Role Description
We're looking for a senior platform engineer to build, from the first line of code, the AWS platform that will carry rural health data, and then run it in production. You'll own the landing zone and Kubernetes platform behind the project, a cloud-based, open-source semantic data model. The project will harmonize EHR, claims and public-health data into one computable form and serves it through FHIR APIs.
The platform holds protected health information. It is held to NIST SP 800-53 moderate controls and the HIPAA Security Rule, with 99.9% availability, a 15-minute RPO, a 4-hour RTO and a seven-year tamper-evident audit log. You'll build it alongside a dedicated DevSecOps engineer, and by the end of the term the whole environment must be rebuildable from code and ready to hand to the Client.
Qualifications
-
7+ years in infrastructure or platform engineering, including 4+ years running production Kubernetes on AWS (EKS strongly preferred).
-
Deep Terraform or OpenTofu: multi-account organizations, modules, remote state, and policy as code (OPA, Checkov or tfsec).
-
Hands-on with VPC design, Transit Gateway, Network Firewall, PrivateLink, IAM Identity Center, KMS, Aurora PostgreSQL, MSK or Kafka, S3 Object Lock, ECR and AWS Backup.
-
GitOps and CI: Argo CD or Flux, Helm, GitHub Actions, container image signing and SBOMs.
-
Observability: Prometheus and Grafana, OpenTelemetry, and log shipping to OpenSearch or Elasticsearch.
-
Experience operating a regulated workload (HIPAA, FedRAMP, PCI or similar) and can explain what the regulation changed about the design.
-
Ability to write clear runbooks and ADRs, and comfortable leading and reviewing the work of one or two engineers.
Requirements
-
U.S. work authorization; background check before production access; HIPAA training before any access.
-
Stack: AWS (us-west-2, DR in us-east-2), EKS on Bottlerocket, Aurora PostgreSQL, MSK, S3 Object Lock, Keycloak, OpenSearch, OpenTofu, GitOps.
Benefits
-
Engagement as a 1099 independent contractor; you work as part of HK's team.
-
Term: Mid-October 2026 through September 2027; a second year is possible, subject to funding.
-
Commitment: Full time, 40 hours a week.
-
Reports to: HK's Software/Development Director, with architecture direction from the program architect and security direction from the HIPAA Security Officer.
-
Location: Remote within the U.S.; core hours 9:00 a.m.β3:00 p.m. Mountain; occasional travel to Salt Lake City.
Your First 30 Days
-
Week 1:
Organization, accounts, SCPs, org-wide logging and security services live; KMS key plan applied.
-
Week 2:
Sandbox VPC, EKS, Aurora, MSK, S3, ECR and Keycloak provisioned from code; Client VPN working.
-
Week 3:
OpenSearch SIEM baseline, CI/CD with signing and policy gates, Argo CD syncing, cost budgets and tags; platform handed to engineering.
-
Week 4:
Test environment built from the same modules; first partner connectivity pattern documented; first monthly cost report.
Nice to Have
-
Karpenter and Bottlerocket in production; Cilium or Calico network policy.
-
Spark on Kubernetes and Iceberg tables; Strimzi or MSK operations at scale.
-
Keycloak or another OIDC provider; Kyverno or Gatekeeper.
-
AWS Solutions Architect or DevOps Engineer Professional; CKA or CKS.
-
Public-sector or healthcare delivery, and experience handing a platform over to a client team.