Logo for Viaduct

Forward-Deployed Engineer - AWS Platform / SRE Engineer

Role overview

Qualifications

  • Real AWS ops/admin depth - you've architected and run production AWS environments, not just consumed one someone else built
  • Strong Infrastructure-as-Code chops (Terraform, Terragrunt, or similar)
  • Proficiency with Kubernetes (Helm, Kustomize, kubectl) and GitOps patterns (Argo CD, Flux, or similar)
  • Experience building CI/CD pipelines (GitHub Actions, Argo Workflows, or similar)

Responsibilities

  • Architect and build an independent AWS environment for the team - landing zone, networking, IAM, security
  • Install, configure, and integrate new platform capabilities as the team needs them (e.g., Dagster OSS on Kubernetes workers, CI/CD integration)
  • Build and maintain a paved path for deploying internal Python/TS web app prototypes, including external exposure and Okta-based access control
  • Own observability, reliability, and cost-effectiveness for everything running in production

About the company

Viaduct logo

Viaduct

Computer Software / SaaS

www.viaduct.ai

Company details

Company typeStartup
IndustryComputer Software / SaaS
Company size11 - 50

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

About Us

Viaduct builds production-grade AI systems for the world's manufacturers: not pilots, not proofs of concept. The Internal Efficiencies team is deploying real AI use cases inside one of Japan's largest manufacturers - a modern cloud and AI stack, shipped all the way down to a plant floor running robots, lasers, and IoT gear most software teams never get near.

We're a new team building fast. Viaduct already has a sophisticated, battle-tested platform - AWS landing zone, Terraform, AKS, Postgres, ClickHouse, Argo, observability - with genuinely great bones. But that platform was built to host production SaaS applications, and our team's needs don't look like that. We need our own environment, built on the lessons of what already exists, but shaped around how we actually work: fast iteration, new tooling, production use cases shipping constantly.

 

Who You Are

You're an infrastructure engineer who treats AWS as something you architect and own, not something you're handed. You've built a cloud environment from scratch - landing zone, networking, IAM, the works - and you know the difference between copying a pattern and understanding why it exists. You're equally comfortable in the DevOps/DevEx world: CI/CD, GitOps, Kubernetes, making other engineers faster. And once things are live, you don't walk away - you watch them, you look for what's about to break, and you fix it before it does.

You like being a force multiplier. You'd rather build the paved road once than answer the same infra question five times.

 

About the Role

You'll work directly with the head of Internal Efficiencies and effectively own infrastructure for the team - currently 6+ people including 4 engineers, with plans to double engineering headcount or more over the next year as we take on more production use cases.

This is a build-from-scratch role with an unusually strong reference platform next door. You'll stand up an independent AWS environment purpose-built for how our team operates, informed by (but not constrained to) the existing hub-and-spoke Terraform setup. From there, you'll install and integrate the tools that let the team ship: a Dagster OSS agent running on Kubernetes workers, wired into CI/CD; a paved path for deploying "ordinary" Python/TypeScript prototype web apps with external access and Okta integration; and the observability and cost discipline to keep it all sane as it scales.

Once things are in production - and with this team, things go to production fast - you're the one proactively watching them: looking for robustness gaps, scalability limits, and cost inefficiencies before they become incidents, and building the automation that keeps the rest of the team out of the weeds.

This isn't a role where you disappear into infrastructure and hand down decrees. You'll work hand-in-hand with IE engineers, product managers, and leadership to understand what's actually being built and where it's headed, and with the wider Viaduct engineering org to stay aligned with (and pull forward, where it makes sense) the platform patterns they've already proven out. You own the infrastructure decisions - but you make them in the open, with the people who depend on them.

 

What You'll Do

  • Architect and build an independent AWS environment for the team - landing zone, networking, IAM, security - informed by Viaduct's existing best-practices infrastructure but designed for our own needs
  • Install, configure, and integrate new platform capabilities as the team needs them (e.g., Dagster OSS on Kubernetes workers, CI/CD integration)
  • Build and maintain a paved path for deploying internal Python/TS web app prototypes, including external exposure and Okta-based access control
  • Own observability, reliability, and cost-effectiveness for everything running in production
  • Proactively identify and close robustness, scalability, and operational gaps before they become incidents
  • Build automation that removes infrastructure toil from the rest of the team
  • Ensure production systems are secure, backed up, and kept current with minimal downtime
  • Partner closely with IE engineers, product managers, and leadership on infrastructure needs and tradeoffs, and with the wider Viaduct engineering org to stay aligned with broader platform direction

 

What We're Looking For

  • Real AWS ops/admin depth - you've architected and run production AWS environments, not just consumed one someone else built
  • Strong Infrastructure-as-Code chops (Terraform, Terragrunt, or similar)
  • Proficiency with Kubernetes (Helm, Kustomize, kubectl) and GitOps patterns (Argo CD, Flux, or similar)
  • Experience building CI/CD pipelines (GitHub Actions, Argo Workflows, or similar)
  • Comfort owning infrastructure decisions independently, with imperfect information, on a small and fast-moving team
  • Bonus: experience with Dagster, ClickHouse/Postgres administration, or Okta/SSO integration

 

Security and Privacy Responsibilities

  • Member of the CSIRT Team
  • Follow our policy and procedure documents related to security and privacy
  • Follow the guidelines in the Employee Handbook
  • Participate in new hire and annual training for security and privacy
  • Treat data security and privacy as one of your primary job responsibilities
  • Report Security Incidents you discover as bugs
  • Get approval from the Security Team before adding new 3rd party software to our codebase
  • Explicitly consider security implications when doing PR reviews

 

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Platform Engineer Related jobs

Other jobs at Viaduct

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.