
Infrastructure Cloud Engineer
Posted 4 days ago

Posted 4 days ago
This is a fully remote position, open to applicants in Pakistan.
• Design and execute landing zones in Azure and AWS, incorporating hub-and-spoke architectures and policy guardrails.
• Develop and sustain Terraform modules, workspaces, remote state, and automated environment provisioning from development to production.
• Manage and secure AKS/EKS clusters, focusing on node pools, autoscaling, ingress, image scanning/signing, and zero-downtime upgrades.
• Create and optimize CI/CD pipelines using GitHub Actions, Azure DevOps, and Jenkins for building, testing, scanning, deploying, and gated promotions.
• Facilitate application platforms such as API Management/API Gateway, Azure Functions/AWS Lambda, and messaging services like Service Bus, SNS/SQS, and EventBridge.
• Oversee observability through Azure Monitor, Log Analytics, App Insights, CloudWatch, X-Ray, and OpenTelemetry, including alerts, runbooks, SLIs/SLOs, and on-call duties.
• Promote FinOps practices, including tagging, cost allocation, rightsizing, reserved instances/savings plans, egress optimization, and Well-Architected reviews.
• Integrate logs and telemetry while onboarding data sources with the SIEM.
• Establish and uphold security guardrails utilizing Azure Policy, AWS Config, Defender for Cloud, Security Hub, GuardDuty, and WAF policies.
• Implement least-privilege access across Entra ID and AWS IAM/Identity Center, including workload identity federation for CI/CD processes.
• Administer change control and audit processes through IaC-first workflows, runbooks, and architectural decision records.
• Ensure patch and version management for Kubernetes, node OS/AMIs, container images, and managed services, including automated drift detection.
• Lead investigations into Azure/AWS incidents, conduct root-cause analysis, and enforce preventative measures.
• Provide architectural insights regarding security, reliability, networking, and cost-effectiveness during design evaluations.
• Bachelor's degree in IT, Computer Science, or a related field.
• At least 5 years of relevant experience.
• Practical production experience with both Azure and AWS platforms.
• Extensive knowledge of Terraform (modules, workspaces, state, policy as code).
• Strong operational expertise in Kubernetes (AKS/EKS), including Helm, ingress controllers, ACR/ECR.
• Solid understanding of networking fundamentals: VNet/VPC, routing, VPNs, Private Link/Endpoints, ExpressRoute/Direct Connect, load balancers, WAF, DNS.
• Proficient in identity & access management: Entra ID and AWS IAM, SSO/OIDC, and secrets management (Key Vault/KMS).
• Experience implementing CI/CD with GitHub Actions, Azure DevOps, or Jenkins; focusing on security gates and artifact repositories.
• Familiarity with observability/SRE practices across metrics, logs, tracing, alerting, incident response, and post-mortems.
• Strong scripting skills (PowerShell, Bash) and OS-level knowledge across Linux/Windows.
• Experience with disaster recovery patterns (IaC rebuilds), high availability architectures, and RTO/RPO planning.
• Desirable: Knowledge of M365 Conditional Access (global policies, break-glass, step-up).
• Desirable: Familiarity with AWS landing zone tooling (Control Tower, IAM Identity Center, account vending/guardrails).
• Desirable: Ability to read and maintain CloudFormation or Bicep where Terraform is the primary tool.
• Desirable: Experience in web hosting: CDN/WAF (Front Door/CloudFront), TLS/PKI, caching, performance optimization.
• Desirable: Understanding of data fundamentals: S3/Blob lifecycle, RDS/Aurora/SQL MI/Postgres, Redis/ElastiCache/Azure Cache.
• Desirable: Knowledge of Kubernetes and supply-chain security: admission controls, image signing, SBOM.
• Preferred certifications: Azure AZ-104, AZ-305, AZ-500; AWS Solutions Architect – Associate; CKA; Terraform Associate.
• Preferred or bonus certifications: AZ-700, AZ-400, AWS SA-Pro, AWS DevOps Pro, AWS Security, AWS Advanced Networking, CKS, FinOps Certified Practitioner.
• Competitive salary and performance-based bonuses.
• Comprehensive health, dental, and vision insurance.
• Flexible working hours and remote work options.
• Opportunities for professional development and continued education.
• Supportive work environment that encourages innovation and collaboration.
Strategic Communications
Bright Vision Technologies
Get handpicked remote jobs straight to your inbox weekly.