
Infrastructure as Code Engineer
Posted Jul 24

Posted Jul 24
This is a fully remote position, open to applicants in United Kingdom.
• Conduct an audit of our current AWS environment, which includes the existing admin web application, to evaluate what should be maintained, modified, or decommissioned as part of the target architecture.
• Create and implement a modular, reusable Terraform codebase for our fundamental AWS infrastructure (covering compute, networking, storage, IAM, and managed services) to replace manual/console-driven provisioning and aspects of the existing admin tool lacking a proper audit trail.
• Establish remote state management with locking (such as S3 and DynamoDB) and encryption at rest, while defining access controls to ensure state files are neither stored locally nor committed to version control.
• Develop and integrate CI/CD pipelines that automatically plan, validate, and apply Terraform changes, including automated policy and security scanning (Checkov, tfsec) on every pull request.
• Create version control workflows, module structures, and environment separations (development/staging/production and demo) to ensure that every infrastructure change undergoes peer review, is logged, and is attributable to an individual and a pull request.
• Incorporate our existing compliance obligations into reusable modules and pipeline checks: secure configuration and patch/update tracking relevant to Cyber Essentials Plus, access control and logging pertinent to ISO 27001, and change control and data handling discipline relevant to our Bacs Approved Bureau status.
• Sequence the migration plan to avoid jeopardizing ISO 27001 certification, considering that our audit falls within this contract period. While you won't manage or communicate regarding the audit itself, the phasing, rollback strategies, and documentation must be cognizant of that timeline.
• Design and construct an on-demand ephemeral environment capability: a complete, isolated stack that a developer or QA engineer can initiate as needed, execute a full test cycle against, and subsequently dismantle automatically.
• Ensure that any fixture or seed data used in ephemeral test environments is synthetic or properly masked, avoiding the use of production data in compliance with BAB regulations on customer data handling and verification.
• Document architectural decisions, runbooks, and module usage to ensure the environment remains maintainable after the engagement concludes.
• Provide hands-on training and workshops for the internal CTO, DevOps, and infrastructure teams, collaborating with staff, including the lead DevOps engineer who developed the current admin tool, on actual migration tasks.
• Outline a phased migration plan that transitions existing infrastructure to code without service interruption, prioritizing the highest-risk manual and unaudited changes first.
• Generate a transition and handoff plan along with knowledge transfer materials ahead of the contract's conclusion, specifying what responsibilities will be retained by the internal team moving forward.
• Proven hands-on experience with Terraform at an enterprise level: module design, state management, workspaces, and multi-environment patterns, beyond just tutorial-level knowledge.
• Extensive working knowledge of AWS services: EC2, VPC, IAM, RDS/Aurora, ECS/EKS, Lambda, ELB, S3.
• Experience in constructing CI/CD pipelines for infrastructure (using GitHub Actions, GitLab CI, Jenkins, or CircleCI).
• Familiarity with designing ephemeral/on-demand environments (including PR- or job-triggered stack creation and teardown, database seeding from masked snapshots or synthetic fixtures, and automated cost/resource cleanup).
• Proficient scripting skills in Python and/or Bash for automation and tooling integration.
• Experience with IaC security and compliance scanning tools (such as Checkov, tfsec, or similar) and secrets management.
• Experience in embedding audit trails and change control evidence into infrastructure workflows, with the ability to articulate how Terraform combined with CI/CD provides the traceability that an unaudited admin script cannot offer.
• Familiarity with UK compliance standards relevant to our requirements: ISO 27001 controls (access control, logging, risk treatment), Cyber Essentials Plus control areas (secure configuration, patch management, access control), and Bacs Approved Bureau criteria regarding change control and data handling.
• Demonstrated experience in training, mentoring, or upskilling engineering teams; teaching capability is a crucial requirement.
• Experience leading or contributing to a brownfield migration (transitioning existing manual/bespoke automation to IaC), with the discernment to assess and diplomatically integrate with tools already developed by internal staff.
• Excellent written documentation skills, as the value of your contributions is directly tied to how effectively the team can operate without your ongoing involvement.
• 25 days of annual leave plus an additional day for your birthday or significant celebration.
• Private Health Insurance.
• Life Assurance at four times the base salary.
• Enhanced company pension contribution.
• Personal Travel Insurance.
• Access to the Benefiz benefits platform and a variety of opt-in benefits.
• Electric/Hybrid Vehicle scheme and Cycle to Work scheme.
• 10-day rolling sick plan, including extended illness pay.
• Employee Assistance Program (EAP) and support from Mental Health First Aiders.
LiteLLM AI Gateway
Snowflake
RTX
C-MORE
Get handpicked remote jobs straight to your inbox weekly.