Position: Cloud/DevOps Engineer
About Aivar Innovations
Aivar is an AI-first technology partner where cutting-edge technology meets industry expertise to supercharge your projects.
Experience:
3–7 years | Strong AWS + Terraform required
Technical Focus:
Our accelerators get deployed into customer cloud accounts with strict compliance requirements (HIPAA, SOC 2, HITRUST). Own the full deployment and operations story: Terraform modules for customer provisioning, CI/CD pipelines, compliance-hardened configurations, observability stack, and multi-tenant network isolation.
Key Responsibilities:
- Build Terraform modules that provision the full accelerators stack in customer AWS accounts — repeatable, version-controlled, compliant.
- Implement compliance-hardened infrastructure — HIPAA-eligible configs, encryption at rest/transit, private endpoints, IMDSv2, audit logging.
- Design CI/CD pipelines — automated testing, container builds, staged rollouts, and rollback mechanisms.
- Configure observability stack — Prometheus, Grafana, FluentBit, OpenTelemetry with alerting.
- Design VPC architecture — private subnets, security groups, NACLs, NAT gateways, peering for customer deployments.
- Produce compliance evidence for SOC 2, HIPAA, HITRUST audits; automate evidence collection.
- Automate Day 2 operations — backup/restore, secret rotation, certificate management, patch management.
Must-Have Technical Skills:
- AWS deep expertise — VPC design, IAM policies, multi-account strategy (not surface-level).
- Terraform — modules, state management, workspaces, drift detection, CI/CD integration.
- Container orchestration — ECS (Fargate) or EKS, ECR, container security scanning.
- CI/CD design — GitHub Actions, CodePipeline, or equivalent.
- Security engineering — IAM, least-privilege, encryption, network segmentation, secrets management.
- Monitoring — Prometheus, Grafana, CloudWatch, alerting configuration.
- Experience deploying into customer/third-party cloud accounts.
Core Tech Stack:
Terraform, AWS (VPC, ECS/EKS, RDS, S3, Lambda, KMS, CloudTrail, Security Hub, GuardDuty), GitHub Actions, Docker/ECR, Prometheus/Grafana/FluentBit/OpenTelemetry, Bash, Python