NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs
4 days ago
Apply with autofill
Apply with autofill
Opsbrasil·4 days ago
4 days ago

Cloud Engineer AWS ( CDK / Serverless) ( 102-09SENG-01 )

Acre, BrazilContractRemoteSenior · 5+ yearsCloud Engineer

Sign up free to see how well your resume matches this role.

Boost your chances at opsbrasil

How you compare FREE

?
Your scoreYour score: not yet known
→
66
Top 10%Top 10%: 66 out of 100

Top 10% of NextRaise users matched against Cloud Engineer roles in Brazil.

Must-have skills for this role

  • aws
  • cdk
  • infrastructure-as-code
  • typescript

PDF or DOCX · no account needed

Apply faster with autofill FREEThe NextRaise extension autofills your application in one click.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Inventory the CDK estate and build a modernization plan: upgrade the CDK library/CLI, replace deprecated constructs, move hardcoded context into per-environment config.
  • Consolidate duplicated stacks into shared constructs without losing resource identity — map logical IDs before and after, pick a preservation method, and confirm nothing gets replaced before touching production.
  • Run the library upgrade and the stack refactor as two separate, ordered deployments, with a rollback path tested in dev and test first.
  • Migrate all six Lambda functions from Node 18 to Node 24, close an open PII logging finding, and regression-test each one.
  • Re-verify the security perimeter after both deployments — WAF, the mTLS domain and truststore, X-Ray tracing, upstream timeouts — working directly with the customer's POS team across all six external callers.
  • Build deployment pipelines for dev/test/prod with OIDC federation, approval gates, and a ServiceNow change step. Add CDK assertion tests, drift detection, and API access log retention.
  • Publish the SQS queue ARN and KMS key ARN via Parameter Store, and grant send permission to the downstream Terraform-managed system — this is the key ordering dependency for that team's build.
  • Align naming, tagging, and documentation with the customer's internal standards, and document your identity-preservation decisions clearly enough for the next engineer to follow.

What they're looking for

  • 5+ years with AWS, including 3+ years working in infrastructure-as-code.
  • Hands-on AWS CDK experience in TypeScript — construct trees, logical ID derivation, and what happens when a construct path changes.
  • Real experience with CloudFormation resource identity: stack refactoring, logical ID overrides, cdk diff against deployed state, drift detection.
  • Working Terraform knowledge — comfortable operating across the CDK/Terraform boundary.
  • Solid AWS serverless background: Lambda, API Gateway (REST), SQS and DLQs, Parameter Store, KMS, Secrets Manager.
  • Experience with AWS edge and security services — WAF web ACLs, mutual-TLS custom domains and truststores, cross-account/cross-boundary IAM.
  • Practical experience migrating Nodejs runtimes (e.g. Node 18 → 24), including dependency and deprecation handling.
  • CI/CD pipeline experience with OIDC federation and approval gates (GitHub Actions or equivalent).
  • Working knowledge of observability tools — X-Ray, CloudWatch metrics and alarms, log retention.
  • Comfortable communicating clearly with non-engineers, and working well when parts of the scope are still being figured out.
  • Fluent English (C1 level) for daily communication with the client.

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

This role modifies a live serverless gateway in production — no downtime, no change in behaviour — leaving a clean handoff point for a downstream build managed in Terraform. This is careful surgery on production infrastructure with active external consumers, not a greenfield build.

The scope includes modernizing a CDK estate made up of four stacks, six Lambda functions, a WAF web ACL, an mTLS custom domain/truststore, and a REST API — preserving resource identity during consolidation and coordinating two sequenced deployments with a tested rollback path.

What you will do

  • Inventory the CDK estate and build a modernization plan: upgrade the CDK library/CLI, replace deprecated constructs, move hardcoded context into per-environment config.

  • Consolidate duplicated stacks into shared constructs without losing resource identity — map logical IDs before and after, pick a preservation method, and confirm nothing gets replaced before touching production.

  • Run the library upgrade and the stack refactor as two separate, ordered deployments, with a rollback path tested in dev and test first.

  • Migrate all six Lambda functions from Node 18 to Node 24, close an open PII logging finding, and regression-test each one.

  • Re-verify the security perimeter after both deployments — WAF, the mTLS domain and truststore, X-Ray tracing, upstream timeouts — working directly with the customer's POS team across all six external callers.

  • Build deployment pipelines for dev/test/prod with OIDC federation, approval gates, and a ServiceNow change step. Add CDK assertion tests, drift detection, and API access log retention.

  • Publish the SQS queue ARN and KMS key ARN via Parameter Store, and grant send permission to the downstream Terraform-managed system — this is the key ordering dependency for that team's build.

  • Align naming, tagging, and documentation with the customer's internal standards, and document your identity-preservation decisions clearly enough for the next engineer to follow.

  • 5+ years with AWS, including 3+ years working in infrastructure-as-code.

  • Hands-on AWS CDK experience in TypeScript — construct trees, logical ID derivation, and what happens when a construct path changes.

  • Real experience with CloudFormation resource identity: stack refactoring, logical ID overrides, cdk diff against deployed state, drift detection.

  • Working Terraform knowledge — comfortable operating across the CDK/Terraform boundary.

  • Solid AWS serverless background: Lambda, API Gateway (REST), SQS and DLQs, Parameter Store, KMS, Secrets Manager.

  • Experience with AWS edge and security services — WAF web ACLs, mutual-TLS custom domains and truststores, cross-account/cross-boundary IAM.

  • Practical experience migrating Nodejs runtimes (e.g. Node 18 → 24), including dependency and deprecation handling.

  • CI/CD pipeline experience with OIDC federation and approval gates (GitHub Actions or equivalent).

  • Working knowledge of observability tools — X-Ray, CloudWatch metrics and alarms, log retention.

  • Comfortable communicating clearly with non-engineers, and working well when parts of the scope are still being figured out.

  • Fluent English (C1 level) for daily communication with the client.

Engagement details

  • Hourly contractor

  • 100% remote

  • Estimated duration: 6–8 weeks

  • Time zone: EST or MST

Company

Opsbrasil
Acre, Brazil

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Opsbrasil's careers site·first seen 18 Sept 2026·last verified 18 Sept 2026·How we source jobs

Similar jobs

  • Analista de Infraestrutura Cloud & Linux Pleno at DXC TechnologySP, Brazil–match not yet calculated
  • Especialista Kubernetes— Pleno at DXC TechnologySP, Brazil–match not yet calculated
  • Especialista Kubernetes— Sênior at DXC TechnologySP, Brazil–match not yet calculated
  • Analista Azure — Pleno at DXC TechnologySP, Brazil–match not yet calculated
  • Gestão de Demandas Azure e AWS at DXC TechnologySP, Brazil–match not yet calculated

Browse more jobs

  • Cloud Engineer jobs in United States
  • Cloud Engineer jobs in India
  • Cloud Engineer jobs in Germany
  • Retail Sales Associate jobs in United States