IT Cloud Engineer - Requisition
Listed on 2025-11-30
-
IT/Tech
Systems Engineer, Cybersecurity
General Summary
The Cloud Engineer role focuses on the design, implementation, and management of secure, scalable, and cost‑effective cloud platforms across AWS and Azure environments. This position supports core infrastructure and architecture initiatives while enhancing engineering practices in areas such as networking, identity management, observability, and security. Responsibilities include developing and maintaining secure production environments with an emphasis on Kubernetes, identity‑based access, and Dev Sec Ops methodologies.
The role also involves managing resilient EKS platforms, multi‑cluster configurations, Git Ops workflows, admission controls, network policies, and comprehensive identity frameworks.
All Team Members will display a Four Diamond commitment to Customer Service through the delivery and maintenance of the Quality Standards established by Pechanga Resort Casino (PRC).
Key Responsibilities- Design and Build:
Multi‑account/subscription landing zones, VPC/VNet topologies, private connectivity (Transit Gateway, Private Link / Private Endpoint, VPN / Direct Connect / Express Route) and secure baseline controls - Platform Ops:
Run production environments (patching, backups, DR, autoscaling, capacity planning, OS / hypervisor images, AMIs / VM images) - Identity & Security:
Implement least‑privilege IAM / Entra , SSO, Conditional Access, secrets management (AWS KMS, Azure Key Vault) and policy guardrails (SCPs, Azure Policy) - Networking:
Build resilient L3 / L7 routing, load balancing (ALB / NLB, Azure LB / App GW), DNS, TLS and service‑to‑service connectivity (Private Link, VNet peering, TGW) - Observability:
Standardize logging / metrics / tracing (Cloud Watch, Azure Monitor / Log Analytics), create SLOs / dashboards and incident response runbooks - Author high‑fidelity analytics (KQL) mapped to MITRE ATT&CK, tune noisy rules, implement UEBA and wire SOAR / playbooks for auto‑containment (isolate instance, block token, rotate keys, disable user)
- Normalize / ingest logs from cloud control planes, EDR, firewalls, API gateways, containers and serverless into SIEM
- Shift‑left controls in CI/CD (Git Hub Actions and Azure Dev Ops)
- Lead Kubernetes cluster lifecycle management (provisioning, upgrades, scaling, monitoring, troubleshooting)
- Lead efforts around observability, policy enforcement, cost optimization and RBAC / security hardening within the Kubernetes cluster
- Support CI/CD pipelines and Git Ops‑based deployment
- Ability to troubleshoot issues related to networking, storage, interdependencies, security, etc.
- Building highly available, cost efficient, fault tolerant and scalable distributed systems
- Ensure the stability, integrity and efficient operation of the infrastructure
- Manage Linux based tools, position requires experience with Linux and scripting
- Writing and enforcement of security policies in a cloud environment
- Assist in reviewing logs, writing alerts and tag management
- Configure and maintain permission sets and access privileges to all cloud resources
- Continuously manage the configuration of all AWS Org environments and AWS services
Accountability:
This position has no supervisory responsibilities. The Team Member is responsible for protecting the assets of PRC.
- Bachelor’s degree or equivalent in IT, computer science or related field; and a minimum of (7) years or more of relevant work experience; or equivalent combination of education and progressive, relevant and direct experience may be considered in lieu of minimum educational/experience requirements indicated above.
- 6+ years working in an enterprise level environment designing, building server, storage & network solutions in virtualized environments.
- 3+ years of experience implementing private/public and/or hybrid cloud solutions.
- 3+ year experience in container technology like Docker, Kubernetes or EKS.
This position requires the ability to read, analyze, and interpret common scientific and technical journals. It also requires the ability to respond to common inquiries or complaints from customers, regulatory agencies, or members of the community. The…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).