HK Tech

HK Tech

·yesterday

Senior platform engineer (lead)

Apply now

Location

remote, United States

Commitment

Full Time

Level

Lead / Manager

Required skills

AWSKubernetesEKSTerraformOpenTofuGitOpsHIPAA complianceInfrastructure as CodeCI/CDGitHub ActionsArgo CDPostgreSQLKafkaObservabilityNetwork securityLeadership

Job Description

Senior Platform Engineer (Lead)

AWS landing zone and Kubernetes platform for a HIPAA-regulated public-health data platform · Remote (U.S.)

We're looking for a senior platform engineer to build, from the first line of code, the AWS platform that will carry rural health data, and then run it in production. You'll own the landing zone and Kubernetes platform behind the project, a cloud-based, open-source semantic data model. The project will harmonize EHR, claims and public-health data into one computable form and serves it through FHIR APIs.

The platform holds protected health information. It is held to NIST SP 800-53 moderate controls and the HIPAA Security Rule, with 99.9% availability, a 15-minute RPO, a 4-hour RTO and a seven-year tamper-evident audit log. You'll build it alongside a dedicated DevSecOps engineer, and by the end of the term the whole environment must be rebuildable from code and ready to hand to the Client.

THE ROLE AT A GLANCE

  • Engagement: 1099 independent contractor; you work as part of HK's team
  • Term: Mid-October 2026 through September 2027; a second year is possible, subject to funding
  • Commitment: Full time, 40 hours a week
  • Reports to: HK's Software/Development Director, with architecture direction from the program architect and security direction from the HIPAA Security Officer
  • Location: Remote within the U.S.; core hours 9:00 a.m.–3:00 p.m. Mountain; occasional travel to Salt Lake City

Requirements

  • U.S. work authorization; background check before production access; HIPAA training before any access

Stack

AWS (us-west-2, DR in us-east-2), EKS on Bottlerocket, Aurora PostgreSQL, MSK, S3 Object Lock, Keycloak, OpenSearch, OpenTofu, GitOps

WHAT YOU'LL DO

You take the platform from the first OpenTofu module to a production environment with a warm DR standby by spring, and you're the person who can rebuild it all from code.

  • Build the AWS Organization as code: separate accounts for management, security, log archive, sandbox, test, staging and production, plus OUs, IAM Identity Center with MFA, and organization-wide CloudTrail and Config.
  • Design the network: private-only VPCs across three AZs, egress inspected through Network Firewall, Transit Gateway, VPC endpoints, and Client VPN. You'll also set the partner connectivity patterns (site-to-site VPN, PrivateLink, mTLS with a private CA).
  • Run Amazon EKS: private endpoint, Bottlerocket nodes with Karpenter, pod security standards, Cilium network policies, upgrades, and capacity and cost tuning for Kafka and Spark.
  • Operate the data services: Aurora PostgreSQL (TLS, PITR, Global Database), MSK, S3 zones with Object Lock and cross-region replication, ECR, Secrets Manager and AWS Backup, plus Keycloak, Prometheus and OpenTelemetry on the cluster.
  • Own the delivery pipeline: GitHub Actions with OIDC to AWS, OpenTofu plan and apply with policy gates, Argo CD, Helm conventions and Kyverno admission. Shipping should be easy for every engineering team on the program.
  • Keep it running: write the runbooks, lead the monthly restore drill and the annual cold-rebuild test, take on-call for severity-1 platform incidents (15-minute acknowledgment), and run post-incident reviews.
  • Report and hand over: report monthly on availability, capacity and tagged AWS spend. You'll prove portability on open-source equivalents (MinIO, Nessie, self-managed PostgreSQL) and hand the platform to the Client's team with documentation they can run it from.
  • Lead: guide a second platform engineer day to day and review the DevSecOps engineer's infrastructure changes. You'll be able to cover each other's on-call.

YOUR FIRST 30 DAYS

The first three weeks are the critical path for the whole program. You'll pair with the DevSecOps engineer to stand up the landing zone, then hand it to the application teams.

  • Week 1: Organization, accounts, SCPs, org-wide logging and security services live; KMS key plan applied
  • Week 2: Sandbox VPC, EKS, Aurora, MSK, S3, ECR and Keycloak provisioned from code; Client VPN working
  • Week 3: OpenSearch SIEM baseline, CI/CD with signing and policy gates, Argo CD syncing, cost budgets and tags; platform handed to engineering
  • Week 4: Test environment built from the same modules; first partner connectivity pattern documented; first monthly cost report

WHAT YOU BRING

7+ years in infrastructure or platform engineering, including 4+ years running production Kubernetes on AWS (EKS strongly preferred).

Deep Terraform or OpenTofu: multi-account organizations, modules, remote state, and policy as code (OPA, Checkov or tfsec). You've built an AWS Organization from zero before.

Hands-on with VPC design, Transit Gateway, Network Firewall, PrivateLink, IAM Identity Center, KMS, Aurora PostgreSQL, MSK or Kafka, S3 Object Lock, ECR and AWS Backup.

GitOps and CI: Argo CD or Flux, Helm, GitHub Actions, container image signing and SBOMs.

Observability: Prometheus and Grafana, OpenTelemetry, and log shipping to OpenSearch or Elasticsearch.

You've operated a regulated workload (HIPAA, FedRAMP, PCI or similar) and can explain what the regulation changed about the design.

You write clear runbooks and ADRs, and you're comfortable leading and reviewing the work of one or two engineers.

NICE TO HAVE

  • Karpenter and Bottlerocket in production; Cilium or Calico network policy.
  • Spark on Kubernetes and Iceberg tables; Strimzi or MSK operations at scale.
  • Keycloak or another OIDC provider; Kyverno or Gatekeeper.
  • AWS Solutions Architect or DevOps Engineer Professional; CKA or CKS.
  • Public-sector or healthcare delivery, and experience handing a platform over to a client team.

Ready to join the team?

Apply now

Similar Jobs: