JDS Advisory LLP
Website:
jdsadvisoryllp.com
Job details:
About the Role
We're looking for a Senior Cloud Infrastructure Engineer to own and evolve our Infrastructure-as-Code
platform. Our infrastructure runs entirely on AWS, managed through a Terragrunt + Terraform
module/config pattern across multiple environments (dev, QA, staging, sandbox, production). You'll build
reusable modules, harden security and compliance, and keep our multi-environment deployments reliable,
repeatable, and auditable.
What You'll Do
- Design and maintain reusable Terraform modules and environment-specific Terragrunt configurations using a module + config pattern.
- Manage AWS infrastructure across multiple isolated environments, each with an independent remote state (S3 backend + DynamoDB locking).
- Own core AWS services: VPC networking (multi-AZ), EKS, EC2, RDS (SQL Server & PostgreSQL), Lambda, SQS/SNS/EventBridge, CloudFront, WAF, Route53, Amplify, FSx, and KMS.
- Build and maintain EKS clusters (node groups, cluster autoscaler, IRSA roles for Ingress Controller, Cert Manager, EBS CSI, ArgoCD).
- Implement and enforce security and compliance: WAF rules (including AWS Managed Rules / Bot Control), IAM least-privilege roles, ACM certificates, Secrets Manager, and secure secret injection via environment variables.
- Maintain observability tooling: CloudWatch alarms, CloudTrail, Grafana dashboards and alert rules, and Route53 health checks.
- Run and improve CI/CD security pipelines (GitHub Actions) with TFLint and Checkov, and keep pre-commit hooks (terragrunt_fmt, terraform_fmt, terraform_docs) green.
- Manage shared platform infrastructure: ECR with replication, CodeArtifact (Maven/NPM), and a Pritunl VPN server.
- Manage MongoDB Atlas infrastructure via the Terraform provider.
- Mentor junior engineers, lead code reviews, and champion IaC best practices across the team.
Must-have
- 5–7 years minimum of hands-on experience in DevOps, Cloud Infrastructure, Platform, or Site Reliability Engineering roles.
- Strong hands-on experience with Terraform and Terragrunt in a multi-environment setup.
- Deep AWS knowledge across networking, compute, databases, serverless, and security services.
- Production experience operating Amazon EKS / Kubernetes.
- Solid understanding of remote state management, state isolation, and backend bootstrapping (S3 DynamoDB).
- Experience embedding security into IaC: Checkov, TFLint, IAM least-privilege, KMS, WAF, and secrets management.
- Comfortable with GitHub Actions CI/CD and pre-commit tooling.
- Proficient with Bash and shell scripting; Linux fundamentals.
- Git workflow discipline, including signed/verified commits.
Nice-to-have
- Experience with MongoDB Atlas, Grafana provisioning-as-code, or AWS Amplify.
- Familiarity with pinning external modules to commit SHAs for reproducibility.
- Exposure to VPN infrastructure (Pritunl) and CodeArtifact/private registries.
- Multi-region deployment experience.
Tech Stack
Terraform • Terragrunt • AWS • EKS/Kubernetes • Lambda • RDS • MongoDB Atlas • CloudFront/WAF •
Grafana • GitHub Actions • Checkov • TFLint • BashExperience with MongoDB Atlas, Grafana
Click on Apply to know more.