[Job- 31345]Senior DevOps Engineer
Salve esta vaga e mantenha sua pesquisa organizada
Crie uma conta gratuita para salvar vagas, criar alertas e retornar a esta listagem a partir do seu painel.
At CI&T, we help large enterprises transform the potential of AI into real business impact with AI Deployment, AI-native execution, and tech-integrated business solutions.
With 30 years of experience in technological transformation, we accelerate innovation with expertise in Agentic SDLC, Application modernization, Data & AI, Martech and Business strategy.
We are 8,000 CI&Ters across more than 25 countries, collaborating to build solutions with real impact. AI is already part of how we work, evolve, and innovate every day.
You willco-own a multi-account AWS network foundation: hub and spoke on Transit Gateway, centralised inspection, controlled egress, hybrid connectivity into a client's SD-WAN estate through a third-party vendor. You will be in the room when the client's cloud architect asks why a subnet is a /25 and not a /24 - and the answer has to be yours.
The work is unglamorous in the way that matters. Most of what goes wrong in a landing zone does not go wrong in a module - it goes wrong at the seams.We want someone who has been burned by those and now checks for them by reflex.
Responsabilidades:
- Own the network foundationend to end: Transit Gateway with separated inspected and uninspected route tables, VPC design across inspection, egress, ingress, shared services, and workload tiers
- Define and enforce therouting posturethat makes traffic pass a firewall rather than merely sit near one
- Verify that postureby test, not by reading your own plan
- Design and implementTransit Gateway Connect over GRE with BGP, two peers for availability, ASNs agreed in advance
- Extract precise inputs fromthird-party SD-WAN vendorswho are not on your team and do not share your deadline
- ManageAWS IPAMwith a delegated organisation administrator, pool hierarchy mapped to accounts, RAM shares to spoke accounts
- Justifyevery prefix- "it looked tidy" is not an answer
- ImplementAWS Network Firewallwith stateful rule groups, default drop posture, domain allowlisting, and managed threat signatures
- Be the person who knows whether an application failing to reach the internet isthe firewall working correctly
- Write and maintainTerraform across multiple accountswith per-phase state separation, deployed throughGitHub OIDC
- Implement drift detection, static validation, and a pipeline thata client can inherit
- Manage log delivery into governance accounts, resource policies,KMS key policies, and service-linked roles
- Understand that these accept broken configurations silently - andprove delivery by watching a log arrive
- Write downwhy: why a prefix is what it is, why an option was rejected, what a deviation is
- Prevent the next engineer from reversing a deliberate choicebecause nobody recorded the reasoning
- Write downwhy: why a prefix is what it is, why an option was rejected, what a deviation is
- Prevent the next engineer from reversing a deliberate choicebecause nobody recorded the reasoning
Requisitos:
- Transit Gateway: association vs. propagation (no hedging), appliance mode, and why it exists
- VPC design: Network Firewall, NAT and egress control, PrivateLink, Route 53 Resolver
- Hands-on withhub and spoke and centralised inspection- built it, broke it, and fixed it(non-negotiable)
- Ability to describe arouting asymmetry you diagnosedor a firewall you had to prove was in the path
- Organizations, Control Tower, OUs, SCPs, delegated administrators, RAM
- Experienceinheriting a landing zonesomeone else deployed
- Module design,state layout across accounts and phases
- Read a plan and know before applying whether you are renaming ordestroyinga resource
- Site-to-site VPN or Direct Connect, GRE, BGP peering, route advertisement, ASN allocation
- Default tochecking the environmentrather than trusting a report - including your own
- Every serious problem was found by someonequerying the accountinstead of reading a summary
- Clear, precise, unhedged prose - adelivery skill, not a nice-to-have
- Inglês Avançado/Fluente é obrigatório
Diferencial:
- AWS Advanced Networking Specialty certification - or the equivalent scar tissue
- Experience withSD-WAN platforms on AWS(Cisco, Fortinet, Palo Alto) and Transit Gateway Connect
- Exposure tomanufacturing or industrial environments
- Familiarity withAWS Account Factory for Terraform (AFT)
- Working fluency in both Portuguese and English - client conversations in English; team wo