This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Cloud Infrastructure Engineer based in Brazil.
This is a senior individual contributor role focused on building and operating foundational cloud infrastructure at organizational scale.
You’ll join a CloudOps team responsible for identity, networking, governance, security, resilience, and shared cloud services across a complex multi-account environment.
The role combines hands-on engineering with broad technical ownership across AWS, Azure, and GCP.
You’ll use Infrastructure as Code to create secure, reusable platforms, guardrails, automation, and self-service capabilities for engineering teams.
Your work will directly improve cloud security, reliability, scalability, operational efficiency, and developer productivity.
You’ll tackle challenging infrastructure problems while partnering closely with Engineering, Security, FinOps, and other technical teams.
AI-assisted engineering is part of the workflow, giving you opportunities to use modern tooling while maintaining strong standards for architecture, security, testing, and production quality.
Accountabilities
- Own and evolve a multi-account AWS landing zone, including AWS Organizations, Control Tower, Account Factory for Terraform, organizational structures, Service Control Policies, tagging standards, and permission boundaries.
- Extend cloud governance, security controls, operational standards, observability, and backup capabilities across AWS, Azure, and GCP.
- Design and improve cloud identity and access management using least-privilege principles, including SSO, federation, IAM Identity Center, permission sets, group structures, credential management, and privileged-access reduction.
- Design and operate cloud networking capabilities covering IP address management, VPC architecture, routing, transit connectivity, Cloud WAN, egress, and public/private DNS.
- Help transition workloads from public internet exposure toward private and zero-trust networking models, including Kubernetes control planes, databases, and internal platforms.
- Build self-service infrastructure capabilities for engineering teams, including account and environment provisioning, access requests, lifecycle management, and infrastructure inventory.
- Design and maintain backup, restoration, disaster recovery, immutable backup, and ransomware-resistant strategies across regions, accounts, business units, and managed data platforms.
- Create reusable Terraform and Terragrunt modules and infrastructure patterns that can be safely adopted across engineering teams.
- Develop and maintain CI/CD automation for cloud infrastructure while improving consistency, reliability, and deployment speed.
- Partner with Security teams to investigate and remediate cloud security findings and with FinOps teams to identify scalable cloud cost-optimization opportunities.
- Maintain cloud standards, technical documentation, operating procedures, and shared responsibility models.
- Use AI coding agents to accelerate implementation and automation while retaining ownership of requirements, architecture, testing, security, code review, and production outcomes.
- Develop reusable AI-assisted workflows, prompts, and agent capabilities that improve infrastructure engineering productivity.
- Independently lead complex infrastructure initiatives from design through production and mentor or influence other engineers through technical expertise.
- 7-10+ years of professional experience in Cloud Infrastructure, DevOps, Site Reliability Engineering, Platform Engineering, Systems Engineering, or a related infrastructure discipline.
- 4-5+ years of hands-on experience with a major public cloud, with significant AWS experience strongly preferred.
- 3+ years of Infrastructure as Code experience, ideally with Terraform and/or Terragrunt.
- Proven experience operating AWS at organizational scale, including AWS Organizations, multi-account architectures, and Control Tower or comparable landing-zone solutions.
- Production experience with at least one additional major cloud platform, such as Azure or GCP.
- Strong ability to design reusable Infrastructure as Code modules and patterns for consumption by multiple engineering teams.
- Hands-on experience with cloud identity and access management, including SSO, SAML federation, SCIM, IAM policies, roles, permission boundaries, and least-privilege models.
- Strong cloud networking fundamentals covering IP planning, VPC/VNet design, routing, transit architectures, DNS, private connectivity, and network security.
- Experience designing and maintaining CI/CD pipelines using GitHub Actions, Jenkins, or comparable technologies.
- Scripting or programming experience with Python, Go, Bash, or similar languages, combined with strong Linux fundamentals.
- Working knowledge of Kubernetes and cloud-native infrastructure.
- Experience with AI-assisted development tools such as Claude Code, Cursor, Codex, or similar, including the ability to validate generated code and identify security or operational risks.
- Ability to independently own complex infrastructure projects, make sound technical decisions, and build reusable solutions rather than one-off fixes.
- Strong written and verbal communication skills, with the ability to collaborate across Engineering, Security, FinOps, and other technical teams.
- Advanced English proficiency.
- Bachelor’s degree in Computer Science, Software Engineering, Information Technology, or a related technical discipline.
- Must currently reside in Brazil.
- Desirable experience includes AWS Control Tower/AFT, AWS IPAM, Transit Gateway, Cloud WAN, multi-cloud governance, immutable backups, cloud security platforms, zero-trust networking, Cloudflare, PKI/certificate management, agentic automation, MCP, FinOps, SOC 2, GitHub administration, and relevant cloud or infrastructure certifications.
- Senior-level individual contributor position with broad technical ownership and organizational impact.
- Opportunity to work on large-scale, multi-account cloud infrastructure across AWS, Azure, and GCP.
- Exposure to complex challenges spanning cloud governance, security, networking, disaster recovery, automation, and developer self-service.
- Collaborative environment with close partnerships across Engineering, Security, FinOps, and other technical functions.
- Opportunity to use and shape modern AI-assisted engineering practices.
- Career development through technically challenging projects, mentorship, and cross-functional collaboration.
- Culture centered on innovation, collaboration, empathy, resilience, transparency, and technical ownership.
- Remote opportunity for candidates residing in Brazil.

