> Markdown version of [/jobs/ext/3394922-senior-cloud-aws-infrastructure-engineer](https://www.wearedevelopers.com/jobs/ext/3394922-senior-cloud-aws-infrastructure-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cloud / AWS Infrastructure Engineer - **Company:** Reflex Media - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $130,000.0 - $180,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Amazon S3, Bash Shell, Software as a Service, Cloud Computing, Cloud Computing Security, Cloud Engineering, Databases, Continuous Integration, Relational Databases, Software Debugging, DevOps, Disaster Recovery, Domain Name System (DNS), Failover, Identity and Access Management, Python (Programming Language), PostgreSQL, MySQL, OpenID, Reliability Engineering, Prometheus, Security Assertion Markup Language (SAML), Security Information and Event Management, Management of Software Versions, Backup and Restore, Amazon ElastiCache, Grafana, Amazon Virtual Private Cloud (VPC), Backend, Build Management, Kubernetes, Information Technology, Cloudflare, AWS Fargate, Opsworks, Cloudwatch, Terraform, Access Keys - **Published:** September 21, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=901aac12afba9b93 ## About the Role * Five or more years building and operating production AWS infrastructure. * Strong Terraform in a team setting: module design and versioning, remote state, drift, and PR-based workflows. * Multi-account AWS Organizations or Control Tower experience, including SCPs and cross-account IAM. * Deep IAM: policy and trust-policy design, permission boundaries, and least privilege in practice. * Production container experience on ECS or Kubernetes, and managed relational databases. * Python or Bash for automation and tooling. * Experience migrating or consolidating legacy infrastructure without downtime, and the judgment to sequence that work safely. * Clear writing, and the judgment to weigh risk, cost, and delivery speed against each other. * Daily use of Claude, Claude Code, and Cowork in your engineering workflow., * AFT, Landing Zone Accelerator, or similar account-vending automation. * IAM Identity Center or SAML / OIDC federation with an external IdP. * Designing and testing cross-region DR against defined RPO and RTO targets. * Aurora operations at scale: replication topology, failover, and backup and restore. * Security Hub, GuardDuty, AWS Config, or SIEM-style CloudTrail analysis. EDR tooling such as CrowdStrike. * AWS Backup at organization scale, including cross-region and cross-account copy. * Cloudflare or a comparable CDN and WAF at the edge. * Data or AI workloads on AWS (Redshift, MWAA, Bedrock). * Working with distributed teams across time zones. * AWS certifications (Solutions Architect, SysOps, Security Specialty). * Bachelor's degree in Computer Science, Engineering, or a related field, or an equivalent operational track record. ## Description Seeking.com is the world's largest premium dating platform, founded and led by an MIT alumnus and headquartered in Las Vegas. We are hiring a Senior Cloud / AWS Infrastructure Engineer to build, operate, and secure the AWS environment that runs our products. The environment is AWS Organizations with Control Tower, accounts vended through Account Factory for Terraform, and governance applied through global and per-account customization layers. Infrastructure is Terraform, delivered through a versioned in-house module library. Workloads run across ECS Fargate, Aurora MySQL and PostgreSQL, ElastiCache, EFS, Lambda, OpenSearch, Redshift, MWAA, and Bedrock, with Cloudflare at the edge. Disaster recovery. We are building cross-region DR for a flagship platform, essentially from the ground up. Today the platform is regionally concentrated. You will define the DR plan against real RPO and RTO targets, design and build the replication and failover path, and prove it with real exercises. Security engineering. Identity hardening, replacing static credentials with federated and role-based access, extending preventive and detective controls, and turning findings into engineering fixes., * Senior Cloud or Platform Engineers at consumer subscription, marketplace, or SaaS companies who have run AWS Organizations at scale. * Site Reliability Engineers with a heavy IaC and security bias who have taken a regionally concentrated platform to cross-region DR. * DevOps Engineers from a Terraform-first shop who own module libraries other teams depend on. * Cloud Security Engineers who built the guardrails, the SCPs, and the federated access patterns their org runs on today. What You Will Do Cloud Architecture and Infrastructure as Code * Extend the Terraform module library and the AFT customization layers (VPC and IPAM allocation, private hosted zones, SSM access, backup vaults, account baselines) so new accounts land secure and consistent by default. * Design VPC architecture, cross-account networking, and shared services in a hub-and-spoke configuration model. * Migrate legacy brand infrastructure into the current account structure, state backend model, and module standards. Disaster Recovery * Design and build cross-region recovery for a flagship platform: Aurora replication topology, cross-region backup copy, S3 and EFS replication, container image distribution, DNS failover, and region-parity IaC. * Establish RPO and RTO targets with the business, map dependencies into recovery tiers, and define restoration order. * Standardize backup policy and retention across the estate, including organization-level backup policy and centralized vaults. * Run scheduled DR tests and game days, and write runbooks that make recovery repeatable by anyone on call. Security * Design least-privilege IAM policy and IAM Identity Center permission sets. Reduce standing access and direct assignments. * Replace long-lived IAM access keys with federated SSO, OIDC, and assumed-role access, including in CI/CD. * Author and maintain SCPs and organization controls, plus automated remediation where prevention is not possible. * Extend detective controls: AWS Config rules and conformance packs, Security Hub standards coverage, GuardDuty feature coverage, and consistent finding handling across regions. * Own secrets management on Secrets Manager and SSM Parameter Store, including rotation. * Support incident response and CloudTrail forensics, and convert findings into durable engineering fixes. Reliability and Automation * Operate core infrastructure: monitoring, alerting, AWS Backup, and patch and lifecycle management. * Improve our Prometheus, Grafana, and Alertmanager stack and its CloudWatch alarm coverage so real issues page quickly. * Debug production issues across compute, storage, networking, and databases. * Automate operational work in Python and Bash, and improve CI/CD for infrastructure. * Keep Control Tower and the landing zone current, and contribute to cost visibility and optimization. ## Related Videos - [Shifting Stress to Progress— Understanding DevOps to do DevOps Better](https://www.wearedevelopers.com/videos/268-shifting-stress-to-progress-understanding-devops-to-do-devops-better) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [MySQL Protocol Features You Should Be Aware Of](https://www.wearedevelopers.com/videos/100267-mysql-protocol-features-you-should-be-aware-of) - [Shipping Faster with Less: Render on Cloud Hosting, AI Workloads, and the Future of DevOps](https://www.wearedevelopers.com/videos/1894-shipping-faster-with-less-render-on-cloud-hosting-ai-workloads-and-the-future-of-devops) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)