> Markdown version of [/jobs/ext/626161-senior-platform-engineer](https://www.wearedevelopers.com/jobs/ext/626161-senior-platform-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Platform Engineer - **Company:** TANGO ASSOC INC - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $140,000.0 - $175,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Amazon Elastic Compute Cloud, Microsoft Azure, Computer Networks, Databases, Continuous Delivery, Continuous Integration, DevOps, Github, Identity and Access Management, Python (Programming Language), Key Management, Role-Based Access Control, Reliability Engineering, Ansible, Prometheus, Datadog, Policy as Code, Autoscaling, Istio, Large Language Models, Grafana, Gitlab-ci, Kubernetes, Data Analytics, Hashicorp, Linkerd (Service Mesh), Machine Learning Operations, Cloud Migration, Terraform, Static Application Security Testing - **Published:** June 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=dc17eac11a96f0cf ## About the Role Do you have experience in Tooling?, If you have strong opinions about infrastructure-as-code, love building things other engineers depend on every day, and want genuine end-to-end ownership - this role is for you., * 5+ years in platform, infrastructure, or DevOps engineering with direct production ownership on AWS and/or Azure * IaC: Deep OpenTofu/Terraform proficiency: module authoring, state management, workspace strategy, remote backends, and CI/CD integration; Terramate a plus * Kubernetes: Strong Kubernetes operations: EKS and/or AKS cluster lifecycle, Helm, admission controllers, RBAC, network policies, and autoscaling * Observability & SRE: Hands-on observability experience with two or more of: Prometheus, Grafana, Loki, Tempo, Datadog, or OpenTelemetry - including SLI/SLO definition and alert engineering * CI/CD: CI/CD platform experience: GitHub Actions pipeline authoring, reusable workflow design, and container build/scan pipeline ownership * GitOps: GitOps: ArgoCD or Flux for Kubernetes continuous delivery; progressive delivery patterns (canary, blue-green) a strong plus * IDP: IDP experience: Backstage or equivalent developer portal, GitHub, scaffolding templates, service catalog design, or self-service provisioning tooling * Security: Security-first mindset: policy-as-code, IaC scanning, secrets management, container hardening, and shift- left security practices * Strong communication and documentation skills; comfortable presenting architecture decisions to engineering peers and leadership Nice to Have * SRE background: chaos engineering (AWS FIS, Chaos Monkey), error budget management, incident command, and capacity planning * Service mesh depth: Istio or Linkerd - mTLS, traffic management, and observability integration * FinOps tooling (Kubecost, CloudHealth) and reserved capacity planning experience * Familiarity with AI/ML infrastructure basics: LLM API integration or model serving, as the platform will need to support these workloads * Certifications: AWS Solutions Architect Associate/Professional, CKA/CKAD, Azure Administrator/Solutions Architect, HashiCorp Terraform Associate * Python or Go for platform tooling and CLI development ## Description We are building a platform engineering function from the ground up and this role is at the center of it. As a Senior Platform Engineer you will be a founding team member with a clear, three-part mission: fully rearchitect and codify our cloud estate on AWS and Azure, stand up a world-class SRE and observability practice, and build an Internal Developer Platform with golden paths that make shipping software fast, safe, and self-service. This is a high-ownership individual contributor role. You will work directly with the Platform Engineering Manager to translate strategy into production infrastructure, drive adoption across engineering teams, and set the technical bar for how the platform is built and operated., Cloud Modernization - Rearchitect & Codify * Migrate all existing AWS and Azure infrastructure to OpenTofu/Terraform and Ansible; establish module standards, remote state, and GitOps-based plan/apply pipelines - no unmanaged resources * Audit the cloud estate against the AWS and Azure Well-Architected Frameworks; produce a remediation backlog and drive it to completion across networking, IAM, landing zones, account structure, and cost governance * Implement policy-as-code (OPA/Conftest, AWS SCPs, Azure Policy) to enforce security, tagging, and compliance guardrails at the platform layer - governance embedded, not bolted on * Build and maintain reusable Terraform modules for compute (EKS, AKS, EC2), networking, storage, databases, and identity as shared building blocks for all engineering teams * Define FinOps standards: tagging taxonomy, cost allocation dashboards, rightsizing recommendations, and reserved capacity planning across both clouds SRE & Observability * Design and implement the full observability stack: metrics (Prometheus/Datadog), logs (Loki/OpenSearch), traces (Tempo/Datadog APM), and dashboards (Grafana) - instrumented end-to-end via OpenTelemetry * Define SLIs and SLOs for all platform shared services and critical applications; build error budget dashboards and burn-rate alerting - alert on symptoms, not raw metrics * Establish the SRE practice from scratch: incident runbooks, post-incident review templates, and at least one chaos engineering exercise (AWS FIS or equivalent) * Partner with engineering teams to instrument their services, define meaningful alerts, and build operational dashboards - reliability is a shared responsibility, not a platform team tax * Build capacity planning models for compute and storage so engineering leadership can make data-driven scaling decisions Internal Developer Platform & Golden Paths * Deploy and operate a developer portal (Backstage, GitHub or equivalent) as the single front door: service catalog, scaffolding templates, runbooks, API docs, and on-call ownership all in one place * Build and maintain golden paths for the highest-frequency developer workflows: new service creation, Kubernetes deployment, database provisioning, secrets management, and CI/CD pipeline setup - opinionated defaults with escape hatches for legitimate edge cases * Own the CI/CD platform layer: standardized pipeline templates (GitHub Actions, GitLab CI), reusable workflow libraries, container image build and scan pipelines, and environment promotion workflows with security scanning (SAST, Snyk) built in by default * Own Kubernetes platform operations: EKS and/or AKS cluster lifecycle, Helm chart standards, admission controllers, RBAC, network policies, and service mesh (Istio or Linkerd) * Build the self-service provisioning layer - Backstage scaffolder actions and Terraform automation so developers can provision approved resources without raising a ticket * Measure adoption and run regular feedback sessions with engineering teams; iterate on golden paths based on real friction, not assumptions Cross-Cutting Responsibilities * Partner with peer managers and teams to plan and support migration of existing workloads onto the platform; provide hands-on migration support, not just documentation * Embed security by default across all platform work: IaC scanning (Checkov, tfsec), secrets management (Vault, AWS Secrets Manager, Azure Key Vault), RBAC, and container image hardening * Write clear technical documentation, architecture decision records (ADRs), and runbooks; raise the documentation bar for the whole team * Mentor and support more junior platform engineers; contribute to architecture reviews and build-vs-buy decisions alongside the Platform Engineering Manager ## Related Videos - [Platform Engineering vs. DevOps Why not both?](https://www.wearedevelopers.com/videos/885-platform-engineering-vs-devops-why-not-both) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Find a Developer Job: 12 Best Job Sites For Developers](https://www.wearedevelopers.com/magazine/165-find-a-developer-job-12-best-job-sites-for-developers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers)