AWS DevSecOps Cloud Lead

Cognizant Technology Solutions Corporation
Dallas, TX, United States
24 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Compensation
$114,000.0 - $128,000.0
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Amazon Elastic Compute Cloud Amazon S3 Audit Trail Cloud Computing Cloud Engineering Continuous Integration Software Design Patterns Monitoring of Systems Identity and Access Management Python (Programming Language) Key Management
+31 more
PCI Data Security Standards Release Management Cloud Services TypeScript Management of Software Versions Datadog AWS Cdk Data Logging Scripting Cloud Platform System DevOps Tools - Open-source System Availability Delivery Pipeline Grafana Software Security Kubernetes Helm Charts Amazon Virtual Private Cloud (VPC) Gitlab Containerization Gitlab-ci Kubernetes Deployment Automation Performance Monitor CIS Benchmarks Cloudwatch Terraform Splunk Dynatrace Devsecops Static Application Security Testing Dynamic Application Security Testing

Job description

We are seeking a highly skilled Cloud Architect / Cloud Lead with deep expertise in AWS, DevOps, and DevSecOps practices. This role will be responsible for designing, implementing, and optimizing scalable cloud infrastructure, CI/CD pipelines, and secure deployment frameworks. The ideal candidate will bring strong experience in GitLab, Terraform, AWS CDK, and container platforms, along with a solid understanding of security, compliance, and observability in enterprise environments., * Design and implement robust GitLab CI/CD pipelines using multi-stage YAML for build, testing, security scanning, and multi-environment deployments.

  • Configure and manage GitLab Runners (EC2/EKS-based autoscaling) with focus on scalability, performance, and security.
  • Optimize pipeline performance through parallel execution, caching, artifact reuse, and conditional workflows.
  • Implement automated release management including tagging, semantic versioning, rollback strategies, and audit traceability.

Cloud Infrastructure & Automation

  • Develop Infrastructure as Code (IaC) using Terraform and AWS CDK (TypeScript/Python) with modular and reusable design patterns.
  • Automate provisioning of AWS services such as VPC, IAM, EC2, ECS/EKS, Lambda, RDS, and S3 using parameterized templates.
  • Build and manage multi-account and multi-region AWS environments using CDK pipelines and GitLab integration.
  • Implement scalable and resilient deployment strategies including blue/green, canary, and rolling deployments.

Containerization & Platform Engineering

  • Automate deployment of applications to container platforms (ECS/EKS), including image build pipelines and runtime configuration.
  • Manage Kubernetes deployments using Helm charts and establish repeatable deployment standards.
  • Implement container lifecycle management and registry governance using GitLab Registry and Amazon ECR.

DevSecOps & Compliance

  • Integrate security controls within CI/CD pipelines including SAST, DAST, dependency scanning, container scanning, and secrets detection.
  • Enforce least-privilege access by designing IAM roles, policies, and cross-account access controls.
  • Implement secure configuration and secrets management using AWS Secrets Manager, SSM Parameter Store, and CI/CD variables.
  • Enable compliance reporting aligned to PCI DSS, SOC 2, GDPR, and CIS benchmarks.

Monitoring, Logging & Observability

  • Design and implement end-to-end observability frameworks using AWS CloudWatch (logs, metrics, alarms).
  • Integrate third-party monitoring tools such as Datadog, Dynatrace, Splunk, or Grafana.
  • Build centralized logging architecture with CloudWatch, CloudTrail, and S3 archival and retention policies.
  • Develop custom CloudWatch dashboards with dynamic filtering and service correlation views.
  • Configure advanced alerting mechanisms including composite alarms, anomaly detection, and threshold tuning.
  • Enable cross-account observability using AWS Organizations and centralized monitoring accounts.

Operational Excellence & Troubleshooting

  • Troubleshoot and resolve issues across CI/CD pipelines, infrastructure, networking, IAM, and runtime environments.
  • Perform drift detection and remediation in infrastructure and deployments.
  • Ensure high availability, scalability, and reliability of cloud environments through proactive monitoring and optimization.

Requirements

  • Extensive experience with AWS Cloud services (10+ years preferred)
  • Strong hands-on expertise in Terraform and AWS CDK
  • Experience with GitLab CI/CD and pipeline automation
  • Solid experience with container platforms (ECS/EKS, Kubernetes)
  • Proficiency in DevSecOps tools and security integration

Preferred Skills

  • Experience with multi-account AWS architecture and governance
  • Exposure to financial services regulatory environments
  • Strong scripting skills in Python or TypeScript
  • Experience with observability platforms (Datadog, Splunk, Dynatrace, Grafana)

Benefits & conditions

The annual salary for this position is between $114,000 to $128,000 depending on experience and other qualifications of the successful candidate., Benefits: Cognizant offers the following benefits for this position, subject to applicable eligibility requirements:

  • Medical/Dental/Vision/Life Insurance
  • Paid holidays plus Paid Time Off
  • 401(k) plan and contributions
  • Long-term/Short-term Disability
  • Paid Parental Leave
  • Employee Stock Purchase Plan

Work model:

At Cognizant, we strive to provide flexibility wherever possible, and we are here to support a healthy work-life balance though our various wellbeing programs. Based on this role’s business requirements, this is a hybrid role requiring 3 days a week at client site in Dallas, Texas, USA.

The working arrangements for this role are accurate as of the date of posting. This may change based on the project you’re engaged in, as well as business and client requirements. Rest assured; we will always be clear about role expectations.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:51 min

Audience questions on cloud security and operational capacity

Steffen Heilmann · WWC 2021

10:40 min

Visualizing Prometheus open metrics using custom Grafana dashboards

Stijn Polfliet · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

6:14 min

Structuring CI/CD pipelines with integrated security and quality checks

Christoph Ruggenthaler · LIVE

1:04 min

Visualizing Keycloak performance via standard Grafana troubleshooting dashboards

Alexander Schwartz Alexander Schwartz · WWC 2025

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

Videos

See all

Related articles

See all