Cloud Architect [Remote]

Luxoft Spain
Zaragoza, Spain
4 days ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
4 years minimum
Working hours
Regular working hours
Languages
English

Tech stack

Kubernetes Security Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Amazon S3 Cloud Computing Cloud Computing Security Computer Programming Computer Networks Continuous Integration Information Engineering Software Debugging
+28 more
DevOps Amazon DynamoDB Github Monitoring of Systems Identity and Access Management Python (Programming Language) Modular Design Node.Js OpenID Role-Based Access Control Reliability Engineering Prometheus Azure Machine Learning Load Balancing System Availability Grafana Amazon Virtual Private Cloud (VPC) Kubernetes Deployment Automation Machine Learning Operations Route53 Virtual Agents Opsworks Cloudwatch Terraform Webhooks Dynatrace Vulnerability Analysis

Job description

Descripción del trabajoProject descriptionThe project is for one of the world’s famous science and technology companies in pharmaceutical industry, supporting initiatives in AWS, AI and data engineering, with plans to launch over 20 additional initiatives in the future.ResponsibilitiesAWS Infrastructure & Architecture.Design, provision, and manage AWS infrastructure using Terraform, aligned with the AWS Well-Architected Framework.Core services include:Amazon EKSVPCIAMApplication Load Balancer (ALB)Route 53AWS Certificate Manager (ACM)Kubernetes (EKS) Platform OperationsOwn and operate EKS clusters end-to-endManaged node group lifecycle management:Karpenter-based autoscalingCluster add-on lifecycle upgradesIRSA (IAM Roles for Service Accounts) configurationMulti-AZ high availability and resilienceCI/CD & GitOpsBuild and maintain automated deployment pipelines using:GitHub ActionsArgoCD (GitOps)Enable multi-environment deployments:Dev ? QA ? ProductionImplement release strategies:Blue/Green deploymentsCanary releasesSecurity & ComplianceIntegrate AWS-native security and governance controls:AWS WAFGuardDutySecurity HubKMS (encryption)Secrets ManagerExternal Secrets OperatorEnforce policy controls using:OPA / Kyverno (admission controllers)Observability & MonitoringImplement and manage observability stack:Amazon Managed PrometheusAmazon Managed GrafanaCloudWatch Container InsightsAWS X-Ray (distributed tracing)AI/ML IntegrationLeverage AWS AI/ML services to support agent orchestration:Amazon Bedrock (model inference, agent APIs)SageMaker (model hosting, endpoints)Comprehend (NLP, PII detection)Cost Optimization (FinOps)Implement cost-efficient architecture practices:Spot InstancesSavings PlansKarpenter bin-packing strategiesScheduled scale-to-zero for non-production environmentsPlatform & Engineering CollaborationPartner with platform and ML teams to:Onboard new AI agent workloadsIntegrate MCP servers and execution frameworksSupport extensibility of the agent ecosystemSkillsMust have~4+ years of hands-on AWS experience~ AWS Certifications:~ Required: AWS Solutions Architect (Associate or Professional)~ Preferred: DevOps Engineer, Security Specialty~ Kubernetes & EKS Expertise~ Strong hands-on experience with:~ EKS cluster provisioning and operations~ Managed node groups and Karpenter~ Helm chart management~ Kubernetes RBAC and network policies~ Infrastructure as Code (Terraform)~ Advanced Terraform capabilities:~ Modular design~ Remote state management (S3 + DynamoDB)~ Multi-environment configuration~ Security scanning (Checkov, tfsec) AWS Services Proficiency~ Deep knowledge of:~ EKS, ECR, ALB, Route 53, ACM~ IAM, KMS, Secrets Manager~ IAM Identity Center~ CloudTrail, AWS Config~ GuardDuty, Security Hub, AWS WAF AI/ML Exposure~ Practical experience with:~ Amazon Bedrock (model invocation, agent APIs)~ SageMaker (model deployment and endpoints)~ Comprehend (NLP and PII detection)~ DevOps & Identity~ Experience with:~ GitOps tools (ArgoCD or Flux)~ CI/CD pipelines for container workloads~ OIDC federation:~ GitHub Actions ? AWS~ EKS OIDC provider integration~ Observability & Debugging~ Familiarity with:~ Prometheus, Grafana~ OpenTelemetry~ AWS X-Ray~ CloudWatch Logs Insights~ Kubernetes Security~ Strong understanding of:~ Pod Security Standards~ Network Policies~ Admission webhooks~ Service account least-privilege principlesNice to haveExperience with AI agent frameworks:LangChain, Claude Agent SDK, or similarKnowledge of emerging protocols:A2A (Agent-to-Agent)MCP (Model Context Protocol)Familiarity with:Amazon Bedrock Agents, Knowledge Bases, GuardrailsChaos engineering exposure:AWS Fault Injection Service (FIS)Multi-tenant platform design:Namespace isolationSelf-service provisioningProgramming/debugging skills:Python, Go, or Node.jsFinOps experience:AWS Cost ExplorerCompute OptimizerTagging governanceSavings Plan managementLanguagesEnglish: B2#J-*****-Ljbffr

