AWS Infrastructure Engineer (Architect-Level) — RHEL 7 to RHEL 8 Migration
Overview
The AWS Infrastructure Engineer supports the Operations workstream of a large federal client's technology operations, maintenance, and enhancement program, providing infrastructure architecture and automation for a RHEL 7 to RHEL 8 server migration. This is an architect-level role: the engineer designs the AWS infrastructure-as-code approach and CI/CD automation that the delivery team executes, rather than performing day-to-day, hands-on-keyboard configuration.
Working alongside the Solutioning Architect, DevOps Engineers, and Systems Engineers, this person architects the AWS account structure, instance provisioning, and network connectivity needed to stand up RHEL 8 servers across multiple non-production and production environments, and defines the Infrastructure-as-Code (Terraform, AWS CloudFormation) templates and standards used to build and repeat that migration across each environment tier. The role also owns the architecture for automating the CI/CD pipeline that builds, tests, and promotes infrastructure and application changes up through Production.
Success in this role requires deep, architecture-level expertise in AWS infrastructure and Infrastructure-as-Code (Terraform and/or CloudFormation), strong familiarity with DevSecOps and Agile delivery practices, and the ability to translate migration requirements into a solution design that aligns with the client's governance and security standards.
Key Functions
- Architect the AWS Infrastructure-as-Code approach (Terraform, CloudFormation) used to stand up and configure RHEL 8 servers across multiple non-production and production environments.
- Design AWS account structure, EC2 instance provisioning, VPC configuration, and network connectivity needed to support the RHEL 7 to RHEL 8 migration.
- Account for the system's 30+ internal and external partner integrations when designing secure interface patterns for a FedRAMP-authorized (GovCloud) environment, ensuring those patterns are repeatable across the full range of non-production and production environment tiers.
- Own the architecture for automating the CI/CD pipeline (e.g., Jenkins, GitHub) that builds, tests, and deploys infrastructure and application changes up through Production.
- Define reusable Terraform and CloudFormation templates and IaC standards to ensure consistency and repeatability as the migration approach is repeated across each environment tier.
- Help define the environment tier build-out sequence and validation strategy — determining which environment tier is stood up and migrated first and how it is validated before promoting the migration to the next tier.
- Provide technical direction and design review to DevOps Engineers and Systems Engineers executing infrastructure automation and RHEL 8 server configuration.
- Support the architecture for standing up and configuring RDS instances as part of the environment migration, in coordination with the Database Administrator.
- Support planning for Jenkins job migration and DNS cutover (F5) activities at an architecture and design level.
- Incorporate vulnerability and cloud security posture scanning (e.g., Nessus, Turbot) into the infrastructure architecture.
- Participate in and help lead technical discovery and design sessions with application, infrastructure, security, and cloud engineering stakeholders.
- Ensure infrastructure designs comply with the client's technical reference model, ATO/POA&M requirements, and DevSecOps best practices.
- Help evaluate which existing POA&Ms are addressed or closed as a result of the RHEL 7 to RHEL 8 migration.
- Support performance testing, monitoring, and remediation activities by providing infrastructure-level analysis and recommendations.
- Document architecture decisions, infrastructure designs, and runbooks in Confluence and Jira.
- Coordinate with the Solutioning Architect and Operations Manager to ensure infrastructure delivery aligns with the overall migration timeline.
- Maintain positive working relationships with the federal client, delivery teams, and technical stakeholders while supporting mission-critical systems.
Minimum Qualifications
- Bachelor’s degree and 5 years of relevant experience.
- An additional 2 years of experience (7 years total) with an Associate’s Degree in lieu of a Bachelor’s Degree.
- An additional 4 years of experience (9 years total) with a High School Diploma in lieu of a Bachelor’s Degree.
- Demonstrated experience architecting AWS infrastructure using Infrastructure-as-Code, with hands-on expertise in Terraform and AWS CloudFormation.
- Experience designing and automating CI/CD pipelines that deploy changes up through Production (e.g., Jenkins, GitHub/GitHub Actions).
- Experience architecting AWS account structures, VPCs, instance provisioning, and network connectivity.
- Experience designing secure integration and interface patterns within a FedRAMP-authorized (GovCloud) environment.
- Experience with Red Hat Enterprise Linux (RHEL) server infrastructure, including OS version migrations.
- Experience incorporating vulnerability and cloud security posture management scanning (e.g., Nessus, Turbot) into infrastructure architecture and design.
- Experience supporting DevSecOps practices and Agile delivery.
- Ability to translate infrastructure and migration requirements into architecture-level solution designs and documentation.
- Strong analytical and technical leadership skills — this is an architecture- and design-focused role that provides technical direction rather than day-to-day, hands-on configuration.
- Excellent verbal and written communication skills, with the ability to lead technical discussions across cross-functional and federal stakeholder teams.
- Strong attention to detail and organizational skills.
Preferred Qualifications or Skills
- Experience supporting federal government systems.
- Experience with AWS RDS / PostgreSQL infrastructure.
- Experience automating certificate renewal and installation using Venafi.
- Familiarity with federal agency technical reference models and ATO/POA&M processes.
- AWS certification (e.g., AWS Certified Solutions Architect – Professional).
- Experience using Jira and Confluence, including version-controlled documentation practices.
- Experience supporting large-scale server or operating system migration projects.
- Familiarity with F5 and DNS cutover activities.
Position Details
- Employment type: Full-Time, W2
- Location: 100% Remote (US-based)
- Hours: 40 hours/week with availability during core business hours of 8am–5pm ET
- Start date: On or around October 1, 2026
- Eligibility: Must be eligible to obtain a Public Trust clearance
Compensation: $96,000 - $128,000