Role Description
Own the internal cloud infrastructure and serve as the primary point of contact for cloud operations and infrastructure requests.
-
Manage and continuously improve our multi-account cloud environment, ensuring security, governance, and compliance best practices are consistently applied.
-
Support and maintain compliance with SOC 2 Type II and ISO 27001, ensuring audit evidence is prepared continuously rather than only during audit periods.
-
Operate and improve our identity and access management, including SSO, MFA, permissions, and joiner/mover/leaver processes.
-
Maintain and monitor self-hosted internal services, ensuring they meet agreed service levels and that vulnerabilities are tracked and resolved efficiently.
-
Monitor the security and health of our cloud environment through continuous posture management and proactive risk identification.
-
Own infrastructure cost management for the services under your responsibility and help other teams proactively identify cost or reliability risks before they become issues.
-
Collaborate with engineering teams to improve the reliability, scalability, and operational excellence of our cloud platform.
Qualifications
-
Deep AWS at org level: Organizations, Control Tower, multi-account landing zones, IAM/SCPs, Security Hub/GuardDuty, VPC and multi-AZ networking.
-
IaC as the only way infrastructure gets created - module design, state management, review and promotion between environments. Tool-agnostic, but real depth in at least one (Terraform/OpenTofu, CDK, Pulumi).
-
Understands how to evolve existing systems toward compliance - can look at a running estate and work out what has to change, in what order, to satisfy SOC 2 / ISO 27001.
-
Having been through an audit or certification is a bonus, not a requirement.
-
Internal workforce identity and access: IdP-backed SSO/MFA, centralised access management, automated joiner/mover/leaver.
-
Self-hosting and operating shared internal tooling that other teams depend on - deploy, upgrade, back up, own the uptime.
-
Observability and alerting design, plus on-call for a distributed team.
-
Cloud cost management / FinOps fundamentals.
-
Azure is a nice-to-have extension, not a requirement - AWS depth is what matters, but the estate is going multi-cloud so appetite for it counts.
-
Bash, Python and/or Go for tooling. Comfortable with ambiguity in a remote-first environment, and happy being the first hire in a function.
Values
-
Care: we create with compassion. We prioritize empathy and understanding in every interaction.
-
Ownership: we own the outcome. We take responsibility for our work and are passionate about its impact.
-
Openness: we build trust together. We build trust through open communication and honest feedback.
-
Courage: we dare to innovate. We embrace bold challenges and take calculated risks to move the needle.
-
Excellence: we chase the extraordinary. We chase excellence by pushing boundaries and delivering results that go beyond the ordinary.
Application Process
To apply, follow the application process. Make sure to include a short motivation outlining why you are the perfect candidate for this role. If your profile looks like a good match, our talent team will be in touch to organize further steps within 2 weeks. Please note, that due to a high volume of candidates, we cannot offer personalized feedback to each candidate.