Principal Cloud Infrastructure Engineer; AWS
Listed on 2026-06-15
-
IT/Tech
AWS, Cloud Computing: Infrastructure & Operations, Systems Engineer
AWS Platform Technical Lead
We’re building a world of health around every individual - shaping a more connected, convenient and compassionate health experience. At CVS Health®, you'll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality. Join us and help simplify health care one person, one family and one community at a time.
Position SummaryWe are looking for a Principal Engineer to lead our AWS Cloud Engineering team, owning the Amazon Web Services platform for the enterprise. This role is a foundational platform position and requires you to be the AWS technical authority, setting architectural direction, establishing engineering standards, and ensuring the platform is secure, scalable and built to last. You will design systems others build upon, mentor engineers, and hold the line on quality and best practices.
You bring deep AWS expertise, a platform‑owner mindset, and a leadership presence to align engineers and stakeholders around a shared technical vision. A cloud‑first thinker, you will ensure cloud solutions meet business needs efficiently while prioritizing Infrastructure as Code (IaC) to create repeatable, automated deployments, and you have a proven track record of architecting cloud environments from scratch.
- Own the enterprise AWS platform end‑to‑end: AWS Organizations structure, account hierarchy, and collaborating with teams to ensure platform stability and compliance.
- Define and maintain the AWS Landing Zone, including AWS Control Tower, Service Control Policies (SCPs), billing controls, and account vending patterns as the foundation for all product teams.
- Serve as the final technical authority on AWS architecture decisions, reviewing designs for scalability, security, and operational excellence before they reach production.
- Build self‑service platform capabilities that enable product engineering teams to move fast without compromising standards.
- Lead the AWS cloud engineering team as the technical anchor – set direction, conduct design reviews, unblock engineers, and drive delivery on platform initiatives.
- Establish and enforce engineering standards:
IaC patterns, naming conventions, tagging strategy, branching models, and deployment practices. - Mentor engineers at all levels, building depth on the team and raising the bar on what "excellence" looks like in cloud engineering.
- Partner with architecture, security, operations, and business stakeholders to translate enterprise requirements into platform capabilities.
- Design and own the Terraform framework for all AWS resource provisioning – reusable modules, remote state management via S3/Dynamo
DB, pipeline integration, and policy guardrails. - Build and maintain CI/CD pipelines using AWS Code Pipeline, Code Build, Git Hub Actions, and Amazon ECR for both platform infrastructure and application teams.
- Write production‑quality automation to extend platform functionality, integrate AWS APIs, and eliminate operational toil.
- Implement policy‑as‑code using OPA, AWS Config Rules, and Service Control Policies to enforce governance at scale without manual gatekeeping.
- Architect and operate AWS networking: VPC design, VPC Lattice, AWS Private Link, Transit Gateway, AWS WAF, Shield Advanced, NAT Gateway, and hybrid connectivity via AWS Direct Connect and Site‑to‑Site VPN.
- Own the enterprise security posture on AWS – IAM Roles for Service Accounts (IRSA), ECR Image Signing, AWS Secrets Manager, least‑privilege IAM design, and SIEM/CSPM integration (AWS Security Hub, Prisma Cloud, or Wiz).
- Drive continuous automated compliance across applicable regulatory frameworks (HIPAA, PCI, SOC
2). Controls are enforced in real time, not discovered at audit. - Integrate observability – Amazon Cloud Watch, AWS X‑Ray, Datadog, and SLO/SLI frameworks – as a first‑class platform capability across all workloads.
- Own the AWS platform roadmap, evaluate new AWS services and capabilities, and make deliberate decisions about enterprise adoption and timing.
- Incorporate Fin Ops practices:
Reserved Instances, Savings Plans, rightsizing, AWS Budgets alerting, and cost allocation…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).