Infrastructure as Code Engineer - Multi-Cloud
We are seeking an experienced Infrastructure as Code (IaC) Engineer to design, automate, and secure scalable infrastructure across GCP, AWS, and Azure. The role requires strong expertise in Terraform, cloud networking, network security, IAM, Kubernetes networking, and API gateways.
The engineer will build reusable IaC modules and secure multi-cloud patterns, implement network and security controls, automate infrastructure through CI/CD and policy-as-code, and establish standardized self-service capabilities for engineering teams. The role will also support AI and agentic enablement, orchestrating secure connectivity, identity, API/tool access, and infrastructure patterns for deploying agentic workloads across multi-cloud environments.
- 7+ years of infrastructure engineering experience with strong expertise in Infrastructure as Code (IaC) using Terraform, OpenTofu, or similar frameworks.
- 7+ years of hands-on experience designing and automating infrastructure across Google Cloud Platform (GCP), AWS, and/or Azure, with an emphasis on reusable, standardized multi-cloud patterns.
- Strong knowledge of cloud networking, including VPC/VNet architecture, subnets, routing, DNS, NAT, load balancing, private connectivity, peering, transit architectures, VPN, and dedicated interconnects.
- Deep understanding of network security, including security groups, firewall policies/rules, network ACLs, micro-segmentation, ingress/egress controls, private endpoints, and Zero Trust principles.
- Proven experience implementing network segmentation and isolation patterns across applications, environments, business units, and cloud platforms.
- Strong experience with API gateways and API infrastructure, including secure ingress/egress, authentication and authorization, rate limiting, routing, policy enforcement, private APIs, and service-to-service connectivity.
- Experience designing secure connectivity for Kubernetes and containerized workloads, including GKE/EKS/AKS networking, network policies, service ingress/egress, and workload isolation.
- Strong understanding of IAM, secrets management, encryption, certificates/PKI, and cloud security architecture, with the ability to integrate these controls into IaC modules and deployment pipelines.
- Proven experience building enterprise-grade reusable Terraform modules, policy-driven infrastructure patterns, CI/CD integrations, automated testing, and infrastructure governance.
- Experience designing and operating large-scale, highly available, resilient multi-cloud infrastructure using standardized automation and security controls.
- Strong understanding of distributed systems, microservices, service-to-service communication, and modern application connectivity patterns.
- Experience enabling AI/agentic workloads in multi-cloud environments, including secure agent-to-API/tool connectivity, identity and authorization, controlled network access, API gateway integration, secrets handling, and infrastructure automation for agentic platforms.
- Experience developing multi-cloud network and security architectures spanning GCP, AWS, Azure, on-premises, and SaaS environments.
- Experience building IaC platform capabilities such as reusable modules, golden patterns, self-service infrastructure, policy-as-code, automated compliance, and developer enablement.
- Experience with network security platforms and cloud-native controls, such as Cloud NGFW/firewalls, AWS Network Firewall, Azure Firewall, WAF, IDS/IPS, secure web gateways, and service mesh technologies.
- Experience with API management platforms such as Apigee, AWS API Gateway, Azure API Management, Kong, or equivalent technologies.
- Knowledge of Zero Trust, least privilege, defense-in-depth, micro-segmentation, and secure-by-default infrastructure design.
- Experience with policy-as-code and security automation using technologies such as OPA, Sentinel, organization policies, IAM policies, and automated IaC security scanning.
- Experience with FinOps and cloud cost optimization, particularly network, data-transfer, NAT, load-balancing, API, and multi-cloud connectivity costs.
- Experience enabling agentic AI platforms and AI infrastructure, including secure access to enterprise APIs, MCP/tool integrations, agent identity, guardrails, observability, and controlled cross-cloud connectivity.
- Experience establishing IaC standards and governance for AI/agentic infrastructure, enabling engineering teams to provision secure networking, APIs, compute, identity, and security controls through reusable modules.
- Relevant certifications such as HashiCorp Terraform Associate, GCP Professional Cloud Network Engineer/Cloud Architect/Cloud Security Engineer, AWS Advanced Networking or Security Specialty, or Azure Network/Security certifications.
Employment eligibility to work with American Express in the United States is required as the company will not pursue visa sponsorship for these positions.

