Architect - DevOps
Job Description
Responsibilities
• Design, build, and maintain scalable and secure infrastructure on AWS.
• Develop reusable Terraform modules for provisioning cloud infrastructure.
• Build and maintain automated CI/CD pipelines for infrastructure and application deployments.
• Implement Infrastructure as Code governance, validation, testing, and deployment controls.
• Implement Policy as Code using tools such as:
o HashiCorp Sentinel
o Open Policy Agent (OPA)
• Define and enforce security guardrails across AWS environments.
• Integrate security and compliance checks into CI/CD pipelines.
• Implement preventive and detective cloud security controls.
• Automate validation of Terraform plans before infrastructure deployment.
• Develop policies covering areas such as:
o IAM and least privilege
o Encryption
o Network security
o Public resource exposure
o Logging and monitoring
o Tagging standards
o Approved AWS services and configurations
o Data protection
• Work with security teams to translate security requirements into automated technical controls.
• Map cloud controls to industry security frameworks including NIST.
• Support implementation of controls aligned with:
o NIST Cybersecurity Framework
o NIST SP 800-53
o CIS Benchmarks
o AWS Security Best Practices
• Implement AWS security services such as IAM, KMS, CloudTrail, Config, GuardDuty, Security Hub, CloudWatch, and AWS Organizations.
• Support multi-account AWS environments and enterprise landing-zone architectures.
• Implement automated compliance monitoring and remediation.
• Troubleshoot infrastructure, deployment, security, and pipeline issues.
• Participate in architecture reviews and continuously improve DevSecOps practices.
• Strong hands-on experience with AWS.
• Strong experience with Terraform / Terraform Enterprise / HCP Terraform.
• Experience creating reusable Terraform modules and managing Terraform state.
• Strong understanding of Infrastructure as Code practices.
• Experience building CI/CD pipelines using one or more of:
o GitHub Actions
o Jenkins
• Strong understanding of Git-based development workflows.
• Experience implementing Policy as Code.
• Hands-on experience with Sentinel and/or Open Policy Agent (OPA).
• Understanding of DevSecOps and shift-left security practices.
• Good understanding of AWS IAM, networking, encryption, logging, monitoring, and cloud security.
• Experience implementing security controls within automated deployment pipelines.
• Familiarity with NIST, CIS, and cloud security control frameworks.
• Experience with scripting using Python, Bash, or PowerShell.
• Good understanding of containers and modern cloud-native deployment practices.
• AWS Organizations and Control Tower.
• AWS Config Rules and Service Control Policies.
• Security Hub and GuardDuty.
• Kubernetes / EKS.
• Docker.
• HashiCorp Vault.
• Secrets management.
• SAST, DAST, dependency scanning, and container security tools.
• Experience working in regulated enterprise environments.
• Experience designing enterprise cloud landing zones.
Qualifications
Bachelors - Computer Engineering, Bachelors - Computer Science, Bachelors - Information Technology, Masters - Computer Science
Certifications
Certified Kubernetes Administrator (CKA) - CNCF (Cloud Native Computing Foundation)CNCF (Cloud Native Computing Foundation), HashiCorp Certified Terraform Associate - UdemyUdemy
Required Skills
Agile Methodology, AWS Development, DevOps Process Flow, DevSecOps, Docker (Software), Kubernetes
Language
English (Required)
Language Proficiency -
Proficient - C2
Additional Job Location -
Job Type
Regular
Master Skill List -
DevOps
Remote Type -
Hybrid
Work Shift -
Day Job (United States of America)
The approximate annual base compensation range for this position is:
80,000 to 100,000 USD
"Los Angeles California-based candidates are not eligible for this role"
The actual offer, reflecting the total compensation package plus benefits, will be determined by a number of factors which include but are not limited to the applicant's experience, knowledge, skills, and abilities; geographic location; and internal equity.