> Markdown version of [/jobs/ext/2421678-principal-platform-engineer](https://www.wearedevelopers.com/jobs/ext/2421678-principal-platform-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Platform Engineer - **Company:** Impruvon, Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $160,000.0 - $200,000.0 - **Contract:** Permanent contract - **Skills:** Flutter, Amazon Web Services, Code Review, Continuous Integration, DevOps, Github, Identity and Access Management, Key Management, Network Security, Ruby on Rails, Software Vulnerability Management, AWS Cdk, Pulumi, ReactJS, Technical Debt, Generative AI, Containerization, Kubernetes, Terraform, Software Version Control, Docker - **Published:** August 2, 2026 - **Apply:** https://impruvon.pinpointhq.com/en/postings/8b4e6d2b-397d-4add-b9f1-a5f637975284 ## About the Role * AWS Infrastructure Ownership: 7+ years of experience owning production AWS infrastructure, including direct, hands-on experience with multi-account AWS Organizations (SCPs, consolidated billing, cross-account IAM). * Infrastructure as Code: Deep hands-on experience with AWS CDK, or comparable IaC tooling (Terraform, Pulumi) with a demonstrated ability to ramp quickly. You treat infrastructure as software: code review, testing, version control. * CI/CD: Proven experience designing, operating, and improving CI/CD pipelines; direct experience with GitHub Actions strongly preferred. * Containerization & Orchestration: Strong production experience with containers and a container orchestration platform (ECS or EKS/Kubernetes). * Security & Compliance: Direct experience operating infrastructure under HIPAA and/or SOC 2 Type II. * Autonomy: A track record of owning ambiguous, high-stakes infrastructure and security problems end-to-end with minimal supervision in fast-paced startup environments where requirements evolve. You will be responsible for maturing and evolving our playbook. * Communication: Excellent written and verbal communication skills. In a remote-first company, your ability to communicate asynchronously and document infrastructure decisions and compliance controls clearly enough for both engineers and auditors to follow is critical. * Technical Leverage: Demonstrated ability to write tools or infrastructure patterns that amplify the productivity of the rest of the engineering team, rather than just solving problems for yourself. Nice to Have * AWS Certified Solutions Architect - Professional * AWS Certified Security - Specialty * AWS Certified Generative AI Developer - Professional * Experience in healthcare, fintech, or another highly regulated industry. * Experience with StateRAMP or FedRAMP. * Familiarity with Ruby on Rails, React, and Flutter (useful for cross-team collaboration). * Experience with IoT or hardware-connected systems. ## Description Lead ownership and maturation of a multi-account AWS platform: extend IaC (AWS CDK), improve CI/CD (GitHub Actions), drive container strategy (ECS/EKS, Docker), elevate security and compliance (HIPAA, SOC 2), mentor engineers, and deliver reliable, scalable infrastructure for a regulated healthcare-connected product. The summary above was generated by AI Impruvon builds software and connected hardware that transforms how care teams manage medications for vulnerable populations. Our platform replaces manual, error-prone workflows with real-time, guided systems that improve safety, reduce risk, and simplify compliance across residential care settings. We support providers across 20+ states, including intellectual and developmental disabilities (IDD) providers, assisted living operators, and behavioral health programs. Our platform includes a full electronic Medication Administration Record (eMAR) and administrative dashboard, smart connected MedBoxes that control and track medication access, emergency kits for urgent situations, and tools that help residents build independence with self-medication. Our solution has been proven to reduce medication errors by approximately 48%, directly impacting the safety of individuals in care facilities. We are a high-growth, mission-driven startup solving complex, high-impact problems where reliability, usability, and security matter., We are hiring a Principal Platform Engineer to take ownership of our existing platform infrastructure. Today, our engineering leadership manages AWS, DevOps, and compliance. You will be the primary technical lead for this domain. We are looking for someone who can mature our practices, optimize our workflows, and scale our infrastructure. While you will partner with engineering leadership on strategy, you will be the primary authority on technical implementation. We seek a self-starter who thrives when given a high-level outcome and the freedom to define the technical path to get there. You will own our AWS footprint end-to-end: a multi-account AWS Organizations setup (currently 3 accounts), our Infrastructure-as-Code repo (AWS CDK), CI/CD (GitHub Actions), containerization and orchestration (ECS, considering EKS), and our developer environment tooling (docker compose, devcontainers, mise). You will be responsible for elevating our security and compliance posture - HIPAA, SOC 2 Type II, and likely upcoming work toward StateRAMP or FedRAMP. Most of this foundation already exists. This is not a "build it from zero" role - it's a "take a working but under-resourced platform and bring it to the next level" role. We are looking for an experienced engineer who can quickly assess our environment, identify opportunities for improvement, and drive solutions with a high degree of agency. If you thrive in high-growth, mission-driven environments and are eager to tackle complex engineering challenges while maintaining a high technical bar, this role is for you. Key Responsibilities * Own and evolve our AWS environment across a multi-account AWS Organization structure, including account boundaries, service control policies, cross-account IAM, and cost and security governance. * Extend and maintain our Infrastructure-as-Code repo (AWS CDK), treating infrastructure changes with the same rigor as application code - reviewed, tested, and versioned. * Own and improve CI/CD pipelines in GitHub Actions, pushing toward faster, safer, more automated deployments across applications. * Own our containerization strategy (Docker) and container orchestration platform (currently ECS, potentially moving to EKS) - image standards, base image and dependency security, and day-to-day orchestration operations. * Maintain and improve our devcontainer setup so engineers get consistent reproducible local development environments. * Lead the technical work to elevate our compliance and security posture - maintaining and evolving controls for HIPAA and SOC 2 Type II, and leading the technical requirements for StateRAMP/FedRAMP readiness. * Lead infrastructure-focused security work: secrets management, network security, vulnerability management, and incident response readiness. * Partner with engineering leadership to evolve our platform strategy and formalize our infrastructure practices as we scale. * Proactively identify risk in our infrastructure and compliance posture - cost, security, reliability, audit gaps - and drive fixes to completion without being asked. * Elevate our engineering culture by setting high standards, mentoring other engineers, and simplifying processes to help the team move faster as we scale. * Prioritize pragmatic simplicity, ensuring we build only what is necessary to validate assumptions and deliver value, while resisting complexity that hinders agility. * Ensure the reliability and performance of our critical systems by taking ownership of production issues and implementing sustainable fixes. Skills, Knowledge and Experience, * First 30 Days: Audit the current infrastructure to identify top technical debt and compliance risks. Ship your first impactful changes to production while establishing strong working relationships with the engineering team. * First 60 Days: Take primary ownership of our AWS environment. Begin driving our infrastructure roadmap forward by proactively implementing improvements. * First 90 Days: Operate with full autonomy as the technical authority for the platform. Propose and begin implementing a roadmap for one major initiative (e.g., EKS migration) without needing guidance on implementation details. ## Related Videos - [Platform Engineering vs. DevOps Why not both?](https://www.wearedevelopers.com/videos/885-platform-engineering-vs-devops-why-not-both) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Why segmenting your infrastructure into tiers makes your infrastructure design better](https://www.wearedevelopers.com/videos/1960-why-segmenting-your-infrastructure-into-tiers-makes-your-infrastructure-design-better) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Unleashing Potential Across Teams: The Power of Infrastructure as Code](https://www.wearedevelopers.com/videos/930-unleashing-potential-across-teams-the-power-of-infrastructure-as-code) - [Empowering Thousands of Developers: Our Journey to an Internal Developer Platform](https://www.wearedevelopers.com/videos/1519-empowering-thousands-of-developers-our-journey-to-an-internal-developer-platform) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)