Principal Cloud Platform Architect / Engineering Lead

Bangalore, Karnataka · Onsite Full-time 10+ years Any Graduate Direct Client hiring Posted 1 month ago💰 Not disclosed
Apply now

Must Have Skills

AWSEKSKubernetesAWS OrganizationsVPCTransit GatewayPrivateLinkIAMIRSAECRLambdaALBNLBRoute53CloudTrailGuardDutyKMSSecrets ManagerTerraformDockerBitbucketCI/CDGitOpsHelmRBACNetworkPoliciesOpenTelemetrySigNozPrometheusGrafanaObservabilityZero TrustCloud SecurityInfrastructure ArchitectureAmazon EKSVPC ArchitectureAWS PrivateLinkRoute 53IAM & IRSAAmazon ECRAWS LambdaApplication Load Balancer (ALB)Network Load Balancer (NLB)AWS CloudTrailAmazon GuardDutyAWS Key Management Service (KMS)AWS Secrets ManagerProduction-grade Amazon EKS deploymentsMulti-tenant Kubernetes environmentsKubernetes RBACNetwork PoliciesIngress ControllersKubernetes SecurityService Mesh (Istio/App Mesh preferred)Bitbucket PipelinesOIDC-based AuthenticationCI/CD ArchitectureDocker & ContainerizationInfrastructure as Code (Terraform preferred)Platform AutomationZero Trust ArchitectureLeast Privilege IAMCloud Security ArchitectureEnterprise Governance & ComplianceCentralized LoggingMetricsDistributed TracingAWSOrganizations, Route53, CloudTrail, GuardDuty, KMS, SecretsManager, OIDC, Istio, AppMesh, SigNoz, DirectConnect, VPN, HybridCloud, MultiAccount, MultiTenancy, Ingress, ContainerSecurity, Governance, Compliance, Monitoring, Logging, Tracing, Akamai, WAF, Amplify, ECS, CKA, CKS, Terraform Associate, Architecture

Preferred Skills

AWSEKSKubernetesAWS OrganizationsVPCTransit GatewayPrivateLinkIAMIRSAECRLambdaALBNLBRoute53CloudTrailGuardDutyKMSSecrets ManagerTerraformDockerBitbucketCI/CDGitOpsHelmRBACNetworkPoliciesOpenTelemetrySigNozPrometheusGrafanaObservabilityZero TrustCloud SecurityInfrastructure ArchitectureAmazon EKSVPC ArchitectureAWS PrivateLinkRoute 53IAM & IRSAAmazon ECRAWS LambdaApplication Load Balancer (ALB)Network Load Balancer (NLB)AWS CloudTrailAmazon GuardDutyAWS Key Management Service (KMS)AWS Secrets ManagerProduction-grade Amazon EKS deploymentsMulti-tenant Kubernetes environmentsKubernetes RBACNetwork PoliciesIngress ControllersKubernetes SecurityService Mesh (Istio/App Mesh preferred)Bitbucket PipelinesOIDC-based AuthenticationCI/CD ArchitectureDocker & ContainerizationInfrastructure as Code (Terraform preferred)Platform AutomationZero Trust ArchitectureLeast Privilege IAMCloud Security ArchitectureEnterprise Governance & ComplianceCentralized LoggingMetricsDistributed TracingAWSOrganizations, Route53, CloudTrail, GuardDuty, KMS, SecretsManager, OIDC, Istio, AppMesh, SigNoz, DirectConnect, VPN, HybridCloud, MultiAccount, MultiTenancy, Ingress, ContainerSecurity, Governance, Compliance, Monitoring, Logging, Tracing, Akamai, WAF, Amplify, ECS, CKA, CKS, Terraform Associate, Architecture

About The Company

We are hiring candidates on behalf of a global technology services and solutions company headquartered in East Brunswick, New Jersey, USA, with development and delivery centers across the globe. Since 2003, we have been helping enterprises accelerate digital transformation through innovative solutions in Cloud, AI, Cybersecurity, Governance, Risk & Compliance (GRC), Enterprise Applications, Procurement, Healthcare, and Managed IT Services.


We are seeking an experienced Principal Cloud Platform Architect / Engineering Lead to spearhead the design, implementation, and operationalization of an enterprise-grade AWS cloud platform supporting a major cloud modernization initiative.

