A Belgian public finance organisation is building a secure hybrid cloud platform to standardise how internal teams deploy services on AWS. This role exists to expand a small delivery team working on an AWS landing zone, infrastructure as code using Terraform and CloudFormation, and the runtime platform for Kubernetes workloads. The position requires hands-on familiarity with AWS, CDK/CloudFormation, Terraform, GitLab CI/CD and cloud security practices.
The mission
The immediate project is to design and implement a robust, compliant AWS landing zone that connects two-way with the organisation's on-prem datacenters and supports containerised and Java-based applications. The technical landscape includes AWS accounts governed by SCPs, an external SSO integrated via AWS Identity Center, centralized logging and archiving, and encryption and data classification controls to meet NIS2 and ISO 27001 requirements.
As the medior cloud engineer you will work in a small team composed of two senior cloud architects and other internal ICT Service Operations and ICT Service Delivery engineers. Your day-to-day will include building IaC modules and golden-path templates in Terraform/CloudFormation or CDK, implementing GitLab CI/CD pipelines, and operating Kubernetes clusters and cross-account network setups so internal teams can deploy reliably. You will also document patterns and run knowledge-sharing sessions with platform users.
Your responsibilities
- Design and deliver a secure AWS landing zone using Terraform, CloudFormation or CDK, ensuring repeatable account bootstrap and SCP governance.
- Implement and maintain GitLab CI/CD pipelines that provision infrastructure and deploy platform components, reducing deployment lead time for application teams.
- Configure identity and access flows, integrating an external SSO via AWS Identity Center and enforcing least-privilege through SCPs and IAM patterns.
- Implement logging, archiving and backup strategies and enforce data classification and encryption policies to support NIS2 and ISO 27001 compliance.
- Build golden-path Terraform templates and reusable IaC modules to accelerate internal teams and lower operational errors.
- Collaborate with senior architects and operations teams, delivering runbooks, onboarding sessions and code reviews to raise platform adoption.
Your profile
Essential skills
- Proven experience designing and operating workloads on AWS with hands-on use of Terraform and/or CloudFormation/CDK.
- Practical knowledge of GitLab CI/CD pipelines and experience automating infrastructure delivery.
- Solid understanding of cloud security controls, SCPs, IAM patterns, encryption and data classification.
- Experience with Kubernetes and running containerised applications in production, familiarity with Java-based services is a plus.
- Ability to work in a small multidisciplinary team and communicate infrastructure patterns clearly to application teams.