Description
Job Role: AWS Infrastructure Engineer
Location: Boston MA, Arlington, VA, Atlanta GA, Austin TX, Chicago, IL, Cleveland OH
Experience: 10 Years
Skills:
Lead cloud infrastructure architecture design for DTCC A3P landing zone migration supporting FICC (Fixed Income, Currency, and Commodities) workloads.
Design multi-region AWS infrastructure including VPC architecture, self-managed OpenShift on EC2, Aurora Global Database, DynamoDB Global Tables, and IBM MQ RDQM clustering.
Architect disaster recovery topology with F5 GTM integration, cross-region data replication, and hybrid connectivity (Direct Connect/VPN) for on-premises integration.
Define Terraform IaC modules for enterprise-scale, multi-account deployments with cost governance and Tier 1 resiliency requirements.
Role Scope & Key Responsibilities
Primary Responsibilities:
Landing Zone Architecture: Design and validate DTCC A3P landing zone configuration for FICC workloads with AWS Organizations, SCPs, and multi-account governanceNetwork Design: Define VPC architecture with public/private subnets, VPC endpoints, security groups per SYS ID; configure multi-region topology (us-east-1 primary, us-east-2 standby)Disaster Recovery: Design F5 GTM integration for DR failover and operational traffic rotation; architect cross-region data replication (SRDF-A equivalent, Aurora Global DB, DynamoDB Global Tables)Infrastructure as Code: Define Terraform module structure for FICC infrastructure (OCP on EC2, Aurora, DynamoDB, IBM MQ, Global Scape, Autosys)Compute Architecture: Design EC2 instance sizing and placement for OCP worker nodes, Autosys server, Global cape SFTP, IBM MQ RDQM with HA configurationsObservability: Configure Dynatrace One Agent deployment on OCP and Splunk log forwardingHybrid Connectivity: Define on-premises connectivity architecture (Direct Connect/VPN for Ping Federate, CRS, CDTS MQ, Venafi)Cost Governance: Design tagging strategy (per SYS ID, per environment, per wave) and validate A3P platform service readinessKey Deliverables:
A3P Landing Zone Design (FICC-specific)VPC and Network Architecture (multi-region)Terraform Module Catalog (OCP, Aurora, DynamoDB, MQ, GlobalScape, Autosys)Multi-Region DR Infrastructure DesignOn-Premises Connectivity ArchitectureEC2 Sizing Recommendations
AWS Skills & Services
Governance & multi-account:
AWS Organizations: OU structure, SCPs, consolidated billing, cross-account strategiesAWS Control Tower: Landing zone automation, guardrails, Account FactoryAWS Service Catalog: Standardized resource provisioningNetworking:
Amazon VPC: Advanced design (public/private subnets, VPC endpoints, security groups, NACLs, route tables)AWS Transit Gateway: Hub-and-spoke architecture, multi-region peeringAWS Direct Connect: Hybrid connectivity, VIFs, LAG configurationsAWS VPN: Site-to-Site VPN for on-premises integrationElastic Load Balancing: ALB/NLB for OCP ingress, F5 GTM integration patternsAmazon Route 53: DNS management, health checks, failover routingCompute & Containers:
Amazon EC2: Instance families (compute/memory/storage optimized), placement groups, Auto Scaling, self-managed infrastructureOpenShift on EC2: Overlay networks, load balancers, ingress controllers, persistent storage (EBS/EFS)Database & Storage:
Amazon Aurora: Global Database (cross-region replication), cluster endpoints, failover mechanismsAmazon DynamoDB: Global Tables, on demand/provisioned capacity, DAX cachingAmazon S3: Bucket policies, lifecycle policies, cross-region replication, versioningAmazon EBS: Volume types, snapshots, encryption, cross-region copyAmazon EFS: Shared file storage for OCP persistent volumesMessaging & Integration:
IBM MQ RDQM on EC2: Clustering, HA configurations, mTLS, channel authenticationAmazon MQ: Managed message broker (if applicable for non-RDQM workloads)Disaster Recovery:
AWS Backup: Centralized backup, cross-region/cross-account backupAWS Elastic Disaster Recovery (DRS): Continuous replication, failover orchestrationF5 GTM Integration: DNS-based traffic management, health monitoringMonitoring & Observability:
Amazon CloudWatch: Metrics, logs, alarms, dashboardsAWS X-Ray: Distributed tracingDynatrace OneAgent: APM integration with OCPSplunk: Log forwarding and SIEM integrationSecurity & Compliance:
AWS IAM: Advanced policies, cross-account roles, service accountsAWS KMS: Customer Managed Keys, key policies, cross-region replicationAWS Secrets Manager: Credential rotation, cross-account accessAWS Security Hub: Centralized security findingsAWS Config: Configuration compliance, resource inventoryInfrastructure as Code:
Terraform: Enterprise-scale IaC (multi-account, multi-region), module development, state management, workspacesAWS CloudFormation: Stack Sets for multi-account deploymentsCost Management:
AWS Cost Explorer: Cost analysis, tagging strategiesAWS Budgets: Cost alerts, anomaly detectionTagging Strategy: Per SYS ID, per environment, per waveHybrid Connectivity:
AWS Direct Connect: Dedicated network connections, VIFs, LAGAWS VPN: Site-to-Site VPN for Ping Federate, CRS, CDTS MQ, Venafi integration
Financial Services & Industry Skills
Large regulated financial-services delivery with formal change-control, audit and risk governanceOperational resilience expectations including RTO/RPO, multi-region DR and evidence for audit reviewAwareness of applicable controls and regulations such as DORA, NIST CSF 2.0, PCI DSS, SEC cyber rules, RegSCI and SIFMU/FMI expectations where relevantAbility to create Tech Risk-ready documentation including ADRs, runbooks, design docs, threat models and validation evidenceClear communication with client engineering, security, SRE, data and platform stakeholders as an embedded SMECertifications / Qualifications
AWS Certified Solutions Architect - Associate / ProfessionalAWS Certified SysOps Administrator - AssociateAWS Certified DevOps Engineer - Professional preferred