Quick Overview
Seniority
Mid Senior
Work mode
Remote
Location
United States
Posted
20 hours ago
AWSEncryptionMFASSOCDKComplianceDNSHIPAAOnboardingPostgreSQLTerraformTypeScript
Job Description
Position: Senior AWS Systems Administrator
Location: Remote
Duration: Contract
About the role
We are looking for a Senior AWS Systems Administrator who owns the AWS environment end to end. Production, development, staging, the organization root, the billing alarms, the network topology, the audit trails, the keys, the access controls.
Requirements
- AWS administration depth. At least 7-10 years administering production AWS environments, including time at a senior level where you owned outcomes rather than implemented someone else s design. You can talk through specific decisions you made on networking, IAM, compute, and data services, what they cost, what they enabled, and what you would do differently now.
- VPC, Transit Gateway, and cross organization networking. Deep production experience with VPC design, Transit Gateway topology, site to site VPN, customer gateway configuration, and the operational reality of routing traffic between AWS and external networks. You have built and maintained tunnels between AWS environments and on premises partner networks, and you can defend the topology to a network engineer on the other side of the table.
- HIPAA in production AWS. You have administered AWS environments that handle PHI. You know what a BAA scope looks like in practice, where the encryption boundaries sit, and what an auditor will ask for when they walk through your configuration. You have shipped real production systems under HIPAA, not just read the compliance documents.
- Aurora PostgreSQL and RDS administration. You have run Aurora PostgreSQL in production at a senior level. Scaling, parameter tuning, backup configuration, point in time recovery, read replica strategy, failover behaviour. You have been on the other end of a real outage and can describe what you did.
- Backup, restore, and recovery operations. Production experience running scheduled backups across databases and infrastructure state, executing real restore drills on a cadence, and recovering systems from a real incident rather than from a tabletop exercise. You can describe a restore you performed, what failed, and what you fixed afterward.
- IAM and identity federation. Expert level command of IAM. Roles, policies, cross account access, identity providers, SSO federation, MFA enforcement, and access boundaries. You have implemented least privilege in a real organization, not just on a slide.
- Microsoft Entra ID and workforce identity. Production experience administering Microsoft Entra ID inside a Microsoft 365 environment. Conditional Access policy design, MFA enforcement, SCIM provisioning into downstream SaaS, hybrid or cloud only identity topology, and the lifecycle of employee and contractor accounts from onboarding through offboarding. You have administered the Microsoft 365 services that sit on top of the directory, Exchange, SharePoint, Teams, and license management, and you have maintained the Entra ID groups and policies that govern who reaches what. You have actually run a directory, not just inherited one.
- Route 53 and DNS. Production experience with Route 53, including zone design, routing policies, health checks, and the failover patterns that keep a service reachable when something underneath it falls over.
- Networking fundamentals. You can explain TCP, BGP, IPsec, TLS, and DNS without a search engine open in another tab. You understand what is actually happening when a packet leaves one VPC and arrives in another, and you can troubleshoot when it does not arrive.
- Linux administration. Real production Linux experience. You know your way around system, the network stack, log files, and the tools you actually reach for when something is broken.
- Infrastructure as code. AWS CDK in TypeScript, Terraform, or comparable production experience. You write your changes in code, and you do not consider a change done until it is in version control.
- Monitoring and observability. Production experience with CloudWatch, log aggregation, distributed tracing, and the alerting patterns that page the right person at the right time without crying wolf.
- AI tool fluency. Daily use of AI for operations work, documentation, runbook writing, and incident analysis. Anthropic Claude in particular. We use AI throughout the engineering workflow, and you should be working with it rather than around it.
- On call discipline. You have carried a real production pager. You know what good incident response looks like, and you can teach it.
Education. A four year college degree from an accredited institution or demonstrated engineering depth that makes a degree unnecessary. Show the work.
Similar jobs
- LM
System Engineer - Field Tech Support with Security Clearance
Lockheed Martin
King of Prussia, PA🇺🇸On-site2 months agoTechnology - AE
Database Administrator
NewAtash Enterprises, LLC
Columbus, OH🇺🇸Hybrid20 hours agoSQLSQL ServerSnowflakeTechnology - ST
Senior Systems Administrator with Security Clearance
NewStraitSys Inc
Huntsville, AL🇺🇸On-site20 hours agoAgileTechnology - II
PostgreSQL Database Administrator
NewIntellect IT
United States🇺🇸Remote20 hours agoAzurePostgreSQLTechnology - LE
Document Management Systems Administrator with Security Clearance
NewLeidos
Martinsburg, WV🇺🇸$59.1k - $106.9k/yrOn-site20 hours agoDocument ManagementTechnology - SO
Cloud System Administrator - Set of X with Security Clearance
NewSet of X
Annapolis Junction, MD🇺🇸$92k - $220k/yrHybrid20 hours agoDockerAWSAnsible+5Technology