Public job listings imported for Read-A-Thon. These roles were added via admin CSV import or external sources.
Reports to: Technical LeadershipLocation: Remote About the roleWe're looking for our first dedicated, in-house AWS/DevOps engineer to own infrastructure, reliability, and deployment tooling across a portfolio of live, revenue-generating products. You'll be the technical owner for cloud infrastructure spanning multiple AWS accounts, supporting several distinct applications with their own architectures and audiences —plus the shared services that cut across all of them. What you'll own• Multi-account AWS architecture — administer and harden a multi-account AWS Organization (production, development, and monitoring accounts) with least-privilege IAM, proper root/administrative credential hygiene, and durable secrets management (moving us off ad-hoc password storage and onto a real secrets manager).• Compute & scaling — manage EC2 fleets behind Application Load Balancers, Auto Scaling Groups, and launch templates backed by a golden-AMI deployment pipeline; modernize legacy standalone instances toward containerized (ECR/ECS) or otherwise more resilient patterns where it makes sense.• Databases — administer Amazon Aurora MySQL clusters (multi-database, multi-tenant schemas) including read replica strategy, credential scoping (moving application traffic off shared/master-level database users onto least-privilege service accounts), and CDC-based real-time data pipelines (Epsio) feeding BI and marketing systems.• Networking & access — operate a Tailscale-based zero-trust network (ACLs, subnet routers, tagged service identities) as our primary access layer, including migrating legacy DNS off a legacy registrar onto modern DNS/CDN infrastructure (Cloudflare / Route 53).• CI/CD — own and improve GitLab CI/CD pipelines (OIDC-based AWS role assumption, environment-scoped deploys, secrets-as-CI-variables) across a PHP monolith and a Laravel application; drive the migration of hardcoded application secrets into properly managed CI/CD variables and parameter stores.• Observability & incident response — build out real monitoring where gaps exist today (CloudWatchLogs/Alarms/Synthetics, external uptime monitoring, WAF logging), define on-call/runbook practices, and lead incident response for production issues, including root-cause writeups.• Security posture — manage AWS WAF rules, resolve longstanding dependency/composer security advisories, own certificate lifecycle management (TLS, Apple Pay/payment-processing certs), and generally reduce the accumulated operational risk of a fast-growing, historically under-resourced infrastructure.• Cross-team support — work directly with a small in-house engineering team and outside contractors, and interface with third-party MSPs supporting sibling properties.Our stack (what you'll actually touch)• AWS: EC2, Aurora MySQL (RDS), Application Load Balancer, Auto Scaling Groups, S3, Storage Gateway, ElastiCache (Memcached), CloudWatch (Logs, Alarms, Synthetics, Internet Monitor), Systems Manager (Session Manager, Parameter Store), IAM & AWS Organizations, SES, WAFv2, CloudFormation• Application layers: Legacy PHP (no framework) and Laravel (PHP framework); Apache/PHP-FPM and nginx; Composer dependency management• Data & BI: Aurora MySQL, Epsio (CDC/real-time materialized views), Sigma (BI), Metabase (legacy BI, being retired)• Networking: Tailscale (zero-trust mesh VPN, ACL policy management), Cloudflare (DNS/CDN), legacy DNS providers (migration in progress)• CI/CD & tooling: GitLab CI/CD, OIDC-based cloud role assumption, PhpStorm/JetBrains tooling, LastPass (transitional— a real secrets manager is part of the roadmap)• Third-party integrations: Payment processing (CardPointe/CardConnect, Apple Pay, Google Pay, PayPal), SMS/messaging (Twilio, Plivo), CRM/marketing (HubSpot), accounting exports What you bring• 5+ years in a DevOps/SRE/Infrastructure role with deep, hands-on AWS experience (not just "used AWS" — configuredIAM policies, debugged Aurora replication, tuned Auto Scaling, written CloudFormation/Ter