Cloud Infrastructure Engineer
Ho Chi Minh City - Vietnam
Job Summary
We have an immediate opening for a results-driven hands-on Cloud Infrastructure Engineer to join our Infrastructure Services (IS) team located in Ho Chi Minh. To thrive in this role you should be a strong technical owner with a bias toward execution and a track record of building cloud infrastructure not just managing it. The candidate filling this role will share on-call responsibilities with other members of the team.
Position Overview
The Cloud Infrastructure Engineer is an enterprise-level position responsible for the design architecture implementation automation and Infrastructure as Code (IaC) management of CESs cloud infrastructure. This is not a cloud administration or monitoring role. It requires demonstrated hands-on proficiency in architecting and building cloud-native solutions constructing automated infrastructure delivery pipelines and applying IaC principles at scale across a growing multi-account AWS environment.
This individual will own and drive CESs Infrastructure as Code practice using Terraform and Terraform Cloud defining the standards module patterns and deployment frameworks that underpin cloud infrastructure delivery across the organization. The Cloud Infrastructure Engineer will contribute to an active multi-year migration program provisioning and integrating cloud infrastructure in close coordination with application development data engineering and security teams.
The candidate must demonstrate advanced hands-on expertise with core AWS services a strong command of Terraform and the AWS CLI and the ability to apply cloud networking security governance and FinOps practices in a complex enterprise environment. This role requires proven experience implementing Infrastructure as Code and cloud automation in organizations where standards are still being established and the initiative to create structure and drive adoption across the IS team.
This role carries direct responsibility for engaging with internal stakeholders across CES business lines and external clients and partners including their technical and non-technical representatives to support cloud infrastructure requirements communicate service impact and drive resolution under pressure. The ability to communicate accurately and professionally with technical and non-technical audiences alike is a firm requirement of this role.
Responsibilities
Cloud Architecture & Infrastructure
- Design and implement scalable highly available and fault-tolerant AWS infrastructure solutions across a multi-account AWS Organizations environment.
- Own the architecture and configuration of cloud networking components including VPCs subnets routing tables Transit Gateway Direct Connect and VPN connectivity to on-premises environments.
- Manage and optimize core AWS services including EC2 EKS/ECS Lambda S3 RDS Aurora DynamoDB CloudFront and Route 53.
- Implement and maintain cloud security controls including IAM least-privilege policies service control policies (SCPs) and secrets management in alignment with organizational security standards.
- Establish and maintain robust disaster recovery and business continuity protocols for cloud-hosted systems.
Infrastructure as Code & Automation
- Drive the development of CESs Infrastructure as Code practice using Terraform and Terraform Cloud defining standards modules and deployment models from inception.
- Develop and maintain CI/CD pipelines for infrastructure deployments using GitHub Actions with automated validation testing and rollback.
- Automate operational tasks and provisioning workflows using Python Bash and the AWS CLI.
- Define and document Infrastructure as Code standards naming schemes module patterns and state management best practices for team adoption.
Cloud Migration
- Contribute to an active multi-year program that migrates on-premises servers applications and databases into AWS. This includes network readiness infrastructure provisioning cutover planning and post-migration validation.
- Work with application and data engineering teams to ensure cloud infrastructure is the right size secure and optimized for migrated workloads.
- Support hybrid connectivity between on-premises environments and AWS during the migration transition period.
FinOps & Observability
- Continuously track cloud infrastructure performance uptime and costs with CloudWatch and related tools; proactively resolve issues and eradicate inefficiencies.
- Design and implement tagging strategies cost allocation frameworks and FinOps practices. Deliver financial visibility and optimize cloud spend across accounts.
- Construct and oversee dashboards and alerting systems for infrastructure health capacity and cost trends.
Containerization & Platform
- Administer and maintain containerized workloads running on EKS and/or ECS. Oversee cluster configuration scaling policies and provide operational support.
- Collaborate with development teams to right-size secure and integrate container infrastructure with CI/CD pipelines.
Collaboration & Documentation
- Partner with infrastructure security application and data engineering teams across CESs global offices to align cloud infrastructure with organizational objectives and ensure consistent well-governed delivery.
