remotely.living

Cloud Engineer AWS ( CDK / Serverless) ( 102-09SENG-01 )

OpsBrasil Serviços Cloud LTDA · Remote - Worldwide · contract · 2026-09-20

Apply for this job

Job description

This role modifies a live serverless gateway in production — no downtime, no change in behaviour — leaving a clean handoff point for a downstream build managed in Terraform. This is careful surgery on production infrastructure with active external consumers, not a greenfield build.

The scope includes modernizing a CDK estate made up of four stacks, six Lambda functions, a WAF web ACL, an mTLS custom domain/truststore, and a REST API — preserving resource identity during consolidation and coordinating two sequenced deployments with a tested rollback path.

What you will do

- Inventory the CDK estate and build a modernization plan: upgrade the CDK library/CLI, replace deprecated constructs, move hardcoded context into per-environment config.

- Consolidate duplicated stacks into shared constructs without losing resource identity — map logical IDs before and after, pick a preservation method, and confirm nothing gets replaced before touching production.

- Run the library upgrade and the stack refactor as two separate, ordered deployments, with a rollback path tested in dev and test first.

- Migrate all six Lambda functions from Node 18 to Node 24, close an open PII logging finding, and regression-test each one.

- Re-verify the security perimeter after both deployments — WAF, the mTLS domain and truststore, X-Ray tracing, upstream timeouts — working directly with the customer's POS team across all six external callers.

- Build deployment pipelines for dev/test/prod with OIDC federation, approval gates, and a ServiceNow change step. Add CDK assertion tests, drift detection, and API access log retention.

- Publish the SQS queue ARN and KMS key ARN via Parameter Store, and grant send permission to the downstream Terraform-managed system — this is the key ordering dependency for that team's build.

- Align naming, tagging, and documentation with the customer's internal standards, and document your identity-preservation decisions clearly enough for the next engineer to follow.

Requirements

- 5+ years with AWS, including 3+ years working in infrastructure-as-code.

- Hands-on AWS CDK experience in TypeScript — construct trees, logical ID derivation, and what happens when a construct path changes.

- Real experience with CloudFormation resource identity: stack refactoring, logical ID overrides, cdk diff against deployed state, drift detection.

- Working Terraform knowledge — comfortable operating across the CDK/Terraform boundary.

- Solid AWS serverless background: Lambda, API Gateway (REST), SQS and DLQs, Parameter Store, KMS, Secrets Manager.

- Experience with AWS edge and security services — WAF web ACLs, mutual-TLS custom domains and truststores, cross-account/cross-boundary IAM.

- Practical experience migrating Nodejs runtimes (e.g. Node 18 → 24), including dependency and deprecation handling.

- CI/CD pipeline experience with OIDC federation and approval gates (GitHub Actions or equivalent).

- Working knowledge of observability tools — X-Ray, CloudWatch metrics and alarms, log retention.

- Comfortable communicating clearly with non-engineers, and working well when parts of the scope are still being figured out.

- Fluent English (C1 level) for daily communication with the client.

Engagement details

- Hourly contractor

- 100% remote

- Estimated duration: 6–8 weeks

- Time zone: EST or MST

Highlights

AWS CDK, CloudFormation, Terraform, AWS Serverless (Lambda, API Gateway REST, SQS/DLQ, Parameter Store, KMS, Secrets Manager), AWS Edge & Security (WAF, mTLS, cross-account IAM), Node.js, CI/CD

Originally posted on Himalayas