New

Senior Cloud Infrastructure Engineer

Brazil

 

 

Senior Cloud Infrasructure Engineer

Who We Are

At Platform Science, we’re working to connect everything that moves.

Founded in 2015, Platform Science is an open IoT platform partnering with innovative fleets, application developers, vehicle manufacturers, and equipment providers across the transportation industry. Our technology helps deliver modern solutions to supply chain professionals around the world.

Our employees bring diverse backgrounds, experiences, and perspectives. We believe great ideas can come from anywhere, and we foster a culture built around innovation, collaboration, empathy, resilience, and transparency.

About the Role

Platform Science is looking for a Senior Cloud Infrastructure Engineer  to join our CloudOps team.

CloudOps owns the foundational cloud infrastructure that enables our engineering teams to build, deploy, and operate products at scale. The team manages identity, networking, governance, security guardrails, backup, disaster recovery, and shared cloud services across a multi-account AWS environment spanning hundreds of accounts and multiple business units. We are also extending this operating model across Azure and GCP.

This is a hands-on senior individual contributor role for an engineer who enjoys building foundational infrastructure and solving complex cloud problems. You will own infrastructure and platform capabilities end to end, work primarily through Infrastructure as Code, and create guardrails and self-service capabilities that allow engineering teams to move quickly without sacrificing security or reliability.

The scope is intentionally broad. You may work on cloud identity and permissions, private networking, multi-cloud governance, backup and disaster recovery, security remediation, or developer self-service capabilities.

AI-assisted engineering is also part of how the team operates. We use AI coding agents to accelerate implementation and automation while maintaining rigorous engineering review, security, and production standards.

What You’ll Do

  • Own and evolve our multi-account AWS Landing Zone, including AWS Organizations, Control Tower, Account Factory for Terraform (AFT), organizational structures, Service Control Policies, tagging standards, and permission boundaries.

  • Extend cloud governance, operational standards, security controls, observability, and backup capabilities across AWS, Azure, and GCP.

  • Improve cloud identity and access management using least-privilege principles, including Okta federation, AWS IAM Identity Center, permission sets, group design, credential management, and reduction of standing privileged access.

  • Design and operate cloud networking capabilities, including IP address management, VPC architecture, routing, transit connectivity, Cloud WAN, egress architecture, and public/private DNS.

  • Help transition workloads from public-internet exposure to private and zero-trust networking models, including Kubernetes control planes, databases, and internal platforms.

  • Build self-service infrastructure capabilities for engineering teams, including account provisioning, environment provisioning, access requests, account lifecycle management, and infrastructure inventory.

  • Design and maintain backup, restore, and disaster recovery capabilities across cloud regions, accounts, and business units with different recovery requirements.

  • Implement immutable and ransomware-resistant backup strategies for cloud-native and managed third-party data platforms.

  • Build reusable Terraform/Terragrunt modules and infrastructure patterns that can be safely consumed by engineering teams across the organization.

  • Develop and maintain CI/CD automation for cloud infrastructure.

  • Partner with Security teams to investigate and remediate cloud security findings.

  • Partner with FinOps teams to identify cloud cost optimization opportunities that can be implemented broadly across the organization.

  • Build and maintain documentation, cloud standards, operating procedures, and shared responsibility models.

  • Use AI coding agents as part of the engineering workflow while maintaining ownership for requirements, architecture, testing, security, code review, and production outcomes.

  • Develop reusable prompts, context, workflows, and agent capabilities that improve the CloudOps team's productivity.

Required Experience

 

  • 7–10+ years of professional experience in Cloud Infrastructure, DevOps, Site Reliability Engineering, Platform Engineering, Systems Engineering, or a related infrastructure discipline.

  • 4–5+ years of hands-on experience with AWS or another major public cloud, with significant AWS experience strongly preferred.

  • 3+ years of Infrastructure as Code experience, preferably using Terraform and/or Terragrunt.

  • Experience operating AWS at organizational scale, including AWS Organizations, multi-account architecture, and Control Tower or a comparable landing-zone architecture.

  • Production experience with at least one additional major cloud platform — Azure or GCP — beyond managing a single workload.

  • Strong experience designing reusable Infrastructure as Code modules and patterns consumed by other engineering teams.

  • Hands-on experience with cloud identity and access management, including SSO, SAML federation, SCIM provisioning, IAM policies, roles, permission boundaries, and least-privilege access models.

  • Strong cloud networking fundamentals, including IP address planning, VPC/VNet design, routing, transit architectures, DNS, private connectivity, and network security.

  • Experience designing or maintaining CI/CD pipelines using tools such as GitHub Actions, Jenkins, or similar technologies.

  • Experience scripting or programming with Python, Go, Bash, or similar languages.

  • Strong Linux fundamentals.

  • Working knowledge of Kubernetes and cloud-native infrastructure.

  • Experience using AI coding agents or AI-assisted development tools such as Claude Code, Cursor, Codex, or similar tools. Candidates should understand how to define requirements, establish success criteria, validate generated code, and identify situations where AI-generated infrastructure may introduce security or operational risk.

  • Ability to independently own complex infrastructure projects from design through production implementation.

  • Strong written and verbal communication skills with the ability to collaborate across Engineering, Security, FinOps, and other technical teams.

  • Advanced English proficiency.

  • Bachelor’s degree in Computer Science, Software Engineering, Information Technology, or a related technical field.

  • Must reside in Brazil.

Preferred Qualifications

Experience with one or more of the following is highly desirable:

  • AWS Control Tower and Account Factory for Terraform (AFT)

  • AWS IPAM, Transit Gateway, or Cloud WAN

  • Multi-cloud governance across AWS, Azure, and/or GCP

  • Cross-account immutable backup and ransomware protection

  • MongoDB Atlas, Elastic Cloud, or similar managed data platforms

  • Wiz, GuardDuty, CrowdStrike, or other cloud security posture/security platforms

  • Zero-trust networking technologies such as Zscaler ZPA

  • Cloudflare WAF and DNS

  • Certificate and PKI lifecycle management using ACM, Private CA, cert-manager, or Let’s Encrypt

  • Agentic automation pipelines or automated remediation workflows

  • MCP servers or reusable AI agent skills

  • Secure access patterns and permission boundaries for AI-driven automation

  • Cloud cost optimization and FinOps

  • SOC 2 or comparable security/compliance frameworks

  • GitHub organization administration, including teams, apps, rulesets, and Actions runners

  • AWS, Azure, GCP, Terraform, Kubernetes, or related technical certifications

What Success Looks Like at the IC4 / P4 Level

A successful Senior Cloud Infrastructure Engineer at this level is expected to:

  • Independently own complex infrastructure projects.

  • Make sound technical decisions within established architectural direction.

  • Identify infrastructure risks and propose practical solutions.

  • Build reusable systems rather than one-off fixes.

  • Reduce operational work through automation and self-service.

  • Apply security and least-privilege principles by default.

  • Work effectively across multiple cloud environments.

  • Review infrastructure changes with strong technical judgment.

  • Partner effectively with senior engineers and cross-functional stakeholders.

  • Mentor and influence other engineers through technical expertise without requiring formal people-management responsibility.

  • This is a senior individual contributor position and does not require direct people management.

 

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Platform Science’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 07/31/2029

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.