Senior Cloud Platform Engineer

Anthillcompany — Denmark · Posted ~10 hours ago

Senior Full-time Onsite

Skills

Cloud platform engineering AWS Infrastructure engineering Platform engineering Terraform Cloud platforms

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A growing software company is seeking a Senior Cloud Platform Engineer to strengthen the infrastructure behind enterprise applications operating in a highly regulated industry. You will work in a senior engineering environment with significant responsibility for cloud platform capabilities and collaborate closely with technical leadership and cross-functional teams. The role is permanent, full-time, and office-based.

Highlights

Permanent senior engineering position in a growing technology environment, with ownership of cloud platform capabilities supporting enterprise software. The role offers exposure to modern cloud and AI-enabled systems and collaboration across engineering, product, and design.

Description

Copenhagen, on site. Permanent, full time. Senior. Reporting to the CTPO. Start no later than 1 December 2026. Pharma communication is slow for a good reason. Every claim needs a reference, every asset needs approval, and every market has its own rules. We think the software that wins in this industry treats those rules as part of the product rather than something to work around, and that is what we build. Anthill builds the software pharmaceutical companies use to create, approve and run their digital communication. At some of the world's largest pharma companies, commercial and medical teams rely on our products to produce and distribute regulated content. We're around 70 people, headquartered in Copenhagen, with four products: Activator, Arcane, Amplify and Anthill Cloud. Our products are already delivering GenAI-powered capabilities to Enterprise customers around the world. We're growing fast, and it's a good time to join. In our Copenhagen office, engineers, designers, product people and strategists all sit in the same room. We're 15+ nationalities, so English is the official and everyday language in the office and in the codebase. Engineering runs on AWS with Terraform, Buildkite and a mono repo for our newest platform. THE ROLE Our product teams own their own infrastructure. They write their own Terraform, run their own pipelines and deploy themselves, and we intend to keep it that way. This role owns the platform layer they build on: the AWS account model, identity and access, secrets, agent infrastructure, guardrails, observability, reliability and cost across a multi-account AWS organisation serving regulated customers. It is a hands-on individual role. If the platform function grows, you are the natural person to lead it, but we are not hiring a manager and we would rather say so now. WHAT YOU OWN The AWS account model: provisioning, service control policies, region policy, tagging and naming conventions across the organisationIdentity and access across the full lifecycle, creation, review and removal, through single sign-onSecrets management: one place secrets live, with automated rotation for service credentialsVulnerability management and hardening of the infrastructure itself: baselines, image and runtime currency, segregation and isolation, and the scanning and enforcement point for container and dependency findingsAgent infrastructure: secure, reliable infrastructure connecting AI agents to internal systems, balancing autonomy with control. You control who can invoke what and that it is logged, not what is askedOne observability standard across products for logging, alerting, monitoring and tracing, and an alerting model where cost, security and infrastructure alerts have a named owner and a defined actionReliability and continuity: backup policy, scheduled restore testing, disaster recovery, infrastructure and container health monitoring, and the escalation path when something breaksCost: visibility per account and service, anomaly response, and the budgets and spending limits that prevent a surprise rather than report oneCross-product services outside application code: CI, DNS, certificates and domains. The CI platform decision sits with this role. We run Buildkite today WHAT GOOD LOOKS LIKE AT 90 DAYS The target design for our AWS organisation implemented: account structure, guardrails and identity in Terraform in our repositories, with our newest platform running under them. The migration of our accounts onto it under way and run by you. From there you own the organisation end to end. Alongside that, one observability standard live, and the access lifecycle automated to the point where offboarding is a single action. WHAT WE ARE LOOKING FOR Required: Deep AWS rather than broad cloud, including Organizations and service control policiesInfrastructure as code in production, Terraform in particularReal experience with identity and single sign-on Useful, not required: Landing zones on AWS, Control Tower and Account Factory for Terraform in particularContainers in production, Docker and orchestration on AWSKubernetesAuth0Infrastructure hardening and vulnerability management as an operational discipline rather than a report you forwardComfort in Node.js or Bash, because this role automates manual work away rather than absorbing itObservability tooling such as CloudWatch, Better Stack or Datadog, with enough judgement to standardise on one and defend the choiceCI systems: Buildkite, GitHub Actions, GitLab CI, Jenkins or similar. We use BuildkiteComfort defining standards that other teams build against We also want someone who has thought seriously about agent infrastructure. We are connecting AI agents to internal systems, and the hard problems there are credential scoping, audit and blast radius rather than prompts. If you have opinions about what a non-human identity should and should not be allowed to hold, we want to hear them. Having supported a compliance or certification effort, ISO 27001 or similar, is a strong plus. So is being able to explain an infrastructure trade-off and what it costs to someone who does not work in infrastructure. Experience with regulated customers is useful but not required. We do not expect you to be fluent in everything on the useful list, and some of it will be learned on the job. If you meet the three requirements and have an instinct for where a boundary belongs, apply and we will talk about the rest. WHAT WE OFFER A permanent Danish employment contract, pension and health insurance.A salary set from our salary bands, the same way for everyone at the same level. Where you land in the range depends on your experience and skills, and on pay equity with colleagues at that level.Five days a week in our Copenhagen office, with two work from home days a month as the default. We are on site because most of what engineers learn from each other happens in conversation at someone's desk.Colleagues who have shipped software into pharma and know how demanding that audience is.Clients whose problems are specific and constrained, which is more interesting than it sounds.Occasional office dogs, who expect to be petted. On the office: being in the room matters for this one in particular, because you are building the layer everyone else depends on and most of that work happens next to other engineers rather than in a ticket. APPLYING If you can recognise yourself in just some of these requirements or skills and simply want to learn the rest, we would love to receive your application. We offer an open environment with freedom under responsibility, where you have the opportunity to grow professionally. Apply through LinkedIn, or get in touch directly if you would rather have a conversation before a formal application. We read everything ourselves. Your CV does not need a photo, your age or anything else that is not about your work. If there is a repository, a component library, a design document or a postmortem that tells us more than a cover letter would, send that too. We review applications as they arrive. Where the role has a closing date, it is stated at the top of the ad. Otherwise the role stays open until we find the right person. We only work with recruitment and search firms under a written agreement, and we do not pay fees for candidates we did not ask for. Please do not send CVs to the hiring manager.