For Employers
Apply Now

Please mention DailyRemote when applying

?
Resume Match Score

See how much of this job your resume covers, and what’s missing.

Want a recruiter to go through it line by line?

Get professional review

Create a cover letter for this job

Upload your resume and we draft a letter for this exact role, tailored to what it asks for.

  • Tailored to this role
  • Based on your resume
  • Fully editable
AI Summary

You will build and manage a secure, HIPAA-compliant AWS landing zone and Kubernetes platform from the ground up. You are responsible for leading the platform engineering efforts, ensuring system availability, and facilitating a successful handover to the client.

Senior Platform Engineer (Lead)

AWS landing zone and Kubernetes platform for a HIPAA-regulated public-health data platform · Remote (U.S.)

We're looking for a senior platform engineer to build, from the first line of code, the AWS platform that will carry rural health data, and then run it in production. You'll own the landing zone and Kubernetes platform behind the project, a cloud-based, open-source semantic data model. The project will harmonize EHR, claims and public-health data into one computable form and serves it through FHIR APIs.

The platform holds protected health information. It is held to NIST SP 800-53 moderate controls and the HIPAA Security Rule, with 99.9% availability, a 15-minute RPO, a 4-hour RTO and a seven-year tamper-evident audit log. You'll build it alongside a dedicated DevSecOps engineer, and by the end of the term the whole environment must be rebuildable from code and ready to hand to the Client.

THE ROLE AT A GLANCE

Engagement

1099 independent contractor; you work as part of HK's team

Term

Mid-October 2026 through September 2027; a second year is possible, subject to funding

Commitment

Full time, 40 hours a week

Reports to

HK's Software/Development Director, with architecture direction from the program architect and security direction from the HIPAA Security Officer

Location

Remote within the U.S.; core hours 9:00 a.m.–3:00 p.m. Mountain; occasional travel to Salt Lake City

Requirements

U.S. work authorization; background check before production access; HIPAA training before any access

Stack

AWS (us-west-2, DR in us-east-2), EKS on Bottlerocket, Aurora PostgreSQL, MSK, S3 Object Lock, Keycloak, OpenSearch, OpenTofu, GitOps

WHAT YOU'LL DO

You take the platform from the first OpenTofu module to a production environment with a warm DR standby by spring, and you're the person who can rebuild it all from code.

  1. Build the AWS Organization as code: separate accounts for management, security, log archive, sandbox, test, staging and production, plus OUs, IAM Identity Center with MFA, and organization-wide CloudTrail and Config.
  2. Design the network: private-only VPCs across three AZs, egress inspected through Network Firewall, Transit Gateway, VPC endpoints, and Client VPN. You'll also set the partner connectivity patterns (site-to-site VPN, PrivateLink, mTLS with a private CA).
  3. Run Amazon EKS: private endpoint, Bottlerocket nodes with Karpenter, pod security standards, Cilium network policies, upgrades, and capacity and cost tuning for Kafka and Spark.
  4. Operate the data services: Aurora PostgreSQL (TLS, PITR, Global Database), MSK, S3 zones with Object Lock and cross-region replication, ECR, Secrets Manager and AWS Backup, plus Keycloak, Prometheus and OpenTelemetry on the cluster.
  5. Own the delivery pipeline: GitHub Actions with OIDC to AWS, OpenTofu plan and apply with policy gates, Argo CD, Helm conventions and Kyverno admission. Shipping should be easy for every engineering team on the program.
  6. Keep it running: write the runbooks, lead the monthly restore drill and the annual cold-rebuild test, take on-call for severity-1 platform incidents (15-minute acknowledgment), and run post-incident reviews.
  7. Report and hand over: report monthly on availability, capacity and tagged AWS spend. You'll prove portability on open-source equivalents (MinIO, Nessie, self-managed PostgreSQL) and hand the platform to the Client's team with documentation they can run it from.
  8. Lead: guide a second platform engineer day to day and review the DevSecOps engineer's infrastructure changes. You'll be able to cover each other's on-call.

YOUR FIRST 30 DAYS

The first three weeks are the critical path for the whole program. You'll pair with the DevSecOps engineer to stand up the landing zone, then hand it to the application teams.

Week

What success looks like

Week 1

Organization, accounts, SCPs, org-wide logging and security services live; KMS key plan applied

Week 2

Sandbox VPC, EKS, Aurora, MSK, S3, ECR and Keycloak provisioned from code; Client VPN working

Week 3

OpenSearch SIEM baseline, CI/CD with signing and policy gates, Argo CD syncing, cost budgets and tags; platform handed to engineering

Week 4

Test environment built from the same modules; first partner connectivity pattern documented; first monthly cost report

WHAT YOU BRING

  1. 7+ years in infrastructure or platform engineering, including 4+ years running production Kubernetes on AWS (EKS strongly preferred).
  2. Deep Terraform or OpenTofu: multi-account organizations, modules, remote state, and policy as code (OPA, Checkov or tfsec). You've built an AWS Organization from zero before.
  3. Hands-on with VPC design, Transit Gateway, Network Firewall, PrivateLink, IAM Identity Center, KMS, Aurora PostgreSQL, MSK or Kafka, S3 Object Lock, ECR and AWS Backup.
  4. GitOps and CI: Argo CD or Flux, Helm, GitHub Actions, container image signing and SBOMs.
  5. Observability: Prometheus and Grafana, OpenTelemetry, and log shipping to OpenSearch or Elasticsearch.
  6. You've operated a regulated workload (HIPAA, FedRAMP, PCI or similar) and can explain what the regulation changed about the design.
  7. You write clear runbooks and ADRs, and you're comfortable leading and reviewing the work of one or two engineers.

NICE TO HAVE

  1. Karpenter and Bottlerocket in production; Cilium or Calico network policy.
  2. Spark on Kubernetes and Iceberg tables; Strimzi or MSK operations at scale.
  3. Keycloak or another OIDC provider; Kyverno or Gatekeeper.
  4. AWS Solutions Architect or DevOps Engineer Professional; CKA or CKS.
  5. Public-sector or healthcare delivery, and experience handing a platform over to a client team.

Automatically Apply to the Best Remote Jobs

Stop the endless job search. Our AI finds and applies to the best jobs for you.

Try it Now
Keep looking

Similar Jobs

See all Remote Software Development jobs →

District Systems Engineer

Full Time United States Software Development

Cortex Cloud Sales Specialist

Full Time United States Software Development

Solutions Engineer, Enterprise Accounts - Central

Full Time United States Software Development

Sr. Technical Product Engineer

Full Time United Kingdom Software Development

Senior Manager, GTM - Strata Cloud Manager

Full Time United States $167K - $270K per year Software Development

AI Security Sales Specialist

Full Time France Software Development
Apply Now

Personalize your Remote Job Search in 3 Easy Steps!

Featuring 217,591+ Jobs in Platform Engineer

Answer easy questions

Answer easy questions

217,591+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified