- Build the AWS Organization as code, including separate accounts, organizational units, IAM Identity Center with MFA, and organization-wide CloudTrail and Config.
- Design private VPCs across three Availability Zones, inspected egress, Transit Gateway, VPC endpoints, Client VPN, and partner connectivity patterns.
- Run Amazon EKS with a private endpoint, Bottlerocket nodes, Karpenter, pod security standards, Cilium network policies, upgrades, and capacity and cost tuning.
- Operate Aurora PostgreSQL, MSK, S3 zones with Object Lock and cross-region replication, ECR, Secrets Manager, AWS Backup, Keycloak, Prometheus, and OpenTelemetry.
- Own the delivery pipeline using GitHub Actions with OIDC to AWS, OpenTofu plan and apply with policy gates, Argo CD, Helm conventions, and Kyverno admission.
- Write runbooks, lead monthly restore drills and the annual cold-rebuild test, take on-call for severity-1 platform incidents, and run post-incident reviews.
- Report monthly on availability, capacity, and tagged AWS spend; prove portability on open-source equivalents and hand the platform over with operational documentation.
- Guide a second platform engineer day to day and review the DevSecOps engineer's infrastructure changes.
AWSKubernetesPrometheus+2 more