About Hupo
We are an AI-native start-up building sales enablement products in the banking, financial services, and insurance industry; already trusted by
dozens of enterprise customers (including Fortune 500 companies).
Role at a Glance
Title: Sr. DevOps / Cloud Engineer
Team: Engineering
Employment Type: Full-time
Location: Remote (APAC)
Why This Role Matters
We need a
Sr.DevOps / Cloud Engineer to own our AWS and Azure environments, our multi-tenant deployment architecture, and our IaC CI/CD platform. You'll be a key technical voice on infrastructure decisions and will work directly with enterprise clients on security and integration requirements.
What You'll Do
- Own and evolve Hupo's AWS infrastructure — ECS Fargate, VPCs, IAM, RDS, PrivateLink, API Gateway, and more
- Design and enforce AWS account organisation strategy — multi-account structures, AWS Organizations, SCPs, and landing zone patterns
- Build and maintain multi-tenant deployment pipelines using a TACOS system (Terraform Automation and Collaboration), with per-client workspace and state isolation
- Lead AWS networking design — VPC architecture, Transit Gateway, PrivateLink, NLB, and Private API Gateway for enterprise client integrations
- Drive security and compliance posture for BFSI clients — SOC 2, ISO 27001, and enterprise security due diligence
- Design and operate IAM Identity Center, cross-account role strategies, and external ID patterns for customer-deployed stacks
- Manage GitHub Actions workflows for CI/CD across multiple environments and services
- Lead infrastructure design decisions and produce ADRs, runbooks, and documentation
- Mentor mid and junior engineers on the team
What Success Looks Like
Within your first few months, you'll:
- Take ownership of Hupo's cloud infrastructure across AWS and Azure, and become the go-to person for infrastructure architecture and operational decisions.
- Design and implement scalable, secure, multi-tenant deployment patterns and CI/CD workflows that support our growing enterprise customer base.
- Partner directly with enterprise customers and internal teams to deliver secure integrations, networking solutions, and compliance requirements for BFSI environments.
You'll also be expected to continuously:
- Drive improvements in reliability, security, developer experience, and operational excellence across our infrastructure platform.
- Document decisions, share knowledge, and raise the technical bar across the engineering team.
What We're Looking For
Must-Haves
- 5+ years in a DevOps / Cloud / Platform Engineering role
- Deep AWS expertise — multi-account architecture, VPC networking, IAM, ECS, Terraform
- AWS account organisation — AWS Organizations, SCPs, Control Tower, or equivalent landing zone patterns
- Advanced networking — Transit Gateway, PrivateLink, VPC Endpoint Services, NLB, Route 53 private zones
- IaC orchestration (TACOS) — Spacelift, Terraform Cloud, Atlantis, or similar
- Strong GitHub Actions CI/CD design and troubleshooting
- Security engineering — IAM policies, least-privilege, audit trails, secrets management
- Comfortable working async across time zones
Nice-to-Haves
- Azure alongside AWS (AKS, Entra ID, Azure networking)
- Experience with enterprise BFSI security reviews or SOC 2 / ISO 27001 audits
- Google Workspace + IAM Identity Center integration (SCIM / ssosync)
- SaaS / AI product infrastructure background
- FastAPI, Python, or Node.js service ownership
- Cloudflare DNS management alongside Route 53