Principal Cloud Platform Architect / Engineering Lead - BK
Quick Summary
Weeks one to two: get the lay of the land — the current AWS estate, repositories, pipelines, and application landscape. From there: design the target platform against the existing preliminary design,
About Atlas Systems
Atlas Systems is a global technology services and solutions company headquartered in East Brunswick, New Jersey, USA, with development and delivery centers across the globe. Since 2003, we have been helping enterprises accelerate digital transformation through innovative solutions in Cloud, AI, Cybersecurity, Governance, Risk & Compliance (GRC), Enterprise Applications, Procurement, Healthcare, and Managed IT Services.
With over two decades of industry experience, Atlas Systems partners with organizations across diverse industries to design, build, and manage secure, scalable, and high-performing technology platforms. Our culture is built on innovation, customer success, collaboration, and continuous learning, enabling our teams to solve complex business challenges with cutting-edge technologies.
Learn more at: https://www.atlassystems.com
Apply for this job using thins link:
https://atlas.bamboohr.com/careers/587
Principal Cloud Platform Architect / Engineering Lead
AWS DevOps Resource
AWS | Amazon EKS | Kubernetes | Platform Engineering
Role
Principal Cloud Platform Architect / Engineering Lead — AWS DevOps
Type
Net-new role (not a backfill) — a new cloud-modernization initiative
Reports to
The Cloud / Engineering Lead — direct, day-to-day partnership
Engagement
Approximately two years, with strong likelihood of extension
Working model
Hands-on and collaborative — works hand-in-hand with the lead, with close onboarding
Location
Remote; must overlap U.S. East Coast business hours
Guiding principle
Security-first at every step — non-negotiable
Primary Focus — What Matters Most
Depth in three areas is the primary screen for this role: AWS (hands-on), Amazon EKS / Kubernetes at production scale, and AWS networking (VPC, Transit Gateway, PrivateLink, and routing). Everything else can be ramped on the job — the successful candidate need not be an expert in every technology listed below.
This is a hands-on role working hand-in-hand with the hiring lead, with close onboarding provided; it is a working relationship, not a turnkey handoff. Adjacent tooling such as Bitbucket Pipelines and SigNoz is Git-based and picked up quickly. Security is the guiding principle at every step.
Position Overview
We are seeking a highly experienced Principal Cloud Platform Architect / Engineering Lead to support a major enterprise cloud-modernization initiative for a leading organization.
This is not a traditional DevOps position. The successful candidate must be capable of architecting, implementing, securing, and operationalizing an enterprise-grade AWS and Kubernetes platform. This individual will serve as the technical lead and work closely with Cyber Security, Infrastructure, Networking, Application Engineering, and Operations teams.
The organization is consolidating a portfolio of applications currently hosted across AWS Amplify, Amazon ECS, AWS Lambda, and on-premises environments onto a standardized Amazon EKS platform.
This is a highly visible, hands-on leadership role requiring deep technical expertise, strong architectural judgment, and the ability to translate enterprise security and governance requirements into practical platform capabilities.
Immediate Scope — First 90 Days
The role begins with orientation and moves quickly into design and hands-on build:
- Weeks one to two: get the lay of the land — the current AWS estate, repositories, pipelines, and application landscape.
- From there: design the target platform against the existing preliminary design, and take it through cyber-security review with the wider stakeholder group before build.
- Core early build — account separation: consolidate and split the current single AWS account into distinct Development, UAT, and Production accounts under AWS Organizations, decommissioning the legacy account.
- Bring the remaining repositories into the established repository structure and standards.
- Fine-tune the existing Bitbucket CI/CD pipelines.
- This work proceeds in parallel with other in-flight enterprise initiatives, so careful sequencing and platform stability matter throughout.
Target Platform Architecture
The platform environment includes:
- Amazon EKS with a multi-account architecture
- AWS Organizations
- Separate Development, UAT, and Production accounts
- AWS Transit Gateway
- AWS PrivateLink
- Akamai CDN and Web Application Firewall
- Bitbucket-based CI/CD pipelines
- OpenTelemetry instrumentation
- SigNoz observability
- Secure hybrid connectivity with on-premises systems
- Zero Trust and least-privilege security architecture
The platform is being designed as an enterprise-grade, cyber-reviewable solution with a strong emphasis on security, governance, observability, scalability, resilience, and operational excellence.
Key Responsibilities
- Lead the architecture, design, and hands-on implementation of a multi-account AWS EKS platform.
- Define and implement enterprise Kubernetes standards, governance models, security controls, and operational practices.
- Design secure cloud and hybrid networking patterns using Transit Gateway, PrivateLink, VPN, Direct Connect, VPC routing, and private connectivity.
- Establish a Zero Trust architecture and least-privilege access model across AWS and Kubernetes.
- Design and implement a comprehensive observability framework using OpenTelemetry, SigNoz, Prometheus, Grafana, logging, metrics, and distributed tracing.
- Architect secure CI/CD capabilities using Bitbucket Pipelines, self-hosted runners, OIDC authentication, and automated security controls.
