Job Description
Hi
\n
Hope you're doing well!
\n
Please go through the below description
\n
\n
Job Title: Cloud / Infrastructure Lead Engineer
\n
Location: Remote - US
\n
Duration: Long term Contract
\n
Note: Only on W2
\n
ANY VISA
\n
Experience : 10–14 yrs
\n
\n
\n
Role Purpose
\n
Own the technical architecture and delivery quality of all cloud infrastructure remediation streams. With dedicated specialists (Cloud Platform Engineer for WS1/WS3, Senior Data Platform Engineer for WS4b) now executing the high-complexity delivery work, this role focuses on architecture authority, cross-specialist coordination, and quality gate ownership — with architecture-level familiarity across all domains rather than hands-on mastery of every stack.
\n
Key Responsibilities
\n
- \n
- Hold architecture authority over all infrastructure delivery streams — review and sign off designs from the Cloud Platform Engineer and Senior Data Platform Engineer before execution
- Define rollback procedures for all infrastructure streams; validate they are tested before any production window
- Coordinate production maintenance window scheduling across all 8 environments — sequencing, pre-window snapshot validation, go/no-go criteria
- Review and sign off all CloudFormation, Ansible, and IaC outputs from the three India-based cloud engineers before four-gate submission
- Lead the Phase 1 OS inventory assessment direction — define the per-instance discovery approach; Cloud Engineer OS/Patching executes
- Handle interactive AWS Console and AppStream sessions for restricted accounts, working alongside the Restricted-Account Cloud Engineer
- Enforce IaC-first delivery principle across the entire cloud infrastructure team — zero console changes without an approved Change Order
- Provide architecture-level oversight on Wiz remediation template library design — review patterns from Cloud Engineer Wiz before deployment
- Escalate any cloud infrastructure delivery risk to the Principal Technical Delivery Architect within the same business day
- Own accountability for WS1, WS2, WS3, WS4a, WS4b, and WS14 delivery — the specialists execute; this role approves and governs
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
Must-Have Skills & Experience
\n
- \n
- 10+ years AWS cloud infrastructure engineering; 5+ years as architecture lead on multi-account, multi-environment AWS programs
- Expert CloudFormation — parameterised templates, nested stacks, cross-stack references, StackSets, CFN-LINT/cfn-nag compliance
- Architecture-level familiarity with Amazon EMR and HBase — sufficient to review and approve a blue/green upgrade strategy, Phoenix SQL regression plan, and HBase 1.x/2.x compatibility matrix; a dedicated specialist executes
- Architecture-level familiarity with ECS/Fargate, ALB/NLB, and VPC networking — sufficient to review task definition designs, NACL/SG three-tier segmentation, and Transit Gateway/Network Firewall patterns
- Wiz CSPM — finding category interpretation, remediation pattern review, Phases A–D sequencing oversight
- AWS networking — VPC, Security Groups, NACLs, Transit Gateway, Network Firewall, PrivateLink, VPC Flow Logs
- Production change management — maintenance window governance, rollback decision authority, RTO/RPO accountability
- IaC governance — CFN-LINT, cfn-nag, Ansible playbook review standards, pipeline gate enforcement
- Ansible — playbook review and approval; authoring experience sufficient for architecture decision
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
Nice-to-Have Skills
\n
- \n
- AWS Certified Advanced Networking Specialty or AWS DevOps Engineer Professional
- Hands-on Terraform — useful for cross-referencing IaC patterns even though this engagement is CloudFormation
- CloudWatch advanced monitoring — Contributor Insights, composite alarms, anomaly detection
- Multi-tenant SaaS infrastructure delivery for FSI or banking clients
\n
\n
\n
\n
\n
Tools & Platforms
\n
AWS Console (mandatory for restricted accounts), CloudFormation, StackSets, Ansible (review), SSM Maintenance Windows, EMR (architecture review), ECS/Fargate (review), Wiz, AWS Config, VPC Flow Logs, Transit Gateway, Network Firewall, Jenkins, Bitbucket, CFN-LINT, cfn-nag, CloudWatch, AWS CLI
\n
Success Measures
\n
- \n
- All infrastructure delivery streams accepted through four-gate process on schedule; rework identified and resolved before client submission
- Rollback runbooks tested in non-production and signed off before every production maintenance window opens
- Cloud Platform Engineer and Senior Data Platform Engineer delivery quality consistently meets four-gate standard without Principal Architect escalation
\n
\n
\n
\n
\n
Thanks & Regards
