Full Job Description
We're hiring AWS Cloud Platform Engineers to build and own the platform's foundation. That means the AWS accounts, networking, identity and infrastructure-as-code everything runs on, plus the path from commit to running agent. Each engineer will have a main focus in one of the two areas below and work closely across both. This is a named-team engagement, so the person we propose is the person who starts.
FOCUS AREAS
- Infrastructure & IaC: Build and own the base AWS layer: accounts, networking, identity boundaries, and the reusable IaC modules the rest of the platform is built from.
- CI/CD & Runtime Deployment: Own the path from commit to running agent: container builds, Amazon ECR, pipelines, environment promotion, and AgentCore Runtime session configuration.
ROLE RESPONSIBILITIES
- Account and Environment Foundation: Design and stand up the multi-account AWS structure (Organizations, Control Tower or equivalent) with guardrails and service control policies.
- Networking: Build secure VPC designs and private connectivity (VPC endpoints, PrivateLink, Transit Gateway) so agent workloads can reach internal systems safely.
- Identity Boundaries: Define IAM roles, permission boundaries and least-privilege access for platform services, pipelines and consuming teams.
- Reusable IaC Modules: Build and maintain versioned Terraform and/or AWS CDK modules other teams can use with confidence.
- Build Pipelines: Design and own CI/CD pipelines that build, test, scan and publish agent containers to Amazon ECR.
- Environment Promotion: Automate promotion from dev to test to production with approval gates, rollback and version tracking.
- Runtime Deployment: Configure and deploy agents to AgentCore Runtime, including session settings, scaling, config and secrets handling.
- Golden Path Templates: Build starter repos and pipeline templates so every new agent is set up and shipped the same way.
- Security and Compliance: Build encryption, logging, tagging, image scanning and audit requirements in from the start, working with client security teams.
- Documentation and Enablement: Write module docs, decision records and runbooks so the platform doesn't depend on any one person.
QUALIFICATIONS
- 6+ years of cloud, platform or DevOps engineering experience, with at least 4 years hands-on building production AWS environments.
- Strong infrastructure-as-code skills with Terraform and/or AWS CDK/CloudFormation, including writing reusable modules.
- Deep understanding of AWS IAM, including cross-account access, permission boundaries and service control policies.
- Solid AWS networking knowledge: VPC design, routing, VPC endpoints, PrivateLink, Transit Gateway and DNS.
- Hands-on experience building CI/CD pipelines (GitHub Actions, GitLab CI, AWS CodePipeline/CodeBuild or similar).
- Strong container skills: Docker, Amazon ECR, and deploying to ECS, EKS, Fargate or Lambda.
- Experience with secrets and config management (AWS Secrets Manager, Parameter Store).
- Deep hands-on strength in at least one of the two focus areas, and working knowledge of the other.
- Clear communication and comfortable working in a blended client and vendor team.
PREFERRED QUALIFICATIONS
- AWS certifications such as Solutions Architect Professional, DevOps Engineer Professional or Advanced Networking.
- Experience with Amazon Bedrock, AgentCore Runtime, or deploying LLM/agent-based applications.
- Experience with policy-as-code and supply chain security tools (e.g., OPA, Checkov, cosign, SBOM tooling, Amazon Inspector).
- Experience in pharma, life sciences or another regulated industry with strict security and change control requirements.
WHO YOU ARE
- You think in reusable building blocks and care about the engineers who use them after you
- You default to secure, least-privilege designs and can explain why
- You automate anything you have to do twice
- You write things down so decisions don't live only in your head
- You work well inside a client team and build trust quickly
- You have prior experience in consulting
- Prior experience and connections in the Life Sciences industry is preferred