- Lead the migration of applications from AWS Amplify, Amazon ECS, AWS Lambda, and on-premises environments to Amazon EKS.
- Develop reusable Terraform modules, Helm charts, GitOps patterns, and platform automation.
- Establish Kubernetes multi-tenancy, RBAC, network policies, ingress standards, secrets management, and workload isolation.
- Partner with Cyber Security teams during architecture assessments, threat modeling, security reviews, and compliance evaluations.
- Support platform operational readiness, resiliency testing, disaster recovery planning, and production support processes.
- Produce high-quality architecture diagrams, technical standards, implementation roadmaps, runbooks, and operational documentation.
- Mentor engineers and provide technical leadership across cloud, platform, infrastructure, and application teams.
- Evaluate technical risks, recommend architectural decisions, and drive issues through resolution.
- Operate independently while maintaining strong collaboration across multiple technical and business teams.
Requirements — Priority Guide
How to Read These Requirements — Priority Tiers
Tier 1 — Essential (the hiring gate):
● Hands-on AWS engineering and architecture.
● Amazon EKS and production-scale Kubernetes.
● AWS networking — VPC and routing, Transit Gateway, PrivateLink.
● IAM and least-privilege, with a security-first mindset throughout.
Tier 2 — Strongly preferred (expected for a strong candidate):
● AWS Organizations and multi-account design; hybrid connectivity (VPN / Direct Connect).
● Terraform / Infrastructure as Code; Helm and GitOps operating models.
● Kubernetes RBAC, network policies, multi-tenancy, and container security.
● Zero Trust architecture and cloud security / governance controls.
Tier 3 — Rampable on the job (familiarity is fine; will be trained):
● Bitbucket Pipelines, self-hosted runners, and OIDC-based authentication.
● Observability stack specifics — OpenTelemetry, SigNoz, Prometheus, Grafana.
● Service mesh (Istio or AWS App Mesh) and selected AWS services (Route 53, ECR, GuardDuty, CloudTrail, KMS, Secrets Manager).
The full technical scope is retained below for reference; the tiers above indicate where depth is required versus where the candidate can grow into the role.
Full Technical Scope (Reference)
The complete technical scope is listed below by area. Highlighted items are the Tier 1 essentials; the remainder maps to Tiers 2 and 3 above.
AWS — Expert Level
Candidates should have deep, hands-on experience with:
- Amazon EKS
- AWS Organizations and multi-account architecture
- VPC architecture and routing
- Transit Gateway
- AWS PrivateLink
- Route 53
- IAM and least-privilege access design
- IAM Roles for Service Accounts
- Amazon ECR
- AWS Lambda
- Application and Network Load Balancers
- AWS CloudTrail
- Amazon GuardDuty
- AWS Key Management Service
- AWS Secrets Manager
- Hybrid cloud connectivity
- VPN and AWS Direct Connect
- Cloud security, governance, and compliance controls
Kubernetes — Expert Level
- Production-scale Kubernetes and Amazon EKS implementation
- Kubernetes architecture, administration, and troubleshooting
- Ingress controllers
- Kubernetes RBAC
- Network policies
- Multi-tenant Kubernetes environments
- Helm
- GitOps operating models
- Container security
- Secrets and configuration management
- Cluster upgrades, scaling, resiliency, and lifecycle management
- Service mesh experience with Istio or AWS App Mesh is preferred
Platform Engineering and DevOps
- Bitbucket Pipelines
- Self-hosted CI/CD runners
- OIDC-based authentication
- Enterprise CI/CD architecture
- Docker and containerization
- Infrastructure as Code
- Advanced Terraform experience
- Policy-as-code and automated governance
- Secure software supply-chain practices
- Platform automation and reusable engineering standards
Security Architecture
- Zero Trust architecture
- Least-privilege IAM
- Kubernetes security
- Cloud security architecture
- Workload identity
- Network segmentation
- Secrets and encryption management
- Enterprise governance and compliance
- Security architecture and cyber-review processes
- Experience working in regulated or security-sensitive environments
Observability
- OpenTelemetry
- SigNoz
- Prometheus
- Grafana
- Centralized logging
- Metrics and alerting
- Distributed tracing
- Application and platform monitoring
- Service-level indicators and operational dashboards
Required Qualifications
- 10 or more years of infrastructure, cloud engineering, or platform engineering experience.
- At least 5 years of hands-on AWS architecture and engineering experience.
- At least 5 years of hands-on Kubernetes experience, including production EKS environments.
- Demonstrated experience leading enterprise cloud-platform architecture and implementation.
- Strong hands-on Terraform, Kubernetes, AWS networking, and security experience.
- Proven ability to lead complex cloud migrations and platform-modernization programs.
- Experience partnering with Cyber Security, Networking, Infrastructure, Operations, and Application Engineering teams.
- Strong troubleshooting, problem-solving, and architectural decision-making capabilities.
- Excellent written and verbal communication skills.
- Ability to create clear technical documentation and present architecture decisions to technical and executive stakeholders.
- Ability to work independently and lead initiatives with limited supervision