This is not a traditional DevOps role. We are looking for a highly technical cloud platform engineering leader with deep expertise in AWS architecture, Kubernetes, cloud networking, security, and platform engineering. The ideal candidate should be equally comfortable designing enterprise architecture, writing Terraform code, implementing Kubernetes platforms, reviewing security controls, and leading cloud migration initiatives.

You will collaborate closely with Cloud Engineering, Infrastructure, Networking, Cyber Security, Platform Engineering, Operations, and Application Development teams to build a secure, scalable, resilient, and highly observable cloud platform supporting enterprise-scale workloads.

This is a net-new position created for a strategic multi-year cloud modernization program with strong long-term growth potential.


Role Highlights

  1. Principal-level hands-on technical leadership role
  2. Enterprise AWS Platform Engineering
  3. Production-scale Amazon EKS implementation
  4. Cloud Modernization Program
  5. Multi-account AWS Architecture
  6. Security-first engineering culture
  7. Hybrid Cloud Architecture
  8. Platform Automation
  9. Enterprise Observability
  10. Zero Trust Security

Project Overview

The organization is consolidating applications currently running on:

  1. AWS Amplify
  2. Amazon ECS
  3. AWS Lambda
  4. On-Premises Infrastructure

into a standardized, enterprise-scale Amazon EKS platform.

The cloud platform is designed around:

  1. AWS Organizations
  2. Multi-account AWS Architecture
  3. Amazon EKS
  4. Transit Gateway
  5. AWS PrivateLink
  6. Akamai CDN & WAF
  7. Bitbucket Pipelines
  8. OpenTelemetry
  9. SigNoz
  10. Hybrid Connectivity
  11. Zero Trust Security

First 90 Days

The initial engagement focuses on understanding the existing AWS environment and gradually leading platform implementation.

Initial Responsibilities

  1. Review the current AWS landscape
  2. Understand repositories, pipelines, and application architecture
  3. Validate and enhance the target platform design
  4. Participate in Cyber Security architecture reviews
  5. Separate Development, UAT, and Production environments using AWS Organizations
  6. Consolidate repositories into standardized structures
  7. Optimize Bitbucket CI/CD pipelines
  8. Build the enterprise platform while maintaining production stability

Key Responsibilities

  1. Architect and implement an enterprise-scale AWS Kubernetes platform.
  2. Design secure multi-account AWS environments using AWS Organizations.
  3. Lead Amazon EKS platform engineering for production workloads.
  4. Establish Kubernetes governance, operational standards, and platform best practices.
  5. Design secure hybrid networking using:
  6. Transit Gateway
  7. AWS PrivateLink
  8. VPN
  9. AWS Direct Connect
  10. VPC Routing
  11. Build Zero Trust cloud security architecture.
  12. Implement least-privilege IAM models across AWS and Kubernetes.
  13. Design enterprise CI/CD pipelines using Bitbucket Pipelines and self-hosted runners.
  14. Develop Infrastructure as Code using Terraform.
  15. Build reusable Terraform modules and Helm charts.
  16. Implement GitOps operating models.
  17. Lead migration of workloads from AWS Amplify, ECS, Lambda, and on-premises environments to Amazon EKS.
  18. Establish Kubernetes RBAC, Network Policies, multi-tenancy, secrets management, and workload isolation.
  19. Implement enterprise observability using:
  20. OpenTelemetry
  21. SigNoz
  22. Prometheus
  23. Grafana
  24. Centralized Logging
  25. Distributed Tracing
  26. Partner with Cyber Security teams on:
  27. Architecture Reviews
  28. Threat Modeling
  29. Compliance
  30. Security Assessments
  31. Develop architecture documents, runbooks, standards, and implementation roadmaps.
  32. Lead disaster recovery planning, resiliency testing, and production readiness.
  33. Mentor engineers and provide technical leadership across platform engineering initiatives.

