Senior Platform Engineer
SmarshIndiaFull-Time1w ago
AWSSecurityComplianceLegalCommunicationsGrowthSolutionsCommunityEngineeringInfrastructurePlatformReliability
Job description
Senior Platform Engineer at Smarsh.
About the role
Smarsh helps organizations in regulated industries manage digital communication risks. This role involves designing, building, and operating secure, scalable hybrid cloud network infrastructure on AWS. You will focus on automation, reliability, and operational excellence, working with platform, security, and infrastructure teams.
Key facts
What you'll do
- Design and implement secure, scalable AWS network architectures, including VPCs, subnets, and routing.
- Architect hybrid connectivity solutions using Direct Connect, VPNs, and Transit Gateways.
- Implement firewall strategies with Network ACLs, Security Groups, AWS Network Firewall, and WAF rules.
- Develop and maintain Terraform modules for AWS infrastructure with embedded security guardrails.
- Partner with the Infosec team to establish and enforce Terraform coding standards and security controls.
- Automate firewall rule provisioning, updates, and operational tasks using Python and shell scripting.
- Audit, maintain, and troubleshoot firewall rules and security controls, including optimization and incident response.
- Design and implement monitoring and alerting solutions using DataDog, Prometheus, and AWS CloudWatch.
- Lead troubleshooting for complex network and platform issues and participate in on-call rotations.
Requirements
- Bachelor's degree in Computer Science/Engineering or equivalent professional experience.
- 6-8 years of experience in platform engineering, SRE, or cloud engineering, with a strong focus on AWS networking.
- Expertise with AWS networking services such as VPCs, subnets, Transit Gateways, Route 53, Direct Connect, and VPNs.
- Strong system design and troubleshooting capabilities.
- Hands-on experience architecting hybrid on-premises to AWS connectivity.
- Practical experience with firewall operations, including AWS Network Firewall, NACLs, Security Groups, and WAF in production environments.
- Proficiency with Infrastructure as Code, primarily Terraform, with exposure to CloudFormation.
- Programming skills in Python and Bash/Shell scripting.
- Solid understanding of Linux fundamentals and networking concepts like TCP/IP, routing, and DNS.
- Willingness to provide on-call operational support.
Nice to have
- AWS Advanced Networking - Specialty Certification.
- Experience with Kubernetes or service mesh networking (Istio, Envoy).
- Familiarity with multi-account AWS organization management.
- Experience with CI/CD platforms like GitLab CI, GitHub Actions, or Jenkins.
- Knowledge of monitoring and observability tools such as Prometheus or the ELK stack.
- Understanding of compliance frameworks like SOC 2 or ISO 2700.
Skills & tools
- AWS Networking: VPC, peering, subnets, Transit Gateways, Route 53, Direct Connect, VPNs, AWS PrivateLink, IPAM.
- Firewall Operations: NACLs, Security Groups, AWS Network Firewall, WAF, firewall rule management.
- AWS Services: EC2, RDS, ECS/EKS, Lambda, IAM, CloudFormation, S3.
- Infrastructure as Code: Terraform, CloudFormation.
- Programming: Python, Bash/Shell scripting.
- Monitoring: DataDog, Prometheus, AWS CloudWatch.
- Operating Systems: Linux.
Practical notes
- This role involves participation in an on-call rotation.