling, and workflow automation
· AWS Systems Manager: Automation documents, Run Command, Session Manager, Parameter Store, and Patch Manager for operational toolchains
· AWS Lambda: Serverless automation for event-driven workflows, backup validation, and artifact processing
· Amazon EKS: Cluster provisioning, security baseline configuration, IRSA (IAM Roles for Service Accounts), pod security policies/standards
Account Management & Governance:
· AWS Organizations: Multi-account strategy, OU structure design, and SCP policies
· AWS Control Tower: Landing zone automation, Account Factory customization, and guardrails
· AWS Service Catalog: Automated account vending, standardized resource provisioning, and compliance-approved templates
Security & Compliance:
· AWS IAM: Advanced policies, permission boundaries, cross-account roles, and service accounts
· AWS Secrets Manager: Secure credential management, secret rotation, and integration with CI/CD pipelines
· AWS KMS: Customer Managed Keys (CMKs), key policies, and encryption automation
· AWS Security Hub: Centralized security findings, compliance standards, and automated remediation
· Amazon GuardDuty: Threat detection integration and automated response workflows
· AWS Config: Configuration compliance, resource inventory, and conformance packs
Backup & Disaster Recovery:
· AWS Backup: Centralized backup management, backup plans, vault locking, and cross-account/cross-region backup
· AWS Backup Audit Manager: Compliance framework design and backup policy enforcement
· Amazon S3: Object Lock (WORM compliance), versioning, lifecycle policies, and cross-region replication
· AWS Elastic Disaster Recovery (DRS): Continuous replication and recovery orchestration
CI/CD & DevOps:
· AWS CodePipeline: Pipeline orchestration for automated deployments and artifact validation
· AWS CodeBuild: Managed build service for code scanning, artifact hashing, and container image builds
· AWS CodeDeploy: Automated deployment to EC2, EKS, and Lambda
· Amazon ECR: Container image registry with vulnerability scanning and lifecycle policies
· AWS CodeCommit: Git repository integration (alternative to BitBucket)
Monitoring & Observability:
· Amazon CloudWatch: Metrics, logs, alarms, dashboards, and canary monitoring (CloudWatch Synthetics)
· AWS X-Ray: Distributed tracing for automation workflows
· CloudWatch Logs Insights: Advanced log querying for troubleshooting
· Amazon EventBridge: Event-driven automation and cross-account event routing
Networking & Security:
· Amazon VPC: Advanced networking, security groups, NACLs, VPC peering, and PrivateLink
· AWS Transit Gateway: Hub-and-spoke architecture and route table isolation
· AWS Network Firewall: Stateful/stateless rules and intrusion prevention
· Amazon Route 53: DNS management and private hosted zones
Storage & Data Management:
· Amazon S3: Bucket policies, encryption, event notifications, and presigned URLs
· Amazon EFS: Shared file storage for EKS persistent volumes
· AWS DataSync: Automated data transfer for backup and recovery workflows
GitOps & Version Control:
· AWS CodeCommit / GitHub / GitLab integration: GitOps workflow patterns
· Flux / ArgoCD on EKS: GitOps continuous deployment for Kubernetes
· BitBucket integration: Operational toolchain recovery and automation (nice-to-have)
· Nexus Repository integration: Artifact management and recovery automation (nice-to-have)
Container & Kubernetes Security:
· Amazon EKS: Security baseline configuration, network policies, pod security standards, secrets encryption
· Amazon ECR: Image scanning, vulnerability assessment, and immutable tags
· AWS App Mesh: Service mesh for microservices security and observability
· Kubernetes RBAC: Role-based access control and service account management
Automation & Testing:
· AWS CloudWatch Synthetics: Canary scripts for backup integrity verification and endpoint monitoring
· AWS Systems Manager Automation: Automated remediation and operational runbooks
· Python Testing Frameworks: pytest, unittest for validation testing scripts
· Terraform Testing: terratest, tflint for IaC validation
Financial Services & Industry Skills
· Large regulated financial-services delivery with formal change-control, audit and risk governance
· Operational resilience expectations including RTO/RPO, multi-region DR and evidence for audit review
· Awareness of applicable controls and regulations such as DORA, NIST CSF 2.0, PCI DSS, SEC cyber rules, RegSCI and SIFMU/FMI expectations where relevant
· Ability to create Tech Risk-ready documentation including ADRs, runbooks, design docs, threat models and validation evidence
· Clear communication with client engineering, security, SRE, data and platform stakeholders as an embedded SME
Certifications / Qualifications
· AWS Certified DevOps Engineer - Professional
· AWS Certified Solutions Architect - Associate / Professional
· HashiCorp Terraform Associate / CKA preferred