Lead Engineer Cloud Platform Operations, WARSAW

Experience

  • 7+ years of enterprise cloud engineering and operations experience, with at least 2 years in a team lead or managerial role: including team workload management, ticket queue prioritisation (Jira), and hands-on development of engineers.
  • Deep, hands-on production expertise in AWS is essential; experience across at least one additional platform (OCI and/or Azure) covering both IaaS and PaaS services at enterprise scale.
  • Demonstrable Terraform expertise: authored, maintained, and reviewed IaC codebases in a team environment with CI/CD pipelines (Jenkins, GitHub) and policy gates.
  • Proven track record delivering cloud migration projects and complex cloud transformation initiatives with minimal disruption.
  • Experience designing and operating cloud IAM frameworks: federation/SSO, workload identities, JIT/PAM, least-privilege design, and KMS/HSM secret management.
  • Hands-on experience with cloud networking: VNet/VPC design, private endpoints, hub-and-spoke architectures, DNS, global load balancing, and egress controls.
  • Experience operating Kubernetes clusters (EKS, AKS, or OKE) in production: node pools, autoscaling, admission control, and image supply chain.
  • Background in FinOps practices: cost allocation, rightsizing, commitment planning, anomaly detection, and showback/chargeback.
  • Experience supporting or leading cloud audit and compliance activities (ISO 27001, SOC 2, PCI-DSS, or equivalent) with evidenced remediation.
  • Proficiency with ITSM and project tracking platforms — Jira (primary) and ServiceNow or equivalent — for incident management, ticket queue management, CMDB, and change automation.

Technical Skillset

  • Multi-cloud platform management (AWS primary, OCI, Azure): secure provisioning, tenancy hygiene, landing-zone design, and quota/region governance.
  • Infrastructure-as-Code (Terraform): module design, state management, drift control, and CI/CD pipeline integration (Jenkins, GitHub) with policy/test gates (OPA/Conftest); access controls, secrets hygiene, and security governance across CI/CD tooling.
  • Policy-as-code and guardrails: Azure Policy/Defender for Cloud, AWS SCPs/Config/Control Tower, OCI Policies & Cloud Guard.
  • Deep IAM skills: federation/SSO, workload identities, conditional access, JIT/PAM, least-privilege design patterns, KMS/HSM, and secret lifecycle management.
  • Cloud networking patterns: VNet/VPC design, private links/endpoints, service endpoints, routing/peering, DNS, global load balancing, egress control, and cross-cloud connectivity.
  • Kubernetes/container operations (EKS/AKS/OKE): cluster lifecycle, admission controllers, image signing (SBOM), registry governance, and autoscaling.
  • SRE and operability: SLOs, error budgets, toil reduction, runbook authoring, incident command, and post-incident review facilitation.
  • Security posture and compliance: CSPM/CWPP tooling, CIS/NIST/ISO mapping, vulnerability management, patch baselines, and workload hardening.
  • FinOps tooling: budget management, anomaly detection, commitment planning, showback/chargeback, cost allocation tags, and lifecycle policies.
  • Observability and ITSM automation: centralised log/metrics/trace pipelines, SIEM/SOAR integration, auto-discovery, service mapping, and event enrichment.
  • Backup, disaster recovery, and geo-redundancy for cloud environments; restore drill planning and RTO/RPO definition.
  • Automation scripting (Python, PowerShell, Bash, CLI) for bulk operations, health checks, and compliance reporting.
  • Nutanix (advantageous): familiarity with Nutanix HCI/cloud platform is a strong differentiator, particularly for hybrid workload integration and private-to-public cloud migration scenarios.
  • Strong documentation and coaching skills; ability to standardise patterns into reusable blueprints and service catalog items.
  • AI-assisted automation and agent development (advantageous)

We are seeking an experienced Lead Engineer for Cloud Platform Operations to join Avon’s global technology team. This area lead role carries full accountability for provisioning, securing, and continuously improving Avon’s multi-cloud estate, with AWS as the primary platform, alongside OCI and Azure. The role spans IaaS and PaaS operations, Infrastructure-as-Code engineering, cloud-native security and networking, Kubernetes/container platforms, SRE practices, and FinOps - partnering closely with application, security, and infrastructure teams to deliver a reliable, governed, and cost-efficient cloud platform. The successful candidate combines deep technical breadth across cloud disciplines with the leadership capability to mentor engineers and drive continuous improvement.


,[Lead provisioning, management, and optimisation of multi-cloud infrastructure across AWS (primary), OCI, and Azure (IaaS, PaaS, cloud-native), ensuring security, scalability, and cost efficiency within landing-zone guardrails (tagging, naming, quota, region standards)., Build all infrastructure as code (Terraform) with drift detection and safe auto-remediation; integrate IaC pipelines with pre-merge security/compliance gates (OPA/Conftest, terraform validate/plan) and secure CI/CD tooling (Jenkins, GitHub)., Maintain a Cloud Service Catalog of approved blueprints enabling governed self-service; standardise proven patterns into reusable blueprints., Own policy-as-code guardrails (AWS Control Tower/SCPs, Azure Policy, OCI Policies); identity and access (least privilege, SSO, role mapping, break-glass, workload identities, KMS/HSM secrets management); and secure networks (hub-and-spoke, private endpoints, egress controls, DNS, global load balancing, cross-cloud connectivity)., Lead Kubernetes/container operations (EKS/AKS/OKE) — cluster lifecycle, autoscaling, admission control, supply-chain security — plus golden images, patch pipelines, and vulnerability management (CIS/NIST)., Embed SRE practices (SLOs, error budgets, observability, incident response) and develop automation (PowerShell, Python, Bash, AI-assisted tooling) to reduce toil., Own FinOps (cost allocation, budgets, rightsizing, commitments); backup, DR, and business continuity (RTO/RPO, restore drills); and CMDB/ITSM integration with audit-ready evidence., Lead cloud migrations with minimal disruption; ensure regulatory compliance and audit remediation; manage vendor relationships (AWS, Oracle, Microsoft)., Participate in governance, reporting, and service reviews, regularly reviewing cloud utilisation and performance., Mentor engineers in build standards and IaC patterns; manage team workload and capacity, prioritise the Jira queue, run the on-call rota, and drive continuous improvement.] Requirements: AWS, Automation, Cloud platform, Red Hat, Ansible, VMware vSphere, Bash script, Pacemaker, Kerberos, LDAP, Python
Data publikacji: 2026-06-25
APLIKUJ