Cloud Engineer
Washington, DC - USA
Job Summary
Position Summary
We are seeking an experienced Cloud Engineer to support the implementation automation governance and ongoing operations of our AWS cloud environment. This role will focus on AWS multi-account management cloud security infrastructure automation identity and access management networking monitoring and cost optimization.
The candidate must have strong hands-on experience with AWS services such as AWS Control Tower AWS Organizations IAM IAM Identity Center Service Control Policies VPC EC2 S3 RDS Lambda CloudWatch CloudTrail AWS Config and GuardDuty. The role also requires infrastructure-as-code experience using Terraform and AWS CloudFormation.
The Cloud Engineer will work closely with Application DevOps SRE Network Security and other support teams as required.
Key Responsibilities
- Manage and support AWS cloud infrastructure across development staging and production environments.
- Support AWS multi-account governance using AWS Control Tower AWS Organizations organizational units account structure and guardrails.
- Manage IAM roles IAM policies permission sets permission boundaries security groups network access and least-privilege access controls.
- Administer AWS IAM Identity Center including permission sets account assignments and group-based access.
- Implement and maintain Service Control Policies to enforce cloud security compliance and operational standards.
- Deploy and manage AWS infrastructure using Terraform AWS CloudFormation AWS CLI and automation scripts.
- Support AWS networking components including VPCs subnets route tables security groups NACLs internet gateways NAT gateways load balancers VPN DNS and traffic flow configurations.
- Troubleshoot cloud infrastructure issues related to networking compute storage access permissions deployments and application connectivity.
- Monitor cloud resources using CloudWatch CloudTrail AWS Config GuardDuty and other monitoring and security tools.
- Support cloud security best practices including IAM governance encryption logging secrets management monitoring and compliance controls.
- Manage secrets and secure access using tools such as AWS Secrets Manager AWS Systems Manager Parameter Store and Delinea.
- Support cost optimization initiatives including resource right-sizing reserved instances savings plans automated shutdown schedules budget controls and cloud usage reporting.
- Create automation scripts using Python Bash AWS CLI or Lambda to reduce manual operational tasks.
- Use Git and CI/CD tools to support infrastructure change management code reviews branching and deployment workflows.
- Maintain documentation for cloud architecture operational standards procedures runbooks and security controls.
- Participate in operational support cloud governance automation initiatives infrastructure improvements and production incident resolution as needed.
Required Qualifications
- Bachelors degree or Masters degree in Computer Science Information Technology Engineering or equivalent work experience.
- 8 years of hands-on experience working with AWS cloud services.
- Strong knowledge of core AWS services including EC2 VPC IAM S3 RDS Lambda CloudWatch CloudTrail AWS Config and GuardDuty.
- Experience with AWS Control Tower AWS Organizations IAM Identity Center Service Control Policies and multi-account AWS governance.
- Experience with infrastructure-as-code tools such as Terraform and AWS CloudFormation.
- Strong understanding of AWS networking concepts including VPCs subnets routing DNS load balancing security groups NACLs NAT gateways internet gateways and traffic flow.
- Experience with Linux administration and Linux fundamentals.
- Working knowledge of CI/CD tools such as GitHub Actions Jenkins AWS CodePipeline or similar platforms.
- Experience using Git for version control branching pull requests and code reviews.
- Experience with scripting and automation using Python Bash AWS CLI or Lambda.
- Ability to troubleshoot cloud infrastructure networking application access and permission-related issues.
- Strong understanding of cloud security best practices IAM policies encryption logging monitoring and compliance requirements.
- Strong communication skills and ability to work with cross-functional technical teams including Application DevOps SRE Network Security and Infrastructure teams.
Preferred Qualifications
- AWS certification such as AWS Certified Solutions Architect AWS SysOps Administrator or AWS DevOps Engineer.
- Experience with AWS cost management tools such as AWS Cost Explorer AWS Budgets Compute Optimizer or third-party FinOps tools.
- Experience with centralized logging cloud governance tagging standards account controls access reviews and operational reporting.
- Experience supporting enterprise AWS environments with multiple accounts and environments.
Soft Skills
- Strong problem-solving and troubleshooting skills.
- Strong written and verbal communication skills.
- Ability to explain technical concepts to both technical and non-technical stakeholders.
- Ability to collaborate with cross-functional teams.
- Commitment to continuous learning and staying current with cloud technologies.
- Ability to manage priorities timelines and multiple workstreams effectively.
Work Environment
This role may support development staging and production environments. The Cloud Engineer will participate in operational support cloud governance automation initiatives infrastructure improvements cost optimization security improvements and production incident resolution as needed.
This role is based in our Washington DC office. A reasonable rate of compensation for this position is between $130000 $150000 per year. ACS employees work a hybrid schedule consisting of working onsite two days per work week as decided by functional area. The balance of the week is open to working remotely though employees are always welcome onsite each day if they choose.
ACS currently provides the following benefits for this position: paid vacation leave paid sick leave paid holidays health insurance flexible spending account or health care savings account dental insurance life insurance vision insurance retirement benefits short- and long-term disability and 4-week work from anywhere; each benefit is subject to the terms of the applicable program. Additional benefits may apply based on skills experience and location.
Any actual offer of employment reflecting the total compensation package and benefits will be made in the sole discretion of ACS. ACS reserves the right to amend or modify its employment benefits and compensation structure at any time.
#LI-DNI
Required Experience:
IC
About Company
The American Community School opened its doors in 1955, when Mr. and Mrs. Ben Parker opened their residence to American families interested in a school with an American curriculum. During that first year, there were only 12 students in grades 1 through 8. As the young Kingdom grew, so ... View more