(Senior) Cloud Infrastructure Engineer - AWS · GCP · Azure

Shine
Amsterdam, Netherlands
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Amazon Elastic Compute Cloud Amazon S3 Microsoft Azure Cloud Computing Cloud Computing Security Databases Domain Name System (DNS) Github Monitoring of Systems Identity and Access Management Virtual Private Networks (VPN)
+28 more
SQL Azure Networking Basics Routing OpenID PCI Data Security Standards Peering Reliability Engineering Newrelic Prometheus Single Sign-On SQL Databases Datadog Data Logging Transport Layer Security Load Balancing Okta Cloud Monitoring Grafana Firewalls (Computer Science) Amazon Virtual Private Cloud (VPC) Event Driven Architecture Kubernetes Cloudflare AWS Fargate Route53 Cloudwatch Terraform Docker

Job description

We’re looking for a Senior Site Reliability / Cloud Infrastructure Engineer to join our Infrastructure team. This is a long-term position to replace a recent departure and strengthen our capacity as we scale.

You’ll play a crucial role in maintaining and improving the reliability, security, and scalability of our cloud infrastructure. By taking ownership of critical infrastructure tasks, you’ll help redistribute workload across the team and free your teammates to focus on strategic initiatives.

You are an expert in at least one of these three clouds: AWS, GCP or Azure, paired with the fundamentals that transfer across all of them., * Maintain & improve reliability - ensure availability, scalability, and performance of infrastructure and services across our multi-cloud estate.

  • Automation & Infrastructure as Code - build and maintain infra with Terraform/Terragrunt; automate repetitive operational work.
  • Observability & monitoring - define SLOs/SLIs and maintain monitoring, logging, and alerting (Prometheus, Grafana, Datadog).
  • Security & compliance - apply cloud security best practices and support audits and regulatory compliance (ACPR, PCI-DSS, GDPR, DORA).
  • Networking & connectivity - operate and improve enterprise-grade networking and connectivity across cloud providers.
  • Collaboration & knowledge sharing - act as a bridge between Infrastructure and Product/Engineering teams, document infra, and mentor peers.

Future opportunities

  • Lead reliability efforts for core business services.
  • Contribute to long-term architecture and multi-cloud strategy.
  • Optimize cloud costs and resource usage (FinOps).
  • Grow into leadership by mentoring junior engineers or leading sub-projects., + AWS (EC2, ECS, EKS, Fargate, Lambda, RDS/Aurora, S3, VPC, Transit Gateway, Route 53)
  • GCP (Cloud Run, GCE, Cloud SQL, VPC)
  • Azure (AKS, Container Apps, VMs, Functions, Azure SQL, VNet)
  • IaC & automation: Terraform / Terragrunt, GitHub Actions, OIDC
  • Containers & orchestration: Docker, Kubernetes (EKS/GKE/AKS), ECS/Fargate
  • Observability: Prometheus, Grafana, Datadog, NewRelic, native cloud monitoring (AWS CloudWatch, GCP Cloud Monitoring, Azure Monitor)
  • Networking: VPC/VNet, Transit Gateway / peering / VPN, DNS, TLS/mTLS, load balancing, Cloudflare
  • Security & IAM: least-privilege design, IAM Identity Center / SSO, Okta, Security Hub / GuardDuty / Config and equivalents
  • Data: SQL databases and event-driven systems, * A 45’ interview with the Hiring Manager to discuss your past experience and the role.
  • A technical discussion / hands-on business case with team members to highlight your skills and give you a feel for the work.
  • A team introduction and personality assessment, with feedback, to see how we can best support your growth.
  • Final alignment & offer.

Requirements

Do you have experience in VPN?, Must-haves

  • 5+ years of relevant experience (Senior level)
  • Strong English communication
  • Terraform expertise
  • Hands-on experience with AWS and/or GCP and/or Azure at scale
  • Solid networking fundamentals (DNS, TLS/mTLS, firewalls, routing, load balancing)
  • Monitoring & observability tooling (Prometheus, Grafana, Datadog, etc.)
  • Cloud and system security best practices
  • Knowledge of SQL databases and event-driven systems

Nice-to-haves

  • Cloudflare
  • Identity & Access Management (Okta)
  • Docker & Kubernetes
  • CI/CD pipelines (GitHub Actions)
  • Experience supporting audits / regulated environments (PCI-DSS, ACPR, ISO 27001, DORA)
  • FinOps / cost optimization fundamentals

Soft skills

  • Problem-solving mindset
  • Strong collaboration & communication
  • Adaptability & proactivity
  • Continuous-improvement drive

What success looks like

  • 3 months - fully onboarded and autonomous in day-to-day infra; delivered documentation updates and proposed improvements.
  • 6 months - owns a domain; contributed to a critical project; led a small internal improvement initiative.
  • 12 months - recognized as the go-to expert in a major infra domain; mentored junior teammates; shaped the roadmap.

About the company

Shine is the financial copilot for entrepreneurs and small business owners. Founded by serial entrepreneurs Rico Andersen and Martin Hegelund, Shine is a leading European fintech on a mission to restore the joy of running a business by ending wasted time on financial admin - offering a connected solution for invoicing, accounting, payroll, business accounts, payments, and financing.

Today we’re part of Cegid, a European leader in cloud software for finance and accounting. Together we serve over one million small businesses and 15,000 accountants across Europe, working from France, Germany, Denmark and the Netherlands, within a wider network spanning Spain, Portugal and Belgium.

Just as we respect our customers’ time, we respect yours. Your hiring experience with Shine and Cegid should feel simple, transparent and genuinely supportive.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:46 min

Navigating a career in cloud transformation consulting

Piet Van Dongen · LIVE

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · WWC 2025

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

2:52 min

Implementing IAM with Keycloak and OpenID Connect

Thomas Südbröcker · LIVE

2:34 min

Docker sandbox architecture and microVM environment integration

Manuel de la Peña Manuel de la Peña · WWC Europe 2026

Videos

See all

Related articles

See all