2 hours ago
Remote, India or Bengaluru, IndiaStaff+

Responsibilities

  • Own the end-to-end AWS platform architecture, roadmap, multi-account strategy, Organizations hierarchy, Control Tower or landing zone, account vending, identity, networking, security, observability, and cost governance.
  • Partner with Azure Platform Engineering to align Management Groups, subscription vending, Enterprise Scale landing zones, identity, networking, security, observability, and cost governance.
  • Define and enforce secure, least-privilege, infrastructure-as-code platform principles across AWS and Azure using Terraform and related cloud-native tools.
  • Lead AWS and Azure hub-and-spoke networking, connectivity, centralized DNS, routing, inspection, private endpoints, and load-balancing patterns.
  • Govern AWS SCPs, IAM policies, permission boundaries, AWS Config, GuardDuty, Security Hub, Azure Policy, RBAC, Defender for Cloud, and related compliance controls.
  • Design centralized root-account, privileged-access, break-glass, identity federation, workload identity, and CI/CD authentication strategies.
  • Own organization-wide logging and observability architectures across AWS and Azure, including CloudTrail, Azure Monitor, flow logs, streaming pipelines, and Splunk or Elastic integration.
  • Drive multi-cloud guardrails and shared platform patterns across AWS, Azure, and GCP in collaboration with Platform Engineering teams and InfoSec.
  • Define modernization paths for AWS and Azure container, database, and data services.
  • Lead Terraform migration, module standards, policy-as-code, pipeline governance, and GitHub or Spacelift delivery practices.
  • Prioritize platform capabilities around application-team needs, measurable outcomes, adoption, cost, performance, scalability, security, and compliance.
  • Mentor senior and mid-level engineers, lead design reviews, communicate with engineering and executive stakeholders, and represent the platform in architecture councils and governance forums.

Requirements

  • 12+ years of platform or cloud engineering experience, including 6+ years with AWS at enterprise scale and hands-on Azure platform engineering in regulated environments.
  • Expertise in Terraform modules and workspaces, infrastructure-as-code governance, policy-as-code or OPA, and CI/CD across AWS and Azure.
  • Deep AWS networking experience with VPCs, Transit Gateway, centralized endpoints, routing, load balancing, and centralized inspection.
  • Strong Azure networking experience with VNets, Azure Virtual WAN, Private Link or Private Endpoints, routing, load balancing, and centralized inspection.
  • Strong AWS security engineering experience with SCPs, IAM, root-account management, AWS Config, GuardDuty, Security Hub, KMS or CMEK, and Secrets Manager.
  • Strong Azure security engineering experience with Azure Policy, deny assignments, RBAC, Defender for Cloud, Key Vault or CMEK, and enterprise secrets integrations.
  • Experience with AWS and Azure identity federation, group-based RBAC, PIM or JIT access, managed identities, OIDC, IRSA, and AKS workload identity.
  • Experience designing AWS and Azure observability, log-streaming pipelines, Splunk or Elastic integrations, and cost optimization.
  • Hands-on experience with AWS Control Tower, AVM, Organizations, AWS Well-Architected Framework, Azure Management Groups, subscription vending, Enterprise Scale landing zones, and Azure Well-Architected Framework.
  • Strong product mindset and demonstrated ability to shape platform roadmaps around application-team needs, adoption, and measurable outcomes.
  • Excellent communication, accountability, ownership, mentoring, cross-business-unit influence, vendor management, risk-trade-off, and executive communication skills.
  • Preferred qualifications include Spacelift, Cloudflare Zero Trust or Tunnels, WAF or DDoS, Palo Alto VM-Series, CloudFormation, Bicep, ARM, GitHub Actions federation, and GCP platform familiarity.

Categories

First American Financial Corporation

About First American Financial Corporation

10,000+ employees
Contact me