OpsBrasil Serviços Cloud LTDA

Cloud Engineer AWS ( CDK / Serverless) ( 102-09SENG-01 )

Worldwide · Remote · REMOTE · FREELANCE
Publiée le 20 septembre 2026 · Candidature traitée sur le site de l’entreprise
DeveloperCloud-EngineerAWS-CDKServerless-ArchitectureCloud-Infrastructure-EngineeringDevOps-EngineerAWS-Cloud-EngineerAWS-Serverless-EngineerAWS-CDK-EngineerAWS-CDK-Platform-EngineerCloud-Developer-(AWS)AWS-CloudFormation-EngineerAWS-DevOps-EngineerCloud-AWS-EngineeringServerless-EngineerAWS-Engineer

This role modifies a live serverless gateway in production — no downtime, no change in behaviour — leaving a clean handoff point for a downstream build managed in Terraform. This is careful surgery on production infrastructure with active external consumers, not a greenfield build. The scope includes modernizing a CDK estate made up of four stacks, six Lambda functions, a WAF web ACL, an mTLS custom domain/truststore, and a REST API — preserving resource identity during consolidation and coordinating two sequenced deployments with a tested rollback path. What you will do • Inventory the CDK estate and build a modernization plan: upgrade the CDK library/CLI, replace deprecated constructs, move hardcoded context into per-environment config. • Consolidate duplicated stacks into shared constructs without losing resource identity — map logical IDs before and after, pick a preservation method, and confirm nothing gets replaced before touching production. • Run the library upgrade and the stack refactor as two separate, ordered deployments, with a rollback path tested in dev and test first. • Migrate all six Lambda functions from Node 18 to Node 24, close an open PII logging finding, and regression-test each one. • Re-verify the security perimeter after both deployments — WAF, the mTLS domain and truststore, X-Ray tracing, upstream timeouts — working directly with the customer's POS team across all six external callers. • Build deployment pipelines for dev/test/prod with OIDC federation, approval gates, and a ServiceNow change step. Add CDK assertion tests, drift detection, and API access log retention. • Publish the SQS queue ARN and KMS key ARN via Parameter Store, and grant send permission to the downstream Terraform-managed system — this is the key ordering dependency for that team's build. • Align naming, tagging, and documentation with the customer's internal standards, and document your identity-preservation decisions clearly enough for the next engineer to follow. Requirements • 5+ years with AWS, including 3+ years working in infrastructure-as-code. • Hands-on AWS CDK experience in TypeScript — construct trees, logical ID derivation, and what happens when a construct path changes. • Real experience with CloudFormation resource identity: stack refactoring, logical ID overrides, cdk diff against deployed state, drift detection. • Working Terraform knowledge — comfortable operating across the CDK/Terraform boundary. • Solid AWS serverless background: Lambda, API Gateway (REST), SQS and DLQs, Parameter Store, KMS, Secrets Manager. • Experience with AWS edge and security services — WAF web ACLs, mutual-TLS custom domains and truststores, cross-account/cross-boundary IAM. • Practical experience migrating Nodejs runtimes (e.g. Node 18 → 24), including dependency and deprecation handling. • CI/CD pipeline experience with OIDC federation and approval gates (GitHub Actions or equivalent). • Working knowledge of observability tools — X-Ray, CloudWatch metrics and alarms, log retention. • Comfortable communicating clearly with non-engineers, and working well when parts of the scope are still being figured out. • Fluent English (C1 level) for daily communication with the client. Engagement details • Hourly contractor • 100% remote • Estimated duration: 6–8 weeks • Time zone: EST or MST Highlights AWS CDK , CloudFormation, Terraform, AWS Serverless (Lambda, API Gateway REST, SQS/DLQ, Parameter Store, KMS, Secrets Manager), AWS Edge & Security (WAF, mTLS, cross-account IAM), Node.js, CI/CD Originally posted on Himalayas