Senior Cloud Engineer

Illumination Works
United States
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Amazon Web Services Amazon S3 Cloud Engineering CompTIA Security+ DevOps Web Development Amazon DynamoDB Federated Identity Management Identity and Access Management Python (Programming Language) OAuth
+18 more
OpenID Public Key Infrastructure Security Assertion Markup Language (SAML) Amazon Simple Notification Service (SNS) Software Engineering YAML Data Logging State Machines AWS Lambda Amazon Virtual Private Cloud (VPC) Cloudformation Servicebus Event Driven Architecture Pytest Api Gateway Amazon Simple Queue Service (SQS) Dynatrace Serverless Computing

Job description

  • Design and implement serverless workloads on AWS using Lambda, API Gateway, EventBridge, SQS, SNS, Step Functions, DynamoDB, and S3.
  • Author and maintain CloudFormation (YAML) templates as the source of truth for infrastructure, including nested stacks, change sets, and drift detection.
  • Build and maintain CI/CD pipelines that lint, test, package, and deploy CloudFormation stacks and code across environments with defined promotion and rollback strategies.
  • Develop Python based Lambda functions, internal tooling, and automation with appropriate testing, logging, error handling, and dependency management.
  • Provide architecture guidance for distributed event-driven systems, including choreography vs. orchestration, idempotency, delivery semantics, dead-letter and replay strategies, and schema evolution.
  • Define event contracts and async integration patterns in partnership with application teams.
  • Implement observability across services: structured logging, distributed tracing (OpenTelemetry), metrics, and actionable alarms.
  • Participate in incident response and post-incident reviews and convert findings into automated guardrails and runbooks.
  • Conduct code and design reviews; mentor junior and mid-level engineers on serverless patterns, IaC standards, and operational practices.

Do you have what it takes? Are you driven to implement creative solutions that unravel complex and ever-changing challenges? We value passion, curiosity, and perseverance with an ability to communicate ideas and results to diverse audiences. We look for people who thrive in collaborative and independent assignments, have the aptitude to learn new data quickly, and who are willing to mentor junior team members.

Requirements

Do you have experience in YAML?, * 4+ years of professional cloud or software engineering experience, with 2+ years building production AWS serverless workloads.

  • Strong Python proficiency, including pytest, packaging, and async patterns.
  • Hands-on CloudFormation experience leveraging Stacks and StackSets.
  • Demonstrated experience designing and operating CI/CD pipelines that deploy infrastructure, application code, and provision managed services.
  • Working knowledge of event-driven architecture patterns and the trade-offs between EventBridge, SNS, SQS, and Kinesis.
  • Practical understanding of AWS IAM, VPC networking, KMS, and least-privilege design for serverless workloads.
  • Experience producing design documentation and driving technical decisions from ambiguous requirements.
  • Light web application development experience sufficient to build internal tools, admin UIs, or thin frontends that integrate with serverless APIs.
  • Must hold an active security clearance
  • CompTIA Security+ certification
  • Acceptable candidates must successfully pass a drug test and background screen

Preferred Skills:

  • AWS GovCloud experience and familiarity with FedRAMP, DoD IL4/IL5, or other regulated environments.
  • Experience designing and deploying agentic AI workloads on Amazon Bedrock, including Bedrock Agents, Knowledge Bases, and tool/function calling integrated with serverless backends (Lambda, Step Functions, EventBridge).
  • Strong background in secure authentication and authorization design with a least-privilege mindset, including PKI and mTLS, AWS IAM roles and policies, OAuth 2.0 flows, OIDC, JWT validation, and federated identity patterns (SAML, IAM Identity Center).
  • Performance and cost tuning for high throughput serverless workloads
  • Additional certifications such as AWS Certified Solutions Architect (Associate or Professional) or AWS Certified DevOps Engineer.
  • Experience contributing to internal developer platforms or shared tooling.

Benefits & conditions

Pulled from the full job description

  • 401(k)
  • Health insurance
  • Paid time off
  • Vision insurance
  • Dental insurance
  • Life insurance
  • Disability insurance, Why choose us? We invest in our employees in all aspects of their life and we value family. We offer market-competitive salary, a generous PTO package, and comprehensive medical, dental, vision and life insurance plans. We also offer 401K, short/long-term disability insurance, a fun and engaging culture, and training opportunities to keep you up to speed on the latest technologies.

About the company

At Illumination Works, we know data, and we should, we’ve been doing it since we started in 2006! We specialize in everything data from big data to data science, data engineering, software engineering, and cloud design. We are a trusted technology partner in user-centered digital transformation-delivering impactful business results to clients. We partner with customers to solve their unique technology and data challenges and stay on top of modern technologies and advancements leveraging our Innovation Lab. Check out our website to learn more at www.ilwllc.com.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:38 min

Managing and versioning system prompts as YAML files

Kevin Lewis Kevin Lewis +1 · WWC 2025

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

3:51 min

Retaining and cultivating internal serverless engineering talent

Nočnica Fee · LIVE

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · WWC 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

Videos

See all

Related articles

See all