New Era Technology - Senior AWS Platform Engineer
Requirements
• Hands-on experience with AWS Control Tower, AWS Organizations, and multi-account landing zone design. • Deep hands-on experience implementing Infrastructure as Code using Terraform and AWS CloudFormation, including reusable modules/templates, parameterization, versioning, validation, state management, and promotion through CI/CD pipelines. • Experience with federated identity using SSO, SAML, or OIDC, and short-lived credential models such as IAM Identity Center and STS role assumption. • Working knowledge of SCPs and AWS guardrail design, with the ability to restrict high-risk actions while preserving developer velocity. • Experience with EKS, RDS or Aurora, Redshift, SQS, SNS, serverless services, or similar managed AWS services at a level needed to build safe self-service templates. • CI/CD pipeline experience supporting Git-based review and promotion workflows across development, staging, production, and other controlled environments. • Familiarity with AWS cost management tooling such as Budgets and Cost Explorer, including spend-based alerting and automated remediation patterns. • Familiarity with CloudTrail, AWS Config, Security Hub, or equivalent centralized logging, security, and audit tooling. • Experience with Account Factory for Terraform and GitOps-based AWS account provisioning. • Experience integrating ServiceNow or a similar ITSM platform as an automated trigger for infrastructure provisioning rather than a manual request queue. • Experience with developer portal tooling such as Backstage. • Background building account-vending, self-service cloud provisioning, or platform-engineering capabilities for large, multi-team engineering organizations. • Experience implementing automated account lifecycle policies, including time-boxed access, expiration notifications, extension approvals, and decommissioning workflows. • AWS Platform and Governance • AWS Control Tower, AWS Organizations, Organizational Units, account baselines, and multi-account governance. • Service control policies, guardrail design, region restrictions, mandatory logging, and security service enablement. • Account vending patterns using Account Factory for Terraform, AWS Service Catalog, or equivalent Organizations-based automation. • Infrastructure as Code and Automation • Advanced Terraform skills, including reusable modules, environment separation, remote state, provider management, variable design, workspace or account separation patterns, code review workflows, and scalable module governance. • Deep AWS CloudFormation experience, including nested stacks, parameters, mappings, outputs, change sets, drift detection, StackSets, reusable templates, and integration with CI/CD deployment workflows. • Ability to compare and apply Terraform and CloudFormation appropriately based on organizational standards, service coverage, governance requirements, maintainability, and deployment model. • Automation experience using scripting, APIs, event-driven workflows, and pipeline orchestration. • Identity, Security, and Access • Federated identity design using IAM Identity Center, SAML, OIDC, or enterprise SSO integrations. • Short-lived access patterns using STS role assumption and least-privilege role design. • Developer and elevated administrator access models constrained by SCPs, permissions boundaries, and environment-specific roles. • Git-based promotion workflows that move validated changes across controlled environments through code review and automated validation. • CI/CD deployment models with environment-scoped roles and controls that prevent direct console changes in controlled environments. • Reusable templates for EKS, managed databases, queues, event-driven services, serverless applications, and network-isolated testing patterns. • Cost governance using AWS Budgets, Cost Explorer, alerting, tagging, chargeback or showback models, and automated remediation. • Centralized observability and audit using CloudTrail, AWS Config, Security Hub, CloudWatch, and related logging and security services. • Success Profile • Success Profile • Strong platform-engineering mindset with a focus on self-service, automation, repeatability, and developer experience. • Ability to balance governance and developer velocity by designing controls that are safe, practical, and scalable. • Excellent communication and documentation skills, with the ability to work across cloud engineering, security, identity, application development, and operations teams. • Comfortable owning end-to-end capabilities, from architecture and implementation through operational support, lifecycle management, and continuous improvement. • New Era Technology, LLC., and its subsidiaries (“New Era” “we”, “us”, or “our”) in its operating regions worldwide are committed to respecting your privacy and recognize the need for appropriate protection and management of any Personal Data that you may provide us. In this, we are also committed to providing you with a positive experience on our websites and while using our products, services and solutions (“Solutions”). • View our Privacy Policy here https://www.neweratech.com/us/privacy-policy/ • We never ask candidates to pay any fees at any point in our hiring process. If you are ever asked to provide payment for training, certification, equipment, or any other purpose, it is not from our company. Only communications from our official company channels should be trusted. Please note our official email domain is @neweratech.com. If you suspect fraudulent activity, please contact us immediately at [email protected] . • @neweratech.com
Responsibilities
• Design, build, and operate organizational units and account-vending automation so standard cloud environment requests can be fulfilled without manual cloud-engineering work. • Implement organization-level guardrails, including SCPs that block unacceptable actions, enforce region restrictions, and enable required logging and security services by default during account creation. • Build and enforce per-account cost controls, including budgets, actual and forecasted spend alerts, and automated remediation paths such as notification, access restriction, quarantine, and cleanup. • Ensure each account or environment is isolated by account, organizational unit, and network boundary from controlled environments and corporate networks, with no default transitive trust. • Partner with the identity team to design federated access patterns and short-lived role assumption models that eliminate the need for long-lived IAM users. • Own and maintain the Terraform, CloudFormation, and CDK module/template library that developers use for EKS, databases, queues, serverless services, and other common application patterns. • Build and maintain delivery pipelines that promote validated infrastructure and application changes through Git review, automated validation, and environment-scoped deployment roles. • Prevent direct console changes in staging and production by enforcing approved pipeline-based promotion and deployment workflows. • Instrument centralized logging and audit trails from the first day of each account’s lifecycle, including account creation records, API audit trails, and security findings. • Define and automate lifecycle policies for account and environment expiration, extension, decommissioning, and cleanup in a governed multi-team operating model.
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT