Senior Platform Engineer (Lead)

New
H
HK TechHealthcare data
Remote within the U.S., Core hours 9:00 a.m.–3:00 p.m. MountainContractLead
Salary not disclosed
Apply NowOpens the employer's application page

Job Details

Experience
7+ years in infrastructure or platform engineering, including 4+ years running production Kubernetes on AWS (EKS strongly preferred). 5+ years in a HIPAA, FHIR and HL7 required also.
Required Skills
AWSKubernetesPrometheusTerraformGitHub Actions

Requirements

  • Have 7+ years of infrastructure or platform engineering experience.
  • Have 4+ years running production Kubernetes on AWS; EKS is strongly preferred.
  • Have 5+ years in a HIPAA, FHIR and HL7 context, as stated in the posting.
  • Have deep Terraform or OpenTofu experience, including multi-account organizations, modules, remote state, and policy as code using OPA, Checkov, or tfsec.
  • Have built an AWS Organization from zero.
  • Have hands-on experience with VPC design, Transit Gateway, Network Firewall, PrivateLink, IAM Identity Center, KMS, Aurora PostgreSQL, MSK or Kafka, S3 Object Lock, ECR, and AWS Backup.
  • Have GitOps and CI experience with Argo CD or Flux, Helm, GitHub Actions, container image signing, and SBOMs.
  • Have observability experience with Prometheus and Grafana, OpenTelemetry, and log shipping to OpenSearch or Elasticsearch.
  • Have operated a regulated workload such as HIPAA, FedRAMP, or PCI, and be able to explain how the regulation affected its design.
  • Write clear runbooks and ADRs and be comfortable leading and reviewing the work of one or two engineers.
  • Nice to have: production experience with Karpenter and Bottlerocket, Cilium or Calico network policy, Spark on Kubernetes, Iceberg tables, Strimzi or MSK at scale, Keycloak or another OIDC provider, and Kyverno or Gatekeeper.
  • Nice to have: AWS Solutions Architect or DevOps Engineer Professional, CKA or CKS, public-sector or healthcare delivery experience, or experience handing a platform over to a client team.

Responsibilities

  • Build the AWS Organization as code, including separate accounts, organizational units, IAM Identity Center with MFA, and organization-wide CloudTrail and Config.
  • Design private VPCs across three Availability Zones, inspected egress, Transit Gateway, VPC endpoints, Client VPN, and partner connectivity patterns.
  • Run Amazon EKS with a private endpoint, Bottlerocket nodes, Karpenter, pod security standards, Cilium network policies, upgrades, and capacity and cost tuning.
  • Operate Aurora PostgreSQL, MSK, S3 zones with Object Lock and cross-region replication, ECR, Secrets Manager, AWS Backup, Keycloak, Prometheus, and OpenTelemetry.
  • Own the delivery pipeline using GitHub Actions with OIDC to AWS, OpenTofu plan and apply with policy gates, Argo CD, Helm conventions, and Kyverno admission.
  • Write runbooks, lead monthly restore drills and the annual cold-rebuild test, take on-call for severity-1 platform incidents, and run post-incident reviews.
  • Report monthly on availability, capacity, and tagged AWS spend; prove portability on open-source equivalents and hand the platform over with operational documentation.
  • Guide a second platform engineer day to day and review the DevSecOps engineer's infrastructure changes.
View Full Description & ApplyYou'll be redirected to the employer's site
View details
Apply Now