> Markdown version of [/jobs/ext/1405513-principal-cloud-infrastructure-engineer-aws](https://www.wearedevelopers.com/jobs/ext/1405513-principal-cloud-infrastructure-engineer-aws). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Cloud Infrastructure Engineer (AWS) - **Company:** CVS Health - **Location:** United States - **Experience:** Expert - **Salary:** $144,200.0 - $288,400.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Amazon Elastic Compute Cloud, Amazon S3, Cloud Computing, Cloud Engineering, DevOps, Amazon DynamoDB, Github, Identity and Access Management, Virtual Private Networks (VPN), Python (Programming Language), PCI Data Security Standards, Cloud Services, Security Information and Event Management, Datadog, Policy as Code, Autoscaling, Delivery Pipeline, Multi-Cloud, Infrastructure as Code (IaC), Amazon Virtual Private Cloud (VPC), Cloudformation, Information Technology, Deployment Automation, AWS Glue, AWS Fargate, Enterprise Integration, Opsworks, Cloudwatch, Amazon Simple Queue Service (SQS), Terraform, Prisma Cloud Platform, Pagerduty, Amazon Redshift, Golang - **Published:** July 23, 2026 - **Apply:** https://www.juju.com/job/00000000gisyhh ## About the Role + 10+ years in cloud and infrastructure engineering with 5+ years of deep, hands-on AWS experience at enterprise scale. + Proven ownership of an AWS Organization - account hierarchy, Billing, Service Control Policies, IAM, and multi-account governance in production. + Demonstrated technical leadership: you have led a platform team or major enterprise cloud initiative, set technical direction, and grown engineers around you. Deep AWS** **expertise** **required** **across: Compute & Containers: EKS (Managed + Auto Mode), ECS/Fargate, EC2, Auto Scaling Groups Networking: VPC, VPC Lattice, AWS PrivateLink, Transit Gateway, AWS WAF, Shield Advanced, Direct Connect Data & Messaging: Amazon Redshift, SNS/SQS, S3, AWS Glue, Kinesis, Amazon MWAA Security: IAM, IRSA, AWS Security Hub, ECR Image Signing, Secrets Manager, VPC Endpoints IaC & Automation: Terraform (modules, remote state, OPA), AWS CodePipeline, AWS Config, CloudFormation Observability: Amazon CloudWatch, AWS X-Ray, Datadog, SLO/SLI design, PagerDuty integration Languages: Python, Go, and Terraform Preferred Qualifications + AWS Certified Solutions Architect - Professional (strongly preferred) + AWS Certified DevOps Engineer - Professional + HashiCorpTerraform Associate or Professional certification + Experience in regulated industries applying HIPAA, PCI-DSS, or FedRAMP controls on AWS + Familiarity with AWS Outposts, EKS Anywhere, and multi-cloud connectivity patterns + Experience with Amazon Bedrock, SageMaker, andMLOpspatterns on AWS, Bachelor's degree in Computer Science, Engineering, or a related field - or equivalent demonstrated experience. ## Description We are looking for a Principal Engineer to lead our AWS Cloud Engineering team, owning the Amazon Web Services platform for the enterprise. This is a foundational platform role - you are the AWS technical authority, setting architectural direction, establishing engineering standards, and ensuring the platform is secure, scalable, and built to last. You lead from the front. You design the systems others build on, mentor the engineers around you, and hold the line on quality and best practices. You bring deep AWS expertise, a platform-owner mindset, and the leadership presence to align engineers and stakeholders around a shared technical vision. This role demands a _cloud-first thinker_ who ensures cloud solutions meet business needs efficiently while prioritizing Infrastructure as Code (IaC) to create repeatable, automated deployments. You need to have a proven track record of _architecting cloud environments from scratch_ . You'll drive cloud transformation initiatives across all CSP's with a focus on AWS platforms while ensuring every design decision considers security, reliability, and scalability. This is not a hands-off leadership role - you write code, review designs, and stay close to the work. Major Responsibilities 1. AWS Platform Ownership + Own the enterprise AWS platform end-to-end: AWS Organizations structure, account hierarchy, while collaborating with several teams to ensure the platform is stable and compliant. + Define andmaintainthe AWS Landing Zone - AWS Control Tower, Service Control Policies (SCPs), billing controls, and account vending patterns - as the foundation all product teams build on. + Serve as the final technical authority on AWS architecture decisions, reviewing designs for scalability, security, and operational excellence before they reach production. + Build self-service platform capabilities that enable product engineering teams to move fast without compromising standards. 