- Engage directly with internal stakeholders across CES business lines and external clients and partners including their technical and non-technical representatives to support cloud infrastructure requirements coordinate resolution of service-impacting issues and communicate clearly in both technical and non-technical terms as the situation requires.
- Manage competing priorities across concurrent workstreams communicating status and risk clearly to IS leadership and relevant stakeholders.
- Draft and update detailed documentation of cloud architecture configurations runbooks and operational procedures.
- Serve in on-call rotation to address critical cloud infrastructure incidents and escalations.
- Evaluate emerging AWS services and devise adoption strategies aligned with organizational objectives.
Qualifications :
Required
- 5 years of hands-on experience in cloud infrastructure engineering or cloud architecture with AWS as the primary platform.
- Demonstrate deep expertise with core AWS services. These include EC2 EKS/ECS Lambda S3 RDS/Aurora DynamoDB VPC IAM Route 53 CloudFront CloudWatch and AWS Organizations.
- Extensive practical experience with Terraform including module authorship state management and configuring remote backends (preferably with Terraform Cloud).
- Demonstrate strong command of AWS CLI and proficiency in Python and/or Bash for automation and operational tooling.
- Have experience building and managing CI/CD pipelines. Experience with GitHub Actions is preferred.
- Have a solid understanding of cloud networking. This covers routing DNS load balancing security groups NACLs Transit Gateway Direct Connect and hybrid connectivity.
- Implement IAM least-privilege SCPs and secrets management in a multi-account AWS environment.
- Have experience with containerization and orchestration such as Docker and Kubernetes (EKS or similar).
- Proven ability to architect and uphold IaC frameworks in environments where standards are still evolvingcomfortable with ambiguity and proactive about creating structure.
- Bachelors degree in computer science Information Technology or a related field or equivalent practical experience.
- Excellent written and verbal communication skills with the demonstrated ability to engage clearly and professionally with technical and non-technical stakeholders across all levels of an organization. This is a firm requirement of this role.
- Demonstrated experience working directly with internal business stakeholders and external clients or partners including their technical and non-technical representatives to coordinate cloud infrastructure solutions communicate service impact and maintain trust during high-pressure situations.
Required Certifications
- AWS Certified Solutions Architect (Professional)
- AWS Certified DevOps Engineer (Professional)
- Active pursuit with demonstrated progress is also acceptable.
Preferred Certifications
- AWS Certified Security (Specialty)
- HashiCorp Terraform Associate or Professional
- Microsoft Certified: Azure Administrator Associate or Azure Network Engineer Associate
Nice to Have
- Experience with AWS CloudFormation alongside Terraform in a mixed IaC environment.
- Familiarity with monitoring and observability platforms beyond CloudWatch (Grafana or similar).
- Exposure to Azure networking and hybrid connectivity in a secondary cloud capacity.
- Experience with FinOps tooling or cloud cost management platforms.
- Familiarity with network security concepts relevant to cloud environments: WAF Shield GuardDuty Security Hub.
Additional Information :
CES offers a competitive salary commensurate with experience a performance-based annual bonus a year-end bonus in accordance with company policy premium health insurance for associates and eligible family members and statutory insurance and benefits in accordance with Vietnamese law. Associates also receive applicable allowances 12 days of annual leave paid sick leave public holidays additional company-designated leave and access to professional development and unlimited online training opportunities.
Beyond the benefits package heres what you can expect at CES:
- Meaningful responsibility and the opportunity to make a real impact in dynamic energy markets.
- The chance to learn from and collaborate with experienced professionals across our teams in Vietnam India and the United States.
- Ongoing opportunities to strengthen your technical analytical and leadership skills.
- Annual performance evaluations and clear opportunities for professional and career development.
- A supportive culture that values initiative accountability collaboration and continuous growth.
- Team-building activities employee engagement events and company celebrations.
Customized Energy Solutions provides equal employment opportunities to all applicants without regard to race color religion sex sexual orientation gender identity national origin disability or status as a protected veteran.
Remote Work :
No
Employment Type :
Full-time
About Company
Customized Energy Solutions (CES), a privately-held company, is a leading service provider of market intelligence and operational support services to companies participating in the retail and wholesale electric and natural gas markets. Utilizing deep know-how developed since the incep ... View more