Stellantis is seeking a skilled and motivated
Cloud Engineer to reinforce and support the design, implementation, and continuous improvement of our AWS Foundation Product - an AWS Landing Zone governing 1,500+ AWS accounts distributed across all Stellantis business functions and geographies (NAFTA, LATAM, Europe, EMEA, and APAC). As a Cloud Engineer, you will collaborate with cross-functional teams - including SecOps, FinOps, platform consumers, and global infrastructure teams - to build reusable platform components, drive DevOps maturity, and operate the AWS organizational layer as a product. AI tools are an integral part of daily engineering practice in this team.
Key Responsibilities:- Design and implement end-to-end automation of the AWS account lifecycle - provisioning, configuration, baselining, and decommissioning - achieving zero-touch operations at scale using Lambda, Step Functions, and EventBridge..
- Build and maintain a self-service cloud platform (account vending machine, network factory, identity federation) enabling application teams to onboard and operate autonomously, backed by an Internal Developer Portal with AI-powered capabilities.
- Own Infrastructure as Code (IaC) delivery pipelines across 1,500+ accounts using Terraform, enforcing GitOps practices, policy-as-code, drift detection, and automated testing at every stage.
- Define and operate SLOs, Error Budgets, and an observability stack with AI-assisted anomaly detection across provisioning, cost, network, and security signals - enabling predictive operations rather than reactive firefighting.
- Manage AWS Control Tower, Organizations, and Service Control Policies (SCPs), enforcing governance, least-privilege IAM, and compliance guardrails with automated self-healing when drift is detected.
- Apply AI tools as a standard daily practice for IaC authoring, automation scripting, test generation, incident analysis, and runbook maintenance - maintaining full engineering ownership of all generated outputs.
- Lead post-mortems and translate every incident into systemic engineering improvements; maintain runbooks and playbooks as versioned, executable artifacts.
Basic Qualifications:
- Bachelor's degree in computer science, Information Technology, or related field.
- Minimum 5 years of experience designing, deploying, and managing AWS cloud environments at enterprise scale in multi-account contexts.
- Expertise in AWS multi-account services: AWS Control Tower, Organizations, Service Control Policies, and Landing Zone design patterns.
- Expert-level Terraform and/or AWS CDK for Infrastructure as Code; GitOps delivery pipelines with drift detection and policy gates (GitHub Actions, GitLab CI...).
- Proficiency in Python and/or Typescripts for building platform tooling, internal CLIs, automation services, and event-driven workflows (Lambda, Step Functions, EventBridge...).
- Daily use of AI coding assistants (GitHub Copilot, Claude Code, Codex ...) with demonstrated ability to review, validate, and own AI-generated code at production quality.
- Solid understanding of DevOps and SRE practices: DORA metrics, SLOs, error budgets, incident management, policy-as-code, and blameless post-mortem culture.
- Strong knowledge of AWS networking: Transit Gateway, VPC design, Route 53, Direct Connect, and PrivateLink.
- Experience with AWS security services: Security Hub, GuardDuty, Config Rules, IAM design, and automated compliance remediation.
- AWS Certifications preferred: DevOps Engineer Professional, Solutions Architect Professional, or Security Specialty.
- Familiarity with AIOps and AI/ML platform services (Amazon Bedrock, SageMaker, Amazon Q Business, DevOps Guru) is a strong plus.