Position: Cloud/DevOps Engineer

About Aivar Innovations

Aivar is an AI-first technology partner where cutting-edge technology meets industry expertise to supercharge your projects.

Experience:

3–7 years | Strong AWS + Terraform required

Technical Focus:

Our accelerators get deployed into customer cloud accounts with strict compliance requirements (HIPAA, SOC 2, HITRUST). Own the full deployment and operations story: Terraform modules for customer provisioning, CI/CD pipelines, compliance-hardened configurations, observability stack, and multi-tenant network isolation.

Key Responsibilities:

  • Build Terraform modules that provision the full accelerators stack in customer AWS accounts — repeatable, version-controlled, compliant.
  • Implement compliance-hardened infrastructure — HIPAA-eligible configs, encryption at rest/transit, private endpoints, IMDSv2, audit logging.
  • Design CI/CD pipelines — automated testing, container builds, staged rollouts, and rollback mechanisms.
  • Configure observability stack — Prometheus, Grafana, FluentBit, OpenTelemetry with alerting.
  • Design VPC architecture — private subnets, security groups, NACLs, NAT gateways, peering for customer deployments.
  • Produce compliance evidence for SOC 2, HIPAA, HITRUST audits; automate evidence collection.
  • Automate Day 2 operations — backup/restore, secret rotation, certificate management, patch management.

Must-Have Technical Skills:

  • AWS deep expertise — VPC design, IAM policies, multi-account strategy (not surface-level).
  • Terraform — modules, state management, workspaces, drift detection, CI/CD integration.
  • Container orchestration — ECS (Fargate) or EKS, ECR, container security scanning.
  • CI/CD design — GitHub Actions, CodePipeline, or equivalent.
  • Security engineering — IAM, least-privilege, encryption, network segmentation, secrets management.
  • Monitoring — Prometheus, Grafana, CloudWatch, alerting configuration.
  • Experience deploying into customer/third-party cloud accounts.

Core Tech Stack:

Terraform, AWS (VPC, ECS/EKS, RDS, S3, Lambda, KMS, CloudTrail, Security Hub, GuardDuty), GitHub Actions, Docker/ECR, Prometheus/Grafana/FluentBit/OpenTelemetry, Bash, Python