
Infrastructure as Code Engineer
Posted Jul 24

Posted Jul 24
This is a fully remote position, open to applicants in United Kingdom.
• Conduct an audit of our current AWS environment, assessing the existing admin web application to determine what should be maintained, modified, or decommissioned as part of the target design.
• Create and implement a modular, reusable Terraform codebase that encompasses our core AWS infrastructure (compute, networking, storage, IAM, and managed services), moving away from manual/console-driven provisioning and addressing components of the existing admin tool that lack an adequate audit trail.
• Establish remote state management with locking (for instance, using S3 and DynamoDB) and encryption at rest, while defining access controls to ensure state files are neither stored locally nor committed to version control.
• Develop and integrate CI/CD pipelines that automatically plan, validate, and apply Terraform changes, including automated policy and security scanning (Checkov, tfsec) with every pull request.
• Set up version control workflows, module structure, and environment separation (dev/staging/prod and demo) to ensure every infrastructure change is peer-reviewed, logged, and attributable to an individual and a pull request.
• Incorporate our existing compliance requirements into reusable modules and pipeline checks: secure configuration and patch/update tracking related to Cyber Essentials Plus, access control and logging pertinent to ISO 27001, as well as change control and data handling discipline relevant to our Bacs Approved Bureau status.
• Coordinate the migration plan to ensure ISO 27001 certification remains secure, given that our audit is scheduled during this contract period. While you will not manage or liaise regarding the audit itself, the phasing, rollback approach, and documentation must consider the timeline.
• Design and create a capability for on-demand ephemeral environments: a fully isolated stack that a developer or QA engineer can instantiate as needed, perform comprehensive testing on, and automatically dismantle afterward.
• Ensure that any fixture or seed data utilized in ephemeral test environments is either synthetic or properly masked, avoiding the use of actual production data in compliance with BAB rules on customer data handling and verification.
• Document architectural decisions, runbooks, and module usage to ensure the environment remains maintainable post-engagement.
• Provide hands-on training and workshops for the internal CTO, DevOps, and infrastructure teams, collaborating with staff, including the lead DevOps engineer responsible for the current admin tool, on practical migration tasks.
• Outline a phased migration plan that transitions current infrastructure to code without service interruptions, prioritizing the highest risk manual and unaudited changes first.
• Prepare a transition and handoff plan along with knowledge transfer materials before the end of the contract, detailing what responsibilities the internal team will assume going forward.
• Proven experience with Terraform at an enterprise level: module design, state management, workspaces, and multi-environment patterns, beyond basic tutorial knowledge.
• In-depth understanding of AWS services: EC2, VPC, IAM, RDS/Aurora, ECS/EKS, Lambda, ELB, S3.
• Experience in constructing CI/CD pipelines for infrastructure using tools such as GitHub Actions, GitLab CI, Jenkins, or CircleCI.
• Familiarity with designing ephemeral/on-demand environments (stack creation and teardown triggered by PRs or jobs, database seeding from masked snapshots or synthetic fixtures, automated cost/resource cleanup).
• Proficiency in scripting using Python and/or Bash for automation and tooling integration.
• Knowledge of IaC security and compliance scanning tools (Checkov, tfsec, or similar) and secrets management practices.
• Experience embedding audit trails and change control evidence into infrastructure workflows, with the ability to concretely discuss how Terraform combined with CI/CD provides the traceability that unaudited admin scripts lack.
• Familiarity with UK compliance frameworks relevant to our operations: ISO 27001 controls (access control, logging, risk treatment), Cyber Essentials Plus control areas (secure configuration, patch management, access control), and Bacs Approved Bureau requirements concerning change control and data handling.
• Demonstrated capability in training, mentoring, or upskilling engineering teams; teaching proficiency is a mandatory requirement, not merely a desirable trait.
• Experience leading or contributing to a brownfield migration (transitioning existing manual/bespoke automation to IaC), including the discernment to assess and diplomatically integrate with tools already developed by internal staff.
• Strong documentation skills, as your deliverables are only as valuable as the team's ability to operate without you afterward.
• 25 days of annual leave plus an additional day for your birthday or significant celebration.
• Private Health Insurance.
• Life Assurance at 4x base salary.
• Enhanced company pension contribution.
• Personal Travel Insurance.
• Access to the Benefiz benefits platform and a variety of opt-in benefits.
• Electric/Hybrid Vehicle scheme and Cycle to Work scheme.
• 10-day rolling sick leave policy, including extended illness pay.
• Employee Assistance Program (EAP) and support from Mental Health First Aiders.
LiteLLM AI Gateway
Snowflake
RTX
C-MORE
Get handpicked remote jobs straight to your inbox weekly.