Principal Cloud Engineer || Location – Remote || Employment type - contract
Job Description:
Domain: Healthcare
We are seeking a Principal Cloud Engineer who thrives at the intersection of cloud architecture, platform engineering, and delivery excellence.
This is a high-impact, design-centric role responsible for shaping cloud strategy and producing implementation-ready designs that teams can execute confidently.
You will lead the design of scalable, secure, reliable systems—and you will remain close to the code and the infrastructure to ensure designs are practical, automatable, and operable.
You’ll partner with Architecture, Security, DevOps, SRE, Data, and Application teams to deliver well-architected solutions across computer, networking, identity, data, integration, observability,
resiliency, and cost optimization.
Design is not just diagrams here.
We expect you to establish patterns, document decisions
(ADRs), validate designs through prototypes, and drive adoption through reference implementations and guardrails.
What You’ll Do (Core Responsibilities)
1) Lead cloud solution design (primary focus)
- Own architecture and detailed design for complex cloud initiatives (greenfield + modernization).
- Create implementation-ready designs:
- Logical + physical architectures
- Network and identity models
- Security controls and threat analysis
- Availability, DR, and scaling strategies
- Data flow and integration patterns
- Observability and operational runbooks
- Produce clear and actionable artifacts, such as:
- Architecture decision records (ADRs)
- Reference architectures and “golden paths”
- Patterns catalog (e.g., event-driven, API-first, data share, batch/stream)
- Standards and guardrails for teams
2) Validate designs with practical engineering
- Build prototypes / spike solutions to de-risk complex designs (e.g., networking, IAM, performance, data movement).
- Create reference implementations (IaC, CI/CD templates, policy as code, sample services).
- Provide technical leadership during delivery: unblock teams, review PRs, guide implementation choices, and ensure design fidelity.
3) Establish secure, compliant, well-governed cloud platforms
- Define a secure-by-default posture: identity, encryption, secrets, network isolation, logging, vulnerability management.
- Implement governance using native cloud capabilities and automation (policies, blueprints, landing zones, guardrails).
- Partner with security and risk teams to ensure controls are built-in, not bolted-on.
4) Engineer for reliability and operability (SRE mindset)
- Design for resilience: HA patterns, DR strategies, chaos/testing approaches, graceful degradation.
- Create observability standards: logs/metrics/traces, SLOs/SLIs, alerting, incident response workflows.
- Drive operational readiness: runbooks, on-call enablement, error budgets, postmortems.
5) Optimize cost and performance (FinOps + pragmatism)
- Design cost-aware architectures and continuous optimization practices: right-sizing, storage tiers, reserved capacity, autoscaling.
- Provide guidance for performance testing, capacity planning, and scaling strategies.
6) Mentor and elevate engineering practices
- Raise the bar for design quality and engineering rigor across teams.
- Lead architecture reviews and design sessions; coach engineers on tradeoffs and patterns.
- Influence without authority—build alignment across stakeholders.
7) Lead vendor partner selection and engagement
- Identify, evaluate, and select cloud technology vendors and partners to support strategic initiatives.
- Assess vendor solutions for technical fit, security, compliance, cost, and operational impact.
- Drive RFP/RFI processes, coordinate technical due diligence, and negotiate terms with vendors.
- Establish ongoing relationships with key partners, ensuring alignment with architecture standards and delivery goals.
Required Qualifications (Must Have)
- 10+ years in software/platform engineering with significant cloud architecture ownership at scale.
- Proven experience leading design for complex cloud systems (not just participating).
- Demonstrated hands-on experience building and operating cloud workloads:
- Infrastructure as Code (Terraform strongly preferred; CloudFormation/Bicep acceptable)
- CI/CD and release automation (GitHub Actions/Azure DevOps/Jenkins/etc.)
- Containers and orchestration (Kubernetes/EKS/AKS/GKE; or equivalent)
Strong cloud fundamentals across:
- Identity and access management (IAM, RBAC, OAuth/OIDC, least privilege)
- Networking (VPC/VNet, routing, peering, private endpoints, DNS, zero trust patterns)
- Security (encryption, key management, secrets, threat modeling, posture management)
- Reliability (HA, DR, multi-zone, multi-region strategies)
- Observability (structured logging, distributed tracing, metrics, SLOs)
- Experience with architecture artifacts and methodologies:
- ADRs, reference architectures, patterns, and well-architected reviews
- Ability to communicate design tradeoffs clearly to technical + executive audiences
Preferred Qualifications (Nice to Have)
- Multi-cloud design experience (Azure/AWS/Google Cloud Platform) or hybrid cloud design (on-prem + cloud).
- Strong integration architecture background:
- API management, event streaming, messaging, service mesh, integration platforms
- Data platform knowledge:
- Data lakes/lake houses, data sharing patterns, streaming vs batch, governance
- Policy-as-code tooling (OPA/Gatekeeper, Azure Policy, AWS SCPs; etc.).
- FinOps practices and cloud cost optimization leadership.
- Certifications (helpful but not required):
- AWS Solutions Architect Professional / Azure Solutions Architect Expert / Google Cloud Platform PCA
- Kubernetes (CKA/CKAD), Security (CCSP), etc.