Cloud Platform Engineer
- Role
- DevOps
- Employment
- Contract
Open to Anywhere in LATAM. Set where you work from to check your eligibility.
No BS summary
AWS cloud/platform engineer for a large enterprise migration program: build and run multi-account AWS landing zones (Control Tower, account vending, guardrails) plus hybrid networking, writing Terraform modules other engineers depend on. Must have production Terraform at scale and deep AWS networking (VPC, Transit Gateway, Direct Connect, VPN). Full-time remote, open to candidates anywhere in LATAM.
Core skills
Required skills
Optional skills
Required languages
This role builds and extends AWS landing zones, account vending and networking for enterprise migrations — the infrastructure and automation specialism, distinct from the Microsoft-workload and data-focused roles on the same program. The scope for year one: 191 applications in the estate being migrated to AWS across 20 business departments, 27 Azure subscriptions and 451 resource groups to map into an AWS account structure, and 5 migration waves to support, each with its own cutover windows and rollback plans. The landing zone itself — account vending, guardrails and centralized networking — is something you'll help build and run, not just consume. What you will do Build and extend AWS multi-account landing zones with Control Tower, account vending and service control policies. Design and implement hybrid networking — VPC architecture, Transit Gateway, Direct Connect and VPN back to on-premises and Azure. Write and maintain Terraform modules that other engineers depend on. Automate delivery through CI/CD — GitHub Actions, GitLab CI or CodePipeline. Operate containerized workloads on EKS with Helm and Argo CD where in scope. Write runbooks and hand over to client engineering teams; knowledge transfer is part of every engagement. Required Production experience writing and maintaining Terraform modules at scale. The single most important skill for this role. Strong AWS networking: VPC design, routing, Transit Gateway, VPN and hybrid connectivity. Deep AWS platform knowledge: compute, storage and IAM. AWS Solutions Architect Associate or higher expected. Comfortable on Linux, with Bash and Python to a working standard. Production CI/CD experience: GitHub Actions, GitLab CI, Jenkins or CodePipeline. Demonstrated experience building or operating a multi-account AWS landing zone. Professional written and spoken English. Nice to have AWS Control Tower, Terragrunt, Kubernetes/EKS, Helm, Argo CD, Ansible, Azure, VMware, AWS DevOps Professional, Serverless/Lambda, GuardDuty/Security Hub, PCI-DSS environments. Engagement details Full-time Start date: February 2027 Open to candidates from all LATAM
What you'll do
- Build and extend AWS multi-account landing zones with Control Tower, account vending and service control policies
- Design and implement hybrid networking — VPC architecture, Transit Gateway, Direct Connect and VPN back to on-premises and Azure
- Write and maintain Terraform modules that other engineers depend on
- Automate delivery through CI/CD — GitHub Actions, GitLab CI or CodePipeline
- Operate containerized workloads on EKS with Helm and Argo CD where in scope
- Write runbooks and hand over to client engineering teams; knowledge transfer is part of every engagement
What they require
- Production experience writing and maintaining Terraform modules at scale — the single most important skill
- Strong AWS networking: VPC design, routing, Transit Gateway, VPN and hybrid connectivity
- Deep AWS platform knowledge: compute, storage and IAM
- AWS Solutions Architect Associate or higher certification expected
- Comfortable on Linux, with Bash and Python to a working standard
- Production CI/CD experience: GitHub Actions, GitLab CI, Jenkins or CodePipeline
- Demonstrated experience building or operating a multi-account AWS landing zone