About The Company
We are hiring candidates on behalf of a global technology services and solutions company headquartered in East Brunswick, New Jersey, USA, with development and delivery centers across the globe. Since 2003, we have been helping enterprises accelerate digital transformation through innovative solutions in Cloud, AI, Cybersecurity, Governance, Risk & Compliance (GRC), Enterprise Applications, Procurement, Healthcare, and Managed IT Services.
We are seeking an experienced Principal Cloud Platform Architect / Engineering Lead to spearhead the design, implementation, and operationalization of an enterprise-grade AWS cloud platform supporting a major cloud modernization initiative.
This is not a traditional DevOps role. We are looking for a highly technical cloud platform engineering leader with deep expertise in AWS architecture, Kubernetes, cloud networking, security, and platform engineering. The ideal candidate should be equally comfortable designing enterprise architecture, writing Terraform code, implementing Kubernetes platforms, reviewing security controls, and leading cloud migration initiatives.
You will collaborate closely with Cloud Engineering, Infrastructure, Networking, Cyber Security, Platform Engineering, Operations, and Application Development teams to build a secure, scalable, resilient, and highly observable cloud platform supporting enterprise-scale workloads.
This is a net-new position created for a strategic multi-year cloud modernization program with strong long-term growth potential.
Role Highlights
- Principal-level hands-on technical leadership role
- Enterprise AWS Platform Engineering
- Production-scale Amazon EKS implementation
- Cloud Modernization Program
- Multi-account AWS Architecture
- Security-first engineering culture
- Hybrid Cloud Architecture
- Platform Automation
- Enterprise Observability
- Zero Trust Security
Project Overview
The organization is consolidating applications currently running on:
- AWS Amplify
- Amazon ECS
- AWS Lambda
- On-Premises Infrastructure
into a standardized, enterprise-scale Amazon EKS platform.
The cloud platform is designed around:
- AWS Organizations
- Multi-account AWS Architecture
- Amazon EKS
- Transit Gateway
- AWS PrivateLink
- Akamai CDN & WAF
- Bitbucket Pipelines
- OpenTelemetry
- SigNoz
- Hybrid Connectivity
- Zero Trust Security
First 90 Days
The initial engagement focuses on understanding the existing AWS environment and gradually leading platform implementation.
Initial Responsibilities
- Review the current AWS landscape
- Understand repositories, pipelines, and application architecture
- Validate and enhance the target platform design
- Participate in Cyber Security architecture reviews
- Separate Development, UAT, and Production environments using AWS Organizations
- Consolidate repositories into standardized structures
- Optimize Bitbucket CI/CD pipelines
- Build the enterprise platform while maintaining production stability
Key Responsibilities
- Architect and implement an enterprise-scale AWS Kubernetes platform.
- Design secure multi-account AWS environments using AWS Organizations.
- Lead Amazon EKS platform engineering for production workloads.
- Establish Kubernetes governance, operational standards, and platform best practices.
- Design secure hybrid networking using:
- Transit Gateway
- AWS PrivateLink
- VPN
- AWS Direct Connect
- VPC Routing
- Build Zero Trust cloud security architecture.
- Implement least-privilege IAM models across AWS and Kubernetes.
- Design enterprise CI/CD pipelines using Bitbucket Pipelines and self-hosted runners.
- Develop Infrastructure as Code using Terraform.
- Build reusable Terraform modules and Helm charts.
- Implement GitOps operating models.
- Lead migration of workloads from AWS Amplify, ECS, Lambda, and on-premises environments to Amazon EKS.
- Establish Kubernetes RBAC, Network Policies, multi-tenancy, secrets management, and workload isolation.
- Implement enterprise observability using:
- OpenTelemetry
- SigNoz
- Prometheus
- Grafana
- Centralized Logging
- Distributed Tracing
- Partner with Cyber Security teams on:
- Architecture Reviews
- Threat Modeling
- Compliance
- Security Assessments
- Develop architecture documents, runbooks, standards, and implementation roadmaps.
- Lead disaster recovery planning, resiliency testing, and production readiness.
- Mentor engineers and provide technical leadership across platform engineering initiatives.
