Cloud Platform Engineer (Agentic Ai) - Sevilla

Luxoft Spain
Sevilla, Spain
about 1 month ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
4 years minimum
Working hours
Regular working hours
Languages
English

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Amazon S3 Cloud Computing Security Cloud Engineering Computer Networks Continuous Integration Information Engineering Software Debugging DevOps Amazon DynamoDB
+25 more
Github Monitoring of Systems Identity and Access Management Modular Design OpenID Role-Based Access Control Prometheus Azure Machine Learning Load Balancing Cloud Platform System System Availability Grafana Amazon Virtual Private Cloud (VPC) Kubernetes Deployment Automation Machine Learning Operations Route53 Virtual Agents Opsworks Cloudwatch Terraform Webhooks Dynatrace AWS EKS Vulnerability Analysis

Job description

Project descriptionThe project is for one of the world’s famous science and technology companies in pharmaceutical industry, supporting initiatives in AWS, AI and data engineering, with plans to launch over 20 additional initiatives in the future.We are seeking a highly skilled Cloud Engineer to lead the infrastructure design, deployment, and operations of the AI agent orchestration platform on AWS.This role is responsible for building and managing a Kubernetes-native, enterprise-grade platform that supports scalable AI agent workloads across development, QA, and production environments.ResponsibilitiesAWS Infrastructure & ArchitectureDesign, provision, and manage AWS infrastructure using Terraform, aligned with the AWS Well-Architected FrameworkCore services include:Amazon EKSVPCIAMApplication Load Balancer (ALB)Route 53AWS Certificate Manager (ACM)Kubernetes (EKS) Platform OperationsOwn and operate EKS clusters end-to-end:Managed node group lifecycle managementKarpenter-based autoscalingCluster add-on lifecycle upgradesIRSA (IAM Roles for Service Accounts) configurationMulti-AZ high availability and resilienceCI/CD & GitOpsBuild and maintain automated deployment pipelines using:GitHub ActionsArgoCD (GitOps)Enable multi-environment deployments:Dev ? QA ? ProductionImplement release strategies:Blue/Green deploymentsCanary releasesSecurity & ComplianceIntegrate AWS-native security and governance controls:AWS WAFGuardDutySecurity HubKMS (encryption)Secrets ManagerExternal Secrets OperatorEnforce policy controls using:OPA / Kyverno (admission controllers)Observability & MonitoringImplement and manage observability stack:Amazon Managed PrometheusAmazon Managed GrafanaCloudWatch Container InsightsAWS X-Ray (distributed tracing)AI/ML IntegrationLeverage AWS AI/ML services to support agent orchestration:Amazon Bedrock (model inference, agent APIs)SageMaker (model hosting, endpoints)Comprehend (NLP, PII detection)Cost Optimization (FinOps)Implement cost-efficient architecture practices:Spot InstancesSavings PlansKarpenter bin-packing strategiesScheduled scale-to-zero for non-production environmentsPlatform & Engineering CollaborationPartner with platform and ML teams to:Onboard new AI agent workloadsIntegrate MCP servers and execution frameworksSupport extensibility of the agent ecosystemSkillsExperience & Certifications4+ years of hands-on AWS experienceAWS Certifications:Required: AWS Solutions Architect (Associate or Professional)Preferred: DevOps Engineer, Security Specialty Kubernetes & EKS ExpertiseStrong hands-on experience with:EKS cluster provisioning and operationsManaged node groups and KarpenterHelm chart managementKubernetes RBAC and network policies Infrastructure as Code (Terraform)Advanced Terraform capabilities:Modular designRemote state management (S3 + DynamoDB)Multi-environment configurationSecurity scanning (Checkov, tfsec) AWS Services ProficiencyDeep knowledge of:EKS, ECR, ALB, Route 53, ACMIAM, KMS, Secrets ManagerIAM Identity CenterCloudTrail, AWS ConfigGuardDuty, Security Hub, AWS WAF AI/ML ExposurePractical experience with:Amazon Bedrock (model invocation, agent APIs)SageMaker (model deployment and endpoints)Comprehend (NLP and PII detection) DevOps & IdentityExperience with:GitOps tools (ArgoCD or Flux)CI/CD pipelines for container workloadsOIDC federation:GitHub Actions ? AWSEKS OIDC provider integration Observability & DebuggingFamiliarity with:Prometheus, GrafanaOpenTelemetryAWS X-RayCloudWatch Logs Insights Kubernetes SecurityStrong understanding of:Pod Security StandardsNetwork PoliciesAdmission webhooksService account least-privilege principlesLanguagesEnglish: B2

Requirements

Experience & Certifications 4+ years of hands-on AWS experience AWS Certifications: Required: AWS Solutions Architect (Associate or Professional) Preferred: DevOps Engineer, Security Specialty Kubernetes & EKS Expertise Strong hands-on experience with: EKS cluster provisioning and operations Managed node groups and Karpenter Helm chart management Kubernetes RBAC and network policies Infrastructure as Code (Terraform) Advanced Terraform capabilities: Modular design Remote state management (S3 + DynamoDB) Multi-environment configuration Security scanning (Checkov, tfsec) AWS Services Proficiency Deep knowledge of: EKS, ECR, ALB, Route 53, ACM IAM, KMS, Secrets Manager IAM Identity Center CloudTrail, AWS Config GuardDuty, Security Hub, AWS WAF AI/ML Exposure Practical experience with: Amazon Bedrock (model invocation, agent APIs) SageMaker (model deployment and endpoints) Comprehend (NLP and PII detection) DevOps & Identity Experience with: GitOps tools (ArgoCD or Flux) CI/CD pipelines for container workloads OIDC federation: GitHub Actions ? AWS EKS OIDC provider integration Observability & Debugging Familiarity with: Prometheus, Grafana, Pod Security Standards Network Policies Admission webhooks Service account least-privilege principles Languages English: B2

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

4:21 min

Scaling operations using Azure AI Foundry tools

Maxim Salnikov Maxim Salnikov · World Congress 2025

2:52 min

Implementing IAM with Keycloak and OpenID Connect

Thomas Südbröcker · LIVE

Videos

See all

Related articles

See all