Requirements

Must have ~4+ years of hands-on AWS experience ~ AWS Certifications: ~ Required: AWS Solutions Architect (Associate or Professional) ~ Preferred: DevOps Engineer, Security Specialty ~ Kubernetes & EKS Expertise ~ Strong hands-on experience with: ~ EKS cluster provisioning and operations ~ Managed node groups and Karpenter ~ Helm chart management ~ Kubernetes RBAC and network policies ~ Infrastructure as Code (Terraform) ~ Advanced Terraform capabilities: ~ Modular design ~ Remote state management (S3 + DynamoDB) ~ Multi-environment configuration ~ Security scanning (Checkov, tfsec) AWS Services Proficiency ~ Deep knowledge of: ~ EKS, ECR, ALB, Route 53, ACM ~ IAM, KMS, Secrets Manager ~ IAM Identity Center ~ CloudTrail, AWS Config ~ GuardDuty, Security Hub, AWS WAF AI/ML Exposure ~ Practical experience with: ~ Amazon Bedrock (model invocation, agent APIs) ~ SageMaker (model deployment and endpoints) ~ Comprehend (NLP and PII detection) ~ DevOps & Identity ~ Experience with: ~ GitOps tools (ArgoCD or Flux) ~ CI/CD pipelines for container workloads ~ OIDC federation: ~ GitHub Actions ? AWS ~ EKS OIDC provider integration ~ Observability & Debugging ~ Familiarity with: ~ Prometheus, Grafana ~ OpenTelemetry ~ AWS X-Ray ~ CloudWatch Logs Insights ~ Kubernetes Security ~ Strong understanding of: ~ Pod Security Standards ~ Network Policies ~ Admission webhooks ~ Service account least-privilege principles Nice to have Experience with AI agent frameworks: LangChain, Claude Agent SDK, or similar Knowledge of emerging protocols: A2A (Agent-to-Agent) MCP (Model Context Protocol) Familiarity with: Amazon Bedrock Agents, Knowledge Bases, Guardrails Chaos engineering exposure: AWS Fault Injection Service (FIS) Multi-tenant platform design: Namespace isolation Self-service provisioning Programming/debugging skills: Python, Go, or Node.js FinOps experience: AWS Cost Explorer Compute Optimizer Tagging governance Savings Plan management Languages English: B2 #J-*****-Ljbffr

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:24 min

Evaluating formal AWS certifications versus raw practical engineering experience

Jan Giacomelli · LIVE

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

6:13 min

Defining cloud proficiency by technical role

Piet Van Dongen · LIVE

2:52 min

Implementing IAM with Keycloak and OpenID Connect

Thomas Südbröcker · LIVE

Videos

See all

Related articles

See all