Priority Technical Skills
Tier 1 – Mandatory (Hiring Gate)
Candidates must demonstrate deep hands-on expertise in:
AWS
- AWS
- Amazon EKS
- AWS Architecture
- AWS Networking
- VPC
- Transit Gateway
- AWS PrivateLink
- IAM
- Least Privilege Security
Kubernetes
- Production Amazon EKS
- Kubernetes Administration
- Kubernetes Architecture
- Kubernetes Security
Tier 2 – Strongly Preferred
- AWS Organizations
- Multi-account Architecture
- Hybrid Connectivity
- VPN
- AWS Direct Connect
- Terraform
- Infrastructure as Code
- Helm
- GitOps
- Kubernetes RBAC
- Network Policies
- Multi-tenancy
- Container Security
- Zero Trust Architecture
- Cloud Governance
Tier 3 – Good to Have
- Bitbucket Pipelines
- Self-hosted Runners
- OIDC Authentication
- OpenTelemetry
- SigNoz
- Prometheus
- Grafana
- Route 53
- Amazon ECR
- AWS GuardDuty
- AWS CloudTrail
- AWS KMS
- AWS Secrets Manager
- Istio
- AWS App Mesh
Required Technical Skills
AWS
- AWS
- Amazon EKS
- AWS Organizations
- VPC
- Transit Gateway
- AWS PrivateLink
- Route 53
- IAM
- IRSA
- Amazon ECR
- AWS Lambda
- ALB
- NLB
- CloudTrail
- GuardDuty
- KMS
- Secrets Manager
- VPN
- Direct Connect
Kubernetes
- Amazon EKS
- Kubernetes
- Helm
- GitOps
- RBAC
- Network Policies
- Multi-tenancy
- Ingress Controllers
- Container Security
- Cluster Administration
DevOps & Platform Engineering
- Terraform
- Infrastructure as Code
- Docker
- Bitbucket Pipelines
- OIDC
- CI/CD
- Platform Automation
DevOps & Platform Engineering
- Terraform
- Infrastructure as Code
- Docker
- Bitbucket Pipelines
- OIDC
- CI/CD
- Platform Automation
Security
- Zero Trust
- IAM
- Kubernetes Security
- Cloud Security
- Governance
- Compliance
- Threat Modeling
Observability
- OpenTelemetry
- SigNoz
- Prometheus
- Grafana
- Logging
- Monitoring
- Metrics
- Distributed Tracing
Required Qualifications
- Bachelor's or Master's degree in Computer Science, Information Technology, or a related field.
- 10+ years of Infrastructure, Platform Engineering, or Cloud Engineering experience.
- 5+ years of hands-on AWS Architecture experience.
- 5+ years of production Kubernetes platform engineering experience.
- Strong expertise in enterprise cloud platform implementation.
- Hands-on experience with Terraform, AWS networking, Kubernetes, and security.
- Proven experience leading cloud modernization initiatives.
- Experience working closely with Infrastructure, Cyber Security, Networking, Operations, and Application Engineering teams.
- Strong troubleshooting and architectural decision-making skills.
- Excellent communication, documentation, and stakeholder management abilities.
- Ability to work independently in a globally distributed engineering environment.
- Must be available during U.S. East Coast business hours.
Preferred Certifications
- AWS Certified Solutions Architect – Professional
- Certified Kubernetes Administrator (CKA)
- Certified Kubernetes Security Specialist (CKS)
- HashiCorp Terraform Associate
Ideal Candidate
The ideal candidate is a Principal Cloud Platform Architect who combines strategic architecture expertise with strong hands-on implementation capabilities.
You should be comfortable moving seamlessly between:
- Enterprise Architecture
- Terraform Development
- Kubernetes Administration
- AWS Networking
- Cloud Security
- Platform Engineering
- Migration Planning
- Production Troubleshooting
- Technical Leadership
This role is best suited for professionals who enjoy designing and building cloud platforms rather than supporting existing DevOps pipelines.
Required Skills
AWSEKSKubernetesAWS OrganizationsVPCTransit GatewayPrivateLinkIAMIRSAECRLambdaALBNLBRoute53CloudTrailGuardDutyKMSSecrets ManagerTerraformDockerBitbucketCI/CDGitOpsHelmRBACNetworkPoliciesOpenTelemetrySigNozPrometheusGrafanaObservabilityZero TrustCloud SecurityInfrastructure ArchitectureAmazon EKSVPC ArchitectureAWS PrivateLinkRoute 53IAM & IRSAAmazon ECRAWS LambdaApplication Load Balancer (ALB)Network Load Balancer (NLB)