Cloud Infrastructure Engineer
Who We Are
At Platform Science, we’re working to connect everything that moves.
Founded in 2015, Platform Science is an open IoT platform partnering with innovative fleets, application developers, vehicle manufacturers, and equipment providers across the transportation industry. Our technology helps deliver modern solutions to supply chain professionals around the world.
Our employees bring diverse backgrounds, experiences, and perspectives. We believe great ideas can come from anywhere, and we foster a culture built around innovation, collaboration, empathy, resilience, and transparency.
About the Role
Platform Science is looking for a Cloud Infrastructure Engineer to join our CloudOps team.
CloudOps owns the foundational cloud infrastructure that enables our engineering teams to build, deploy, and operate products at scale. The team manages identity, networking, governance, security guardrails, backup, disaster recovery, and shared cloud services across a multi-account AWS environment spanning hundreds of accounts and multiple business units. We are also extending this operating model across Azure and GCP.
This is a hands-on senior individual contributor role for an engineer who enjoys building foundational infrastructure and solving complex cloud problems. You will own infrastructure and platform capabilities end to end, work primarily through Infrastructure as Code, and create guardrails and self-service capabilities that allow engineering teams to move quickly without sacrificing security or reliability.
The scope is intentionally broad. You may work on cloud identity and permissions, private networking, multi-cloud governance, backup and disaster recovery, security remediation, or developer self-service capabilities.
AI-assisted engineering is also part of how the team operates. We use AI coding agents to accelerate implementation and automation while maintaining rigorous engineering review, security, and production standards.
What You'll Do
- Implement and maintain components of our multi-account AWS Landing Zone (AWS Organizations, Control Tower, AFT, tagging standards, permission boundaries) within established patterns.
- Support governance, security controls, observability, and backup capabilities across AWS, and increasingly Azure and GCP, following established standards.
- Administer cloud identity and access management day-to-day — Okta federation, AWS IAM Identity Center, permission sets, group membership, credential hygiene — applying least-privilege principles within existing frameworks.
- Configure and maintain cloud networking components: IP address management, VPC configuration, routing, transit connectivity, DNS — following architecture set by senior engineers.
- Contribute to migrating workloads from public-internet exposure to private/zero-trust networking models under established playbooks.
- Build and maintain self-service infrastructure workflows (account provisioning, environment provisioning, access requests) using existing frameworks and patterns.
- Execute backup, restore, and disaster recovery procedures across cloud regions and accounts; help maintain and test DR runbooks.
- Build and maintain Terraform/Terragrunt modules consumed by other engineering teams, following established module patterns.
- Maintain CI/CD automation for cloud infrastructure.
- Investigate and remediate cloud security findings identified by Security teams.
- Support FinOps initiatives by implementing identified cost optimization opportunities.
- Maintain documentation, runbooks, and operating procedures for owned systems.
- Use AI coding agents as part of the engineering workflow, validating output and maintaining ownership of code review, testing, and production outcomes for your work.
Required Experience
- 5+ years of professional experience in Cloud Infrastructure, DevOps, Site Reliability Engineering, Platform Engineering, Systems Engineering, or a related infrastructure discipline (or equivalent combination of education and experience).
- 3+ years of hands-on experience with AWS or another major public cloud, with significant AWS experience strongly preferred.
- 1+ years of Infrastructure as Code experience, preferably using Terraform and/or Terragrunt.
- Working experience within an AWS multi-account environment (AWS Organizations, Control Tower, or comparable landing-zone architecture).
- Exposure to at least one additional major cloud platform (Azure or GCP) beyond a single workload.
- Experience building or maintaining Infrastructure as Code modules used by others.
- Hands-on experience with cloud identity and access management: SSO, SAML federation, SCIM provisioning, IAM policies/roles, permission boundaries.
- Solid cloud networking fundamentals: IP address planning, VPC/VNet configuration, routing, DNS, network security.
- Experience maintaining CI/CD pipelines (GitHub Actions, Jenkins, or similar).
- Scripting/programming experience with Python, Go, Bash, or similar.
- Strong Linux fundamentals.
- Working knowledge of Kubernetes and cloud-native infrastructure.
- Experience using AI coding agents or AI-assisted development tools (Claude Code, Cursor, Codex, or similar), including validating generated code and identifying operational or security risk.
- Ability to work independently on well-defined infrastructure tasks and exercise judgment within established guidelines.
- Strong written and verbal communication skills; able to collaborate across Engineering, Security, and FinOps teams.
- Advanced English proficiency.
- Bachelor's degree in Computer Science, Software Engineering, Information Technology, or a related technical field + 5 years of experience; or equivalent combination of education and experience.
- Must reside in Brazil.
Preferred Qualifications
Experience with one or more of the following is a plus:
- AWS Control Tower and Account Factory for Terraform (AFT)
- AWS IPAM, Transit Gateway, or Cloud WAN
- Exposure to multi-cloud environments (AWS, Azure, and/or GCP)
- MongoDB Atlas, Elastic Cloud, or similar managed data platforms
- Wiz, GuardDuty, CrowdStrike, or other cloud security posture/security platforms
- Zero-trust networking technologies such as Zscaler ZPA
- Cloudflare WAF and DNS
- Certificate and PKI lifecycle basics (ACM, cert-manager, Let's Encrypt)
- Exposure to agentic automation pipelines or AI agent workflows
- Cloud cost optimization / FinOps fundamentals
- AWS, Azure, GCP, Terraform, or Kubernetes certifications
Seen 3 days ago · Platform Science postings close after a median of 8 days.
Original posting on Platform Science's site ↗
Posting text belongs to the employer. Removal requests: contact us.
Nearby
Live postings like this one
Same employer first, then the same role elsewhere.
- 2d ago
- 2d ago
- 2d ago
- 3d ago
- 4d ago
- 4d ago
- 4d ago
- 7d ago
One job at a time
One posting. One CV. $25.
Pick the job you actually want and we write for it.