2. Technical Team Leadership + Lead the AWS cloud engineering team as the technical anchor - set direction, conduct design reviews, unblock engineers, and drive delivery on platform initiatives. + Establish and enforce engineering standards:IaCpatterns, naming conventions, tagging strategy, branching models, and deployment practices. + Mentor engineers at all levels, building depth on the team and raising the bar on what "excellence" looks like in cloud engineering. + Partner with architecture, security, operations, and business stakeholders to translate enterprise requirements into platform capabilities. 3. Infrastructure as Code & Automation + Design and own the Terraformframeworkfor all AWS resource provisioning - reusable modules, remote state management via S3/DynamoDB, pipeline integration, and policy guardrails. + Build and maintain CI/CD pipelines using AWSCodePipeline,CodeBuild, GitHub Actions, and Amazon ECR for both platform infrastructure and application teams. + Write production-quality automation to extend platform functionality, integrate AWS APIs, andeliminateoperational toil. + Implement policy-as-code using OPA, AWS Config Rules, and Service Control Policies to enforce governance at scale without manual gatekeeping. 4. Networking, Security & Compliance + Architect andoperateAWS networking: VPC design, VPC Lattice, AWSPrivateLink, Transit Gateway, AWS WAF, Shield Advanced, NAT Gateway, and hybrid connectivity via AWS Direct Connect and Site-to-Site VPN. + Own the enterprise security posture on AWS - IAM Roles for Service Accounts (IRSA), ECR Image Signing, AWS Secrets Manager, least-privilege IAM design, and SIEM/CSPM integration (AWS Security Hub, Prisma Cloud, or Wiz). + Drive continuous automated compliance across applicable regulatory frameworks (HIPAA, PCI, SOC 2)socontrols are enforced in real time, not discovered at audit. + Integrate observability - Amazon CloudWatch, AWS X-Ray, Datadog, and SLO/SLI frameworks - as a first-classplatformcapability across all workloads. 5. Platform Strategy & Continuous Improvement + Own the AWS platform roadmap, evaluating new AWS services and capabilities and making deliberate decisions about what the enterprise adopts and when. + Incorporate FinOps practices across the platform: Reserved Instances, Savings Plans,rightsizing, AWS Budgets alerting, and cost allocation as engineering disciplines, not afterthoughts. + Research and pilot emerging AWS capabilities - Amazon Bedrock, EKS Auto Mode, Amazon Q for Developer - evaluating their fit for enterprise adoption. + Foster a culture of operational excellence: blameless postmortems, runbook-driven operations, and continuous improvement cycles that make the platform more reliable over time. ## Related Videos - [30 powerful AWS hacks in just 30 minutes: Boost your developer productivity](https://www.wearedevelopers.com/videos/1624-30-powerful-aws-hacks-in-just-30-minutes-boost-your-developer-productivity) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [#90DaysOfDevOps - The DevOps Learning Journey](https://www.wearedevelopers.com/videos/548-90daysofdevops-the-devops-learning-journey) - [Retooling and refactoring - an investment in people.](https://www.wearedevelopers.com/videos/371-retooling-and-refactoring-an-investment-in-people) ## Related Articles - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [From Prototype to Production: Build AI Agents with This Free 4-Course Learning Path](https://www.wearedevelopers.com/magazine/655-from-prototype-to-production-build-ai-agents-with-this-free-4-course-learning-path) - [Top Must-Visit Developer Conferences in the US in 2026](https://www.wearedevelopers.com/magazine/679-top-must-visit-developer-conferences-in-the-us-in-2026)