Priority Technical Skills

Tier 1 – Mandatory (Hiring Gate)

Candidates must demonstrate deep hands-on expertise in:

AWS

  1. AWS
  2. Amazon EKS
  3. AWS Architecture
  4. AWS Networking
  5. VPC
  6. Transit Gateway
  7. AWS PrivateLink
  8. IAM
  9. Least Privilege Security

Kubernetes

  1. Production Amazon EKS
  2. Kubernetes Administration
  3. Kubernetes Architecture
  4. Kubernetes Security

Tier 2 – Strongly Preferred

  1. AWS Organizations
  2. Multi-account Architecture
  3. Hybrid Connectivity
  4. VPN
  5. AWS Direct Connect
  6. Terraform
  7. Infrastructure as Code
  8. Helm
  9. GitOps
  10. Kubernetes RBAC
  11. Network Policies
  12. Multi-tenancy
  13. Container Security
  14. Zero Trust Architecture
  15. Cloud Governance

Tier 3 – Good to Have

  1. Bitbucket Pipelines
  2. Self-hosted Runners
  3. OIDC Authentication
  4. OpenTelemetry
  5. SigNoz
  6. Prometheus
  7. Grafana
  8. Route 53
  9. Amazon ECR
  10. AWS GuardDuty
  11. AWS CloudTrail
  12. AWS KMS
  13. AWS Secrets Manager
  14. Istio
  15. AWS App Mesh

Required Technical Skills

AWS

  1. AWS
  2. Amazon EKS
  3. AWS Organizations
  4. VPC
  5. Transit Gateway
  6. AWS PrivateLink
  7. Route 53
  8. IAM
  9. IRSA
  10. Amazon ECR
  11. AWS Lambda
  12. ALB
  13. NLB
  14. CloudTrail
  15. GuardDuty
  16. KMS
  17. Secrets Manager
  18. VPN
  19. Direct Connect

Kubernetes

  1. Amazon EKS
  2. Kubernetes
  3. Helm
  4. GitOps
  5. RBAC
  6. Network Policies
  7. Multi-tenancy
  8. Ingress Controllers
  9. Container Security
  10. Cluster Administration

DevOps & Platform Engineering

  1. Terraform
  2. Infrastructure as Code
  3. Docker
  4. Bitbucket Pipelines
  5. OIDC
  6. CI/CD
  7. Platform Automation

DevOps & Platform Engineering

  1. Terraform
  2. Infrastructure as Code
  3. Docker
  4. Bitbucket Pipelines
  5. OIDC
  6. CI/CD
  7. Platform Automation

Security

  1. Zero Trust
  2. IAM
  3. Kubernetes Security
  4. Cloud Security
  5. Governance
  6. Compliance
  7. Threat Modeling

Observability

  1. OpenTelemetry
  2. SigNoz
  3. Prometheus
  4. Grafana
  5. Logging
  6. Monitoring
  7. Metrics
  8. Distributed Tracing

Required Qualifications

  1. Bachelor's or Master's degree in Computer Science, Information Technology, or a related field.
  2. 10+ years of Infrastructure, Platform Engineering, or Cloud Engineering experience.
  3. 5+ years of hands-on AWS Architecture experience.
  4. 5+ years of production Kubernetes platform engineering experience.
  5. Strong expertise in enterprise cloud platform implementation.
  6. Hands-on experience with Terraform, AWS networking, Kubernetes, and security.
  7. Proven experience leading cloud modernization initiatives.
  8. Experience working closely with Infrastructure, Cyber Security, Networking, Operations, and Application Engineering teams.
  9. Strong troubleshooting and architectural decision-making skills.
  10. Excellent communication, documentation, and stakeholder management abilities.
  11. Ability to work independently in a globally distributed engineering environment.
  12. Must be available during U.S. East Coast business hours.

Preferred Certifications

  1. AWS Certified Solutions Architect – Professional
  2. Certified Kubernetes Administrator (CKA)
  3. Certified Kubernetes Security Specialist (CKS)
  4. HashiCorp Terraform Associate

Ideal Candidate

The ideal candidate is a Principal Cloud Platform Architect who combines strategic architecture expertise with strong hands-on implementation capabilities.

You should be comfortable moving seamlessly between:

  1. Enterprise Architecture
  2. Terraform Development
  3. Kubernetes Administration
  4. AWS Networking
  5. Cloud Security
  6. Platform Engineering
  7. Migration Planning
  8. Production Troubleshooting
  9. Technical Leadership

This role is best suited for professionals who enjoy designing and building cloud platforms rather than supporting existing DevOps pipelines.

Apply to this job

Required — upload a file or paste the text