Cloud Engineer
Team Cymru · Lake Mary, FL · Today
RemoteRemoteEngineeringFull-time
Key Responsibilities
- Administer the AWS Organization, managing accounts, organizational units, and the multi-account structure day to day
- Administer IAM (users, roles, policies, least-privilege access) along with secrets and key management (Secrets Manager, KMS)
- Implement and maintain governance guardrails, including Service Control Policies (SCPs), Control Tower guidelines, and Account Factory provisioning, under senior guidance
- Design, deploy, and maintain infrastructure as code with CloudFormation, using version control, change sets, and drift detection, and take part in the CI/CD process for templates
- Administer networking and VPCs, including subnets, routing, security groups, and connectivity
- Manage billing and cost: budgets and alerts, cost-allocation tagging, and rightsizing/optimization recommendations
- Maintain resource tagging and governance standards that feed cost allocation and AWS Config rules
- Operate cloud observability, including CloudWatch metrics, logs, and alarms, and CloudTrail, and respond to alerts
- Maintain baseline cloud security services (GuardDuty, Security Hub, AWS Config) and respond to infrastructure-layer security findings in partnership with the Security team
- Support the on-premises private cloud through process-improvement automation, monitoring automation, and application integration, working closely with and learning from the SRE team
- Participate in a shared on-call rotation, responding to incidents and driving resolution
- Maintain documentation and runbooks
Qualifications & Experience
- AWS Certified Cloud Practitioner or an AWS Associate-level certification
- 1-3 years of hands-on AWS experience (junior to mid-level)
- Working knowledge of AWS Organizations, IAM, and multi-account concepts
- Experience with infrastructure as code, especially CloudFormation
- Familiarity with VPC networking (subnets, routing, security groups)
- Exposure to AWS cost management and governance (SCPs, tagging, budgets)
Additional Skills
- Comfortable scripting in Bash and/or Python
- Willingness to learn on-prem virtualization and to join an on-call rotation
- Control Tower and Account Factory experience (nice to have)
- CloudWatch/CloudTrail observability and baseline security services like GuardDuty, Security Hub, AWS Config (nice to have)
- Secrets Manager / KMS experience (nice to have)
- Git-based workflows and CI/CD for infrastructure as code (nice to have)
Education and Certifications
- AWS Certified Cloud Practitioner or AWS Associate-level certification required
- Exposure to on-prem hypervisors (Xen, Proxmox) or Linux administration a plus
- Background in a security- or threat-intelligence-conscious environment a plus
Why Join Team Cymru?
- Provide unmatched global threat intelligence that empowers organizations to proactively disrupt adversaries
- Collaborative, mission-driven culture where your expertise and impact will directly contribute to improving global security
- Remote position