{"id":1722588,"url":"https://alion.io/job/reflex-media-senior-cloud-aws-infrastructure-engineer","title":"Senior Cloud / AWS Infrastructure Engineer","company":{"id":3863845,"name":"Reflex Media","domain":"reflexmedia.com","url":"https://alion.io/company/reflex-media-2","size_band":"51-200","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"JazzHR","truth_index":null},"role":"DevOps","role_family":"DevOps","seniority":"senior","employment_type":"full_time","work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"posting_text","remote_working_hours":null,"hiring_geo_confidence":"inferred","locations":[],"countries":[],"hiring_countries":["US"],"hiring_countries_total":1,"salary":{"min":130000,"max":180000,"currency":"USD","period":"year","gross":null,"usd_annual":180000},"salary_estimate":null,"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Alertmanager","optional":false},{"name":"Amazon Aurora","optional":false},{"name":"Amazon CloudWatch","optional":false},{"name":"Amazon ECS","optional":false},{"name":"Amazon Redshift","optional":false},{"name":"Amazon S3","optional":false},{"name":"AWS","optional":false},{"name":"AWS Bedrock","optional":false},{"name":"AWS Fargate","optional":false},{"name":"AWS Lambda","optional":false},{"name":"CI/CD","optional":false},{"name":"Claude","optional":false},{"name":"Claude Code","optional":false},{"name":"Cloudflare","optional":false},{"name":"DNS","optional":false},{"name":"Grafana","optional":false},{"name":"IAM","optional":false},{"name":"Kubernetes","optional":false},{"name":"Least Privilege","optional":false},{"name":"MySQL","optional":false},{"name":"OpenSearch","optional":false},{"name":"PostgreSQL","optional":false},{"name":"Prometheus","optional":false},{"name":"Python","optional":false},{"name":"Terraform","optional":false},{"name":"Confluence","optional":true},{"name":"Crowdstrike","optional":true},{"name":"Jira","optional":true},{"name":"SIEM","optional":true}],"status":"live","first_seen_at":"2026-10-02T18:29:06Z","employer_posted_date":null,"last_verified_at":"2026-10-02T18:29:06Z","board_verified":false,"closed_at":null,"days_open":8,"trust":{"level":"not_scored","repost_count":null,"flags":[],"days_open":8},"description":"Senior Cloud / AWS Infrastructure Engineer\nIT / Infrastructure | Full-Time, Salaried, Individual Contributor | Reports to Director of IT\nCompany Seeking.com (Reflex Media)Location Remote, anywhere in the USA. Compensation $130,000 to $180,000 base.Schedule Three evenings per week (5:30 to 7:30 PM US Pacific) to overlap with our Singapore Dev and DevOps partners. Flexed time available during the day.\nTravel Occasional travel to Las Vegas for planning, incident postmortems, and team weeks.\nAbout the RoleSeeking.com is the world's largest premium dating platform, founded and led by an MIT alumnus and headquartered in Las Vegas. We are hiring a Senior Cloud / AWS Infrastructure Engineer to build, operate, and secure the AWS environment that runs our products.\nThe environment is AWS Organizations with Control Tower, accounts vended through Account Factory for Terraform, and governance applied through global and per-account customization layers. Infrastructure is Terraform, delivered through a versioned in-house module library. Workloads run across ECS Fargate, Aurora MySQL and PostgreSQL, ElastiCache, EFS, Lambda, OpenSearch, Redshift, MWAA, and Bedrock, with Cloudflare at the edge.\nDisaster recovery. We are building cross-region DR for a flagship platform, essentially from the ground up. Today the platform is regionally concentrated. You will define the DR plan against real RPO and RTO targets, design and build the replication and failover path, and prove it with real exercises.\nSecurity engineering. Identity hardening, replacing static credentials with federated and role-based access, extending preventive and detective controls, and turning findings into engineering fixes.\nWho Should Apply\nSenior Cloud or Platform Engineers at consumer subscription, marketplace, or SaaS companies who have run AWS Organizations at scale.\n\nSite Reliability Engineers with a heavy IaC and security bias who have taken a regionally concentrated platform to cross-region DR.\n\nDevOps Engineers from a Terraform-first shop who own module libraries other teams depend on.\n\nCloud Security Engineers who built the guardrails, the SCPs, and the federated access patterns their org runs on today.\n\nWhat You Will DoCloud Architecture and Infrastructure as Code\n\nExtend the Terraform module library and the AFT customization layers (VPC and IPAM allocation, private hosted zones, SSM access, backup vaults, account baselines) so new accounts land secure and consistent by default.\n\nDesign VPC architecture, cross-account networking, and shared services in a hub-and-spoke configuration model.\n\nMigrate legacy brand infrastructure into the current account structure, state backend model, and module standards.\n\nDisaster Recovery\nDesign and build cross-region recovery for a flagship platform: Aurora replication topology, cross-region backup copy, S3 and EFS replication, container image distribution, DNS failover, and region-parity IaC.\n\nEstablish RPO and RTO targets with the business, map dependencies into recovery tiers, and define restoration order.\n\nStandardize backup policy and retention across the estate, including organization-level backup policy and centralized vaults.\n\nRun scheduled DR tests and game days, and write runbooks that make recovery repeatable by anyone on call.\n\nSecurity\nDesign least-privilege IAM policy and IAM Identity Center permission sets. Reduce standing access and direct assignments.\n\nReplace long-lived IAM access keys with federated SSO, OIDC, and assumed-role access, including in CI/CD.\n\nAuthor and maintain SCPs and organization controls, plus automated remediation where prevention is not possible.\n\nExtend detective controls: AWS Config rules and conformance packs, Security Hub standards coverage, GuardDuty feature coverage, and consistent finding handling across regions.\n\nOwn secrets management on Secrets Manager and SSM Parameter Store, including rotation.\n\nSupport incident response and CloudTrail forensics, and convert findings into durable engineering fixes.\n\nReliability and Automation\nOperate core infrastructure: monitoring, alerting, AWS Backup, and patch and lifecycle management.\n\nImprove our Prometheus, Grafana, and Alertmanager stack and its CloudWatch alarm coverage so real issues page quickly.\n\nDebug production issues across compute, storage, networking, and databases.\n\nAutomate operational work in Python and Bash, and improve CI/CD for infrastructure.\n\nKeep Control Tower and the landing zone current, and contribute to cost visibility and optimization.\n\nRequired Qualifications\nFive or more years building and operating production AWS infrastructure.\n\nStrong Terraform in a team setting: module design and versioning, remote state, drift, and PR-based workflows.\n\nMulti-account AWS Organizations or Control Tower experience, including SCPs and cross-account IAM.\n\nDeep IAM: policy and trust-policy design, permission boundaries, and least privilege in practice.\n\nProduction container experience on ECS or Kubernetes, and managed relational databases.\n\nPython or Bash for automation and tooling.\n\nExperience migrating or consolidating legacy infrastructure without downtime, and the judgment to sequence that work safely.\n\nClear writing, and the judgment to weigh risk, cost, and delivery speed against each other.\n\nDaily use of Claude, Claude Code, and Cowork in your engineering workflow. \n\nPreferred Qualifications\nAFT, Landing Zone Accelerator, or similar account-vending automation.\n\nIAM Identity Center or SAML / OIDC federation with an external IdP.\n\nDesigning and testing cross-region DR against defined RPO and RTO targets.\n\nAurora operations at scale: replication topology, failover, and backup and restore.\n\nSecurity Hub, GuardDuty, AWS Config, or SIEM-style CloudTrail analysis. EDR tooling such as CrowdStrike.\n\nAWS Backup at organization scale, including cross-region and cross-account copy.\n\nCloudflare or a comparable CDN and WAF at the edge.\n\nData or AI workloads on AWS (Redshift, MWAA, Bedrock).\n\nWorking with distributed teams across time zones.\n\nAWS certifications (Solutions Architect, SysOps, Security Specialty).\n\nBachelor's degree in Computer Science, Engineering, or a related field, or an equivalent operational track record.\n\nHow We Work\nInfrastructure is code, reviewed in pull requests.\n\nHuman access to AWS is federated through SSO, short-lived, and least privilege by default.\n\nSecurity, reliability, and cost are design inputs, not afterthoughts.\n\nWe fix the cause rather than automate around it.\n\nEngineering work is tracked in Jira. Decisions and runbooks live in Confluence.\n\nWhy This Role MattersSeeking.com serves more than 50 million members across more than 130 countries. The AWS environment behind that experience is what keeps the promise. This role is the senior engineer who makes sure a region-wide event does not become a member-facing event, and that our security posture matches the trust our members place in us. The work is consequential, the mandate is real, and the person who does it well earns more scope every quarter.\nCompensation and BenefitsBase salary: $130,000 to $180,000, commensurate with experience. \n99 percent coverage of medical, dental, and vision insurance. 65 percent coverage for qualified dependents. 100 percent coverage of short-term disability, long-term disability, and life insurance. 50 percent 401(k) match up to 6 percent per month. Flexible Spending Account. Flexible paid time off. Professional development budget covering AWS certifications and conferences.\nEqual Opportunity EmployerReflex Media is an equal opportunity employer committed to diversity and inclusion in the workplace. We strictly prohibit discrimination of any kind. Candidates are encouraged to apply for qualified positions regardless of race, color, sex, religion, sexual orientation, national origin, disability, genetic information, or any other protected characteristics as outlined by federal, state, or local laws. Hiring decisions are based solely on qualifications, merit, and the needs of the company. All offers of employment are contingent upon the completion of a full background and reference check.\n\nOriginally posted on Himalayas","description_format":"text","description_chars":8166,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Life insurance","Professional development","Vision insurance"],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":[],"lifecycle":[{"event":"open","at":"2026-10-02T21:03:06Z"}],"visa":[],"liveness":{"score":99,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.993,"p_room":1,"age_days":7,"expected_fill_days":33,"reasons":["seen:7","urgency","velocity","win:early"],"computed_at":"2026-10-10T05:45:15Z"},"pay":{"stated_usd_annual":180000,"is_top_pay":true},"html_url":"https://alion.io/job/reflex-media-senior-cloud-aws-infrastructure-engineer","json_url":"https://alion.io/job/reflex-media-senior-cloud-aws-infrastructure-engineer.json","meta":{"generated_at":"2026-10-11T00:54:47Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1225,"day_limit":5000,"remaining_today":3775,"minute_limit":60,"resets_at":"2026-10-12T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":3863845},"rest":"https://alion.io/mcp/rest/get_company?id=3863845"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Freflex-media-senior-cloud-aws-infrastructure-engineer"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Freflex-media-senior-cloud-aws-infrastructure-engineer"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Freflex-media-senior-cloud-aws-infrastructure-engineer"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/reflex-media-senior-cloud-aws-infrastructure-engineer\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Freflex-media-senior-cloud-aws-infrastructure-engineer"}]}