Cloud Engineer
Paymentology
- Нур-Султан
- Постоянная работа
- Полная занятость
- Support and enhance Paymentology’s AWS cloud foundation, including multi-account governance using AWS Organizations, Landing Zone frameworks, and Service Control Policy guardrails.
- Design, implement, and maintain secure IAM roles, policies, and access controls aligned with least privilege and compliance requirements.
- Develop, modularize, and govern Terraform-based Infrastructure as Code to enable scalable, repeatable, and secure infrastructure deployments.
- Integrate infrastructure automation into CI/CD pipelines to ensure consistency across development, testing, and production environments.
- Implement and support core AWS infrastructure services such as API Gateway, Lambda, CloudFront, Route 53, and application and network load balancers.
- Collaborate closely with Platform Engineering and Security teams to align infrastructure standards, governance controls, and operational reliability.
- Support troubleshooting, incident response, and root cause analysis across cloud environments to maintain high availability and performance.
- Maintain clear Confluence documentation, operational runbooks, and infrastructure standards to support long-term platform sustainability.
< 10%
- Strong hands-on AWS expertise with a focus on multi-account environments, Landing Zone governance, and cloud security best practices.
- Deep understanding of IAM governance, including role-based access control, least privilege policy design, and cross-account access patterns.
- Advanced experience with Terraform, including reusable module development, multi-environment deployments, and IaC governance through CI/CD.
- Working knowledge of modern AWS services such as Lambda, API Gateway, CloudFront, Route 53, and ALB/NLB.
- Experience supporting production cloud environments with strong troubleshooting and incident response capabilities.
- Familiarity with compliance-driven environments such as PCI DSS or ISO 27001 is highly advantageous.
- General exposure to Kubernetes or EKS concepts is beneficial, although deep expertise is not required.