Principal Platform Engineer

Impruvon

$160K — $200K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years of experience owning production AWS infrastructure with multi-account AWS Organizations
  • Deep experience with AWS CDK or comparable Infrastructure as Code tools
  • Proven design and operation of CI/CD pipelines, preferable with GitHub Actions
  • Strong production experience with containerization and orchestration (ECS or EKS)
  • Direct experience with HIPAA and SOC 2 Type II compliance
  • Ability to handle ambiguous infrastructure problems independently in fast-paced environments
  • Excellent communication skills, adept at asynchronous documentation

Responsibilities

  • Own and evolve AWS environment across multi-account structure, including security governance
  • Maintain and extend the Infrastructure-as-Code repo, adopting rigorous practices like code review and version control
  • Enhance CI/CD pipelines for faster, safer deployments using GitHub Actions
  • Develop and refine containerization strategies, ensuring security and operational efficiency
  • Oversee and improve developer environments for consistent setups
  • Lead initiatives for compliance and security posture, adapting to HIPAA and SOC 2 Type II
  • Identify risks in infrastructure and compliance, driving proactive solutions
  • Elevate engineering culture by mentoring and simplifying team processes

Benefits

  • 100% company-paid medical coverage (base plan)
  • Dental & vision available
  • 401(k) retirement plan
  • Company-paid life, AD&D, STD & LTD insurance
  • Lifestyle Spending Account
  • Flexible PTO + company holidays
  • Flexible, remote-friendly work environment
  • Mission-driven work with real impact on vulnerable populations
Full Job Description
Principal Platform Engineer

Department: Engineering

Employment Type: Full Time

Location: Remote - USA

Reporting To: Principal Engineer (Head of Engineering)

Compensation: $160,000 - $200,000 / year

Description

We are hiring a Principal Platform Engineer to take ownership of our existing platform infrastructure. Today, our engineering leadership manages AWS, DevOps, and compliance. You will be the primary technical lead for this domain. We are looking for someone who can mature our practices, optimize our workflows, and scale our infrastructure. While you will partner with engineering leadership on strategy, you will be the primary authority on technical implementation. We seek a self-starter who thrives when given a high-level outcome and the freedom to define the technical path to get there.

You will own our AWS footprint end-to-end: a multi-account AWS Organizations setup (currently 3 accounts), our Infrastructure-as-Code repo (AWS CDK), CI/CD (GitHub Actions), containerization and orchestration (ECS, considering EKS), and our developer environment tooling (docker compose, devcontainers, mise). You will be responsible for elevating our security and compliance posture - HIPAA, SOC 2 Type II, and likely upcoming work toward StateRAMP or FedRAMP.

Most of this foundation already exists. This is not a "build it from zero" role - it's a "take a working but under-resourced platform and bring it to the next level" role. We are looking for an experienced engineer who can quickly assess our environment, identify opportunities for improvement, and drive solutions with a high degree of agency. If you thrive in high-growth, mission-driven environments and are eager to tackle complex engineering challenges while maintaining a high technical bar, this role is for you.

Key Responsibilities
  • Own and evolve our AWS environment across a multi-account AWS Organization structure, including account boundaries, service control policies, cross-account IAM, and cost and security governance.
  • Extend and maintain our Infrastructure-as-Code repo (AWS CDK), treating infrastructure changes with the same rigor as application code - reviewed, tested, and versioned.
  • Own and improve CI/CD pipelines in GitHub Actions, pushing toward faster, safer, more automated deployments across applications.
  • Own our containerization strategy (Docker) and container orchestration platform (currently ECS, potentially moving to EKS) - image standards, base image and dependency security, and day-to-day orchestration operations.
  • Maintain and improve our devcontainer setup so engineers get consistent reproducible local development environments.
  • Lead the technical work to elevate our compliance and security posture - maintaining and evolving controls for HIPAA and SOC 2 Type II, and leading the technical requirements for StateRAMP/FedRAMP readiness.
  • Lead infrastructure-focused security work: secrets management, network security, vulnerability management, and incident response readiness.
  • Partner with engineering leadership to evolve our platform strategy and formalize our infrastructure practices as we scale.
  • Proactively identify risk in our infrastructure and compliance posture - cost, security, reliability, audit gaps - and drive fixes to completion without being asked.
  • Elevate our engineering culture by setting high standards, mentoring other engineers, and simplifying processes to help the team move faster as we scale.
  • Prioritize pragmatic simplicity, ensuring we build only what is necessary to validate assumptions and deliver value, while resisting complexity that hinders agility.
  • Ensure the reliability and performance of our critical systems by taking ownership of production issues and implementing sustainable fixes.


Skills, Knowledge and Experience

Requirements
  • AWS Infrastructure Ownership: 7+ years of experience owning production AWS infrastructure, including direct, hands-on experience with multi-account AWS Organizations (SCPs, consolidated billing, cross-account IAM).
  • Infrastructure as Code: Deep hands-on experience with AWS CDK, or comparable IaC tooling (Terraform, Pulumi) with a demonstrated ability to ramp quickly. You treat infrastructure as software: code review, testing, version control.
  • CI/CD: Proven experience designing, operating, and improving CI/CD pipelines; direct experience with GitHub Actions strongly preferred.
  • Containerization & Orchestration: Strong production experience with containers and a container orchestration platform (ECS or EKS/Kubernetes).
  • Security & Compliance: Direct experience operating infrastructure under HIPAA and/or SOC 2 Type II.
  • Autonomy: A track record of owning ambiguous, high-stakes infrastructure and security problems end-to-end with minimal supervision in fast-paced startup environments where requirements evolve. You will be responsible for maturing and evolving our playbook.
  • Communication: Excellent written and verbal communication skills. In a remote-first company, your ability to communicate asynchronously and document infrastructure decisions and compliance controls clearly enough for both engineers and auditors to follow is critical.
  • Technical Leverage: Demonstrated ability to write tools or infrastructure patterns that amplify the productivity of the rest of the engineering team, rather than just solving problems for yourself.


Nice to Have
  • AWS Certified Solutions Architect - Professional
  • AWS Certified Security - Specialty
  • AWS Certified Generative AI Developer - Professional
  • Experience in healthcare, fintech, or another highly regulated industry.
  • Experience with StateRAMP or FedRAMP.
  • Familiarity with Ruby on Rails, React, and Flutter (useful for cross-team collaboration).
  • Experience with IoT or hardware-connected systems.


What Success Looks Like
  • First 30 Days: Audit the current infrastructure to identify top technical debt and compliance risks. Ship your first impactful changes to production while establishing strong working relationships with the engineering team.
  • First 60 Days: Take primary ownership of our AWS environment. Begin driving our infrastructure roadmap forward by proactively implementing improvements.
  • First 90 Days: Operate with full autonomy as the technical authority for the platform. Propose and begin implementing a roadmap for one major initiative (e.g., EKS migration) without needing guidance on implementation details.


Benefits

At Impruvon, we know our people are our greatest asset. We provide a benefits package designed to support your well-being and growth, including:
  • Competitive compensation aligned with experience
  • 100% company-paid medical coverage (base plan)
  • Dental & vision available
  • 401(k) retirement plan
  • Company-paid life, AD&D, STD & LTD insurance
  • Lifestyle Spending Account (wellness, personal use, and company swag)
  • Flexible PTO + company holidays
  • Flexible, remote-friendly work environment
  • Mission-driven work with real impact on vulnerable populations

Similar Jobs

More Jobs at Impruvon

More Information Technology Jobs

Find similar Principal Platform Engineer jobs: