Remote DevOps Engineer (Pulumi)
Role details
Job location
Tech stack
Job description
We're looking for a senior DevOps/platform engineer to accelerate and modernize how we ship infrastructure. Today our infrastructure-as-code runs on Pulumi (TypeScript) across a multi-account AWS estate, with promotion still largely manual. We're moving to a true trunk-based CI/CD model: developers
work in short-lived branches, every merge to
master automatically deploys to production, and each merge request gets its own ephemeral preview environment before it lands. This person will lead that migration hands-on.
This is a hands-on engineering role, not an advisory one. The right candidate has deep Pulumi and TypeScript experience, strong AWS fundamentals, and a track record of building production CI/CD pipelines at scale.
Day to Day:
Modernize the deployment pipeline. Move build-and-deploy from clickops
to full automated CI/CD, adding pre-merge checks (lint, unit tests, SAST, feature-flag validation) in GitLab CI.
- Build a reusable pipeline platform. Partner with the DevOps team to design a GitLab CI setup that combines Pulumi with complementary components
into a reusable foundation - so onboarding a new service or project becomes a single, repeatable invocation rather than bespoke wiring each
time.
-
Establish true CI/CD patterns. Branch-driven automated deploys, immutable SHA-keyed artifacts, ECS rolling deployments with automatic rollback, and ephemeral per-MR environments (Pulumi Review Stacks).
-
Support diverse deployment targets. ECS Fargate services and scheduled tasks, Lambda (zip and container), API Gateway, ALB+Lambda, CloudFront/S3 static and Next.js sites, Step Functions, and data-plane infrastructure.
Requirements
5+ years in DevOps, platform, or cloud infrastructure engineering
-
Hands-on Pulumi experience building and operating production infrastructure (component resources, stack config, multi-stack/multi-account patterns)
-
Strong TypeScript - this is the language our IaC is written in today
-
Deep AWS experience across compute and deployment services: ECS/Fargate, Lambda, API Gateway, IAM, ECR, S3, CloudFront
-
Proven experience designing and shipping CI/CD pipelines (build, artifact management, automated deploy, rollback)
-
Solid grasp of secure deployment practices: OIDC-based cloud auth, crossaccount IAM roles, secrets management, least-privilege access
-
Comfortable owning a migration end-to-end, from design through team-by team rollout