Principal Cloud Infrastructure Engineer; AWS
Listed on 2026-06-02
-
IT/Tech
Systems Engineer, Cloud Computing
Job Summary
We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.
AWS Platform Technical Lead Position Summary We are looking for a Principal Engineer to lead our AWS Cloud Engineering team, owning the Amazon Web Services platform for the enterprise. This is a foundational platform role — you are the AWS technical authority, setting architectural direction, establishing engineering standards, and ensuring the platform is secure, scalable, and built to last. You lead from the front.
You design the systems others build on, mentor the engineers around you, and hold the line on quality and best practices. You bring deep AWS expertise, a platform-owner mindset, and the leadership presence to align engineers and stakeholders around a shared technical vision.
- AWS Platform Ownership:
Own the enterprise AWS platform end-to-end, including AWS Organizations structure, account hierarchy and billing controls. Define and maintain the AWS Landing Zone with Control Tower, Service Control Policies, and account vending patterns. Serve as the final technical authority on AWS architecture decisions, reviewing designs for scalability, security, and operational excellence. Build self‑service platform capabilities that enable product teams to move fast without compromising standards. - Technical Team Leadership:
Lead the AWS cloud engineering team as the technical anchor—set direction, conduct design reviews, unblock engineers, and drive delivery on platform initiatives. Establish and enforce engineering standards for IaC, naming conventions, tagging strategy, branching models, and deployment practices. Mentor engineers at all levels and partner with architecture, security, operations, and business stakeholders to translate enterprise requirements into platform capabilities. - Infrastructure as Code & Automation:
Design and own the Terraform framework for all AWS resource provisioning—reusable modules, remote state management via S3/Dynamo
DB, pipeline integration, and policy guardrails. Build and maintain CI/CD pipelines using Code Pipeline, Code Build, Git Hub Actions, and Amazon ECR for both platform infrastructure and application teams. Write production‑quality automation to extend platform functionality, integrate AWS APIs, and eliminate operational toil. Implement policy‑as‑code with OPA, AWS Config Rules, and Service Control Policies to enforce governance at scale. - Networking, Security & Compliance:
Architect and operate AWS networking including VPC design, VPC Lattice, Private Link, Transit Gateway, WAF, Shield Advanced, NAT Gateway, Direct Connect, and Site‑to‑Site VPN. Own the enterprise security posture on AWS—IAM, IRSA, ECR image signing, Secrets Manager, least‑privilege IAM design, and SIEM/CSPM integration. Drive continuous automated compliance across HIPAA, PCI, SOC2, ensuring controls are enforced in real time. Integrate observability with Cloud Watch, X‑Ray, Datadog, and SLO/SLI frameworks across all workloads. - Platform Strategy & Continuous Improvement:
Own the AWS platform roadmap, evaluate new services and capabilities, and decide what the enterprise adopts. Incorporate Fin Ops practices—Reserved Instances, Savings Plans, rightsizing, budgets, and cost allocation. Research and pilot emerging capabilities such as Bedrock, EKS Auto Mode, and Amazon
Q. Foster a culture of operational excellence with blameless post‑mortems, runbook‑driven operations, and continuous improvement cycles.
- 10+ years in cloud and infrastructure engineering with 5+ years of deep, hands‑on AWS experience at enterprise scale.
- Proven ownership of an AWS Organization—including account hierarchy, billing, Service Control Policies, IAM, and multi‑account governance in production.
- Demonstrated technical…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).