> Markdown version of [/jobs/ext/2906891-cloud-architect-remote](https://www.wearedevelopers.com/jobs/ext/2906891-cloud-architect-remote). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud Architect [Remote] - **Company:** Luxoft Spain - **Location:** Illes Balears, Spain - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Amazon S3, Cloud Computing, Cloud Computing Security, Cloud Engineering, Computer Programming, Computer Networks, Continuous Integration, Information Engineering, Software Debugging, DevOps, Amazon DynamoDB, Github, Monitoring of Systems, Identity and Access Management, Python (Programming Language), Modular Design, Node.Js, OpenID, Role-Based Access Control, Reliability Engineering, Prometheus, Azure Machine Learning, Load Balancing, System Availability, Grafana, Amazon Virtual Private Cloud (VPC), Kubernetes, Deployment Automation, Machine Learning Operations, Route53, Virtual Agents, Opsworks, Cloudwatch, Terraform, Webhooks, Dynatrace, AWS EKS, Vulnerability Analysis - **Published:** September 14, 2026 - **Apply:** https://www.buscojobs.com.es/cloud-architect-remote-en-ibiza-ID-370975797 ## About the Role Core services include: Amazon EKS VPC IAM Application Load Balancer (ALB) Route 53 AWS Certificate Manager (ACM) Kubernetes (EKS) Platform Operations Own and operate EKS clusters end-to-end Managed node group lifecycle management: Karpenter-based autoscaling Cluster add-on lifecycle upgrades IRSA (IAM Roles for Service Accounts) configuration Multi-AZ high availability and resilience CI/CD & GitOps Build and maintain automated deployment pipelines using: GitHub Actions ArgoCD (GitOps) Enable multi-environment deployments: Dev ? QA ? Production Implement release strategies: Blue/Green deployments Canary releases Security & Compliance Integrate AWS-native security and governance controls: AWS WAF GuardDuty Security Hub KMS (encryption) Secrets Manager External Secrets Operator Enforce policy controls using: OPA / Kyverno (admission controllers) Observability & Monitoring Implement and manage observability stack: Amazon Managed Prometheus Amazon Managed Grafana CloudWatch Container Insights AWS X-Ray (distributed tracing) AI/ML Integration Leverage AWS AI/ML services to support agent orchestration: Amazon Bedrock (model inference, agent APIs) SageMaker (model hosting, endpoints) Comprehend (NLP, PII detection) Cost Optimization (FinOps) Implement cost-efficient architecture practices: Spot Instances Savings Plans Karpenter bin-packing strategies Scheduled scale-to-zero for non-production environments Platform & Engineering Collaboration Partner with platform and ML teams to: Onboard new AI agent workloads Integrate MCP servers and execution frameworks Support extensibility of the agent ecosystem Skills Must have 4+ years of hands-on AWS experience AWS Certifications: Required: AWS Solutions Architect (Associate or Professional) Preferred: DevOps Engineer, Security Specialty Kubernetes & EKS Expertise Strong hands-on experience with: EKS cluster provisioning and operations Managed node groups and Karpenter Helm chart management Kubernetes RBAC and network policies Infrastructure as Code (Terraform) Advanced Terraform capabilities: Modular design Remote state management (S3 + DynamoDB) Multi-environment configuration Security scanning (Checkov, tfsec) AWS Services Proficiency Deep knowledge of: EKS, ECR, ALB, Route 53, ACM IAM, KMS, Secrets Manager IAM Identity Center CloudTrail, AWS Config GuardDuty, Security Hub, AWS WAF AI/ML Exposure Practical experience with: Amazon Bedrock (model invocation, agent APIs) SageMaker (model deployment and endpoints) Comprehend (NLP and PII detection) DevOps & Identity Experience with: GitOps tools (ArgoCD or Flux) CI/CD pipelines for container workloads OIDC federation: GitHub Actions ? AWS EKS OIDC provider integration Observability & Debugging Familiarity with: Prometheus, Grafana OpenTelemetry AWS X-Ray CloudWatch Logs Insights Kubernetes Security Strong understanding of: Pod Security Standards Network Policies Admission webhooks Service account least-privilege principles Nice to have Experience with AI agent frameworks: LangChain, Claude Agent SDK, or similar Knowledge of emerging protocols: A2A (Agent-to-Agent) MCP (Model Context Protocol) Familiarity with: Amazon Bedrock Agents, Knowledge Bases, Guardrails Chaos engineering exposure: AWS Fault Injection Service (FIS) Multi-tenant platform design: Namespace isolation Self-service provisioning Programming/debugging skills: Python, Go, or Node.js FinOps experience: AWS Cost Explorer Compute Optimizer Tagging governance Savings Plan management Languages English: B2 ## Description Project description The project is for one of the world's famous science and technology companies in pharmaceutical industry, supporting initiatives in AWS, AI and data engineering, with plans to launch over 20 additional initiatives in the future.We are seeking a highly skilled Cloud Engineer to lead the infrastructure design, deployment, and operations of the AI agent orchestration platform on AWS.This role is responsible for building and managing a Kubernetes-native, enterprise-grade platform that supports scalable AI agent workloads across development, QA, and production environments.Responsibilities AWS Infrastructure & Architecture.Design, provision, and manage AWS infrastructure using Terraform, aligned with the AWS Well-Architected Framework.Core services include: Amazon EKS VPC IAM Application Load Balancer (ALB) Route 53 AWS Certificate Manager (ACM) Kubernetes (EKS) Platform Operations Own and operate EKS clusters end-to-end Managed node group lifecycle management: Karpenter-based autoscaling Cluster add-on lifecycle upgrades IRSA (IAM Roles for Service Accounts) configuration Multi-AZ high availability and resilience CI/CD & GitOps Build and maintain automated deployment pipelines using: GitHub Actions ArgoCD (GitOps) Enable multi-environment deployments: Dev ? QA ? Production Implement release strategies: Blue/Green deployments Canary releases Security & Compliance Integrate AWS-native security and governance controls: AWS WAF GuardDuty Security Hub KMS (encryption) Secrets Manager External Secrets Operator Enforce policy controls using: OPA / Kyverno (admission controllers) Observability & Monitoring Implement and manage observability stack: Amazon Managed Prometheus Amazon Managed Grafana CloudWatch Container Insights AWS X-Ray (distributed tracing) AI/ML Integration Leverage AWS AI/ML services to support agent orchestration: Amazon Bedrock (model inference, agent APIs) SageMaker (model hosting, endpoints) Comprehend (NLP, PII detection) Cost Optimization (FinOps) Implement cost-efficient architecture practices: Spot Instances Savings Plans Karpenter bin-packing strategies Scheduled scale-to-zero for non-production environments Platform & Engineering Collaboration Partner with platform and ML teams to: Onboard new AI agent workloads Integrate MCP servers and execution frameworks Support extensibility of the agent ecosystem Skills Must have 4+ years of hands-on AWS experience AWS Certifications: Required: AWS Solutions Architect (Associate or Professional) Preferred: DevOps Engineer, Security Specialty Kubernetes & EKS Expertise Strong hands-on experience with: EKS cluster provisioning and operations Managed node groups and Karpenter Helm chart management Kubernetes RBAC and network policies Infrastructure as Code (Terraform) Advanced Terraform capabilities: Modular design Remote state management (S3 + DynamoDB) Multi-environment configuration Security scanning (Checkov, tfsec) AWS Services Proficiency Deep knowledge of: EKS, ECR, ALB, Route 53, ACM IAM, KMS, Secrets Manager IAM Identity Center CloudTrail, AWS Config GuardDuty, Security Hub, AWS WAF AI/ML Exposure Practical experience with: Amazon Bedrock (model invocation, agent APIs) SageMaker (model deployment and endpoints) Comprehend (NLP and PII detection) DevOps & Identity Experience with: GitOps tools (ArgoCD or Flux) CI/CD pipelines for container workloads OIDC federation: GitHub Actions ? AWS EKS OIDC provider integration Observability & Debugging Familiarity with: Prometheus, Grafana OpenTelemetry AWS X-Ray CloudWatch Logs Insights Kubernetes Security Strong understanding of: Pod Security Standards Network Policies Admission webhooks Service account least-privilege principles Nice to have Experience with AI agent frameworks: LangChain, Claude Agent SDK, or similar Knowledge of emerging protocols: A2A (Agent-to-Agent) MCP (Model Context Protocol) Familiarity with: Amazon Bedrock Agents, Knowledge Bases, Guardrails Chaos engineering exposure: AWS Fault Injection Service (FIS) Multi-tenant platform design: Namespace isolation Self-service provisioning Programming/debugging skills: Python, Go, or Node.js FinOps experience: AWS Cost Explorer Compute Optimizer Tagging governance Savings Plan management Languages English: B2 ## Related Videos - [Remote Driving on Plant Grounds with State-of-the-Art Cloud Technologies](https://www.wearedevelopers.com/videos/251-remote-driving-on-plant-grounds-with-state-of-the-art-cloud-technologies) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [CI/CD with Github Actions](https://www.wearedevelopers.com/videos/856-ci-cd-with-github-actions) - [Shipping Faster with Less: Render on Cloud Hosting, AI Workloads, and the Future of DevOps](https://www.wearedevelopers.com/videos/1894-shipping-faster-with-less-render-on-cloud-hosting-ai-workloads-and-the-future-of-devops) ## Related Articles - [From Prototype to Production: Build AI Agents with This Free 4-Course Learning Path](https://www.wearedevelopers.com/magazine/655-from-prototype-to-production-build-ai-agents-with-this-free-4-course-learning-path) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany)