Job Summary: We are seeking an experienced AWS Reverse Engineering Engineer to analyze existing AWS environments, applications, infrastructure, configurations, and deployment processes where documentation or Infrastructure-as-Code may be incomplete or unavailable. The role focuses on reverse-engineering the current AWS landscape, identifying dependencies and configuration patterns, documenting the As-Is architecture, and translating existing environments into reusable architecture documentation, Infrastructure-as-Code (IaC), operational procedures, and modernization recommendations.
Key Responsibilities
• Perform detailed discovery and reverse engineering of existing AWS environments across multiple accounts, regions, VPCs, applications, and environments.
• Analyze AWS resources including EC2, VPC, ALB/NLB, Route 53, S3, EBS, RDS/Aurora, DynamoDB, Lambda, ECS/EKS, IAM, KMS, CloudFront, API Gateway, SQS/SNS, CloudWatch, and CloudTrail.
• Reconstruct As-Is cloud architecture from deployed AWS resources when design documents are unavailable or outdated.
• Identify relationships and dependencies between applications, compute, databases, networking, storage, security controls, and external integrations.
• Reverse-engineer manually provisioned infrastructure and convert it into Terraform, AWS CloudFormation, or other IaC frameworks.
• Analyze existing CI/CD pipelines, scripts, and automation implemented through GitHub Actions, GitLab, Jenkins, AWS CodePipeline, and CodeBuild.
• Review IAM roles and policies, security groups, NACLs, KMS configurations, secrets, certificates, and network security controls.
• Analyze application deployment patterns, runtime configurations, environment variables, parameter stores, secrets, and service integrations.
• Create infrastructure inventories, dependency maps, architecture diagrams, and configuration baselines.
• Compare deployed infrastructure against available documentation and identify configuration and documentation gaps.
• Identify technical debt, obsolete resources, configuration drift, security risks, and opportunities for standardization.
• Develop As-Is and To-Be architecture documentation and provide recommendations for modernization and optimization.
• Support migration and modernization initiatives involving rehost, replatform, refactor, or cloud-native transformation.
• Work closely with application, DevOps, SRE, security, network, and cloud architecture teams.
• Create detailed handover documentation, runbooks, deployment procedures, and operational support documentation.
Required Qualifications
• 6-10+ years of overall experience, with 4+ years of hands-on AWS experience.
• Strong hands-on experience with AWS cloud architecture and administration.
• Strong experience with AWS services including EC2, VPC, IAM, S3, RDS, Lambda, ECS/EKS, ELB/ALB, Route 53, CloudWatch, CloudTrail, KMS, Secrets Manager, Systems Manager, and API Gateway.
• Strong Terraform experience for infrastructure discovery, reconstruction, and standardization.
• Hands-on experience with Git, GitHub/GitLab, Jenkins, AWS CodePipeline/CodeBuild, and CI/CD automation.
• Experience with Docker and Kubernetes/EKS, including analysis of existing workloads, manifests, Helm configurations, and service dependencies.
• Strong scripting skills using Python, Bash, and/or PowerShell for discovery, inventory collection, and automation.
• Strong understanding of AWS networking, including VPCs, subnets, routing, security groups, NACLs, Transit Gateway, VPN, Direct Connect, DNS, and load balancing.
• Strong understanding of AWS security, including IAM roles and policies, KMS, Secrets Manager, logging, auditing, security controls, and least-privilege principles.
• Experience with CloudWatch, CloudTrail, and centralized logging and monitoring solutions.
• Ability to understand unfamiliar AWS environments with limited documentation.
• Ability to trace infrastructure and application dependencies and perform root-cause and dependency analysis.
• Ability to read and interpret existing Terraform, CloudFormation, scripts, and pipeline code.
• Experience determining how manually created AWS resources were configured and reconstructing architecture diagrams from deployed infrastructure.
• Experience identifying configuration drift between Infrastructure-as-Code and deployed AWS resources.
• Ability to convert manually provisioned infrastructure into standardized IaC.
• Strong ability to document current state, gaps and risks, and target-state architecture.
Preferred Qualifications
• Experience with AWS CloudFormation or AWS CDK.
• Experience supporting cloud migration and modernization programs involving rehost, replatform, refactor, or cloud-native transformation.
• Experience working across application engineering, DevOps, SRE, security, networking, and cloud architecture teams.
• Experience with large, multi-account and multi-region AWS environments.
• Experience developing reusable architecture documentation, operational procedures, runbooks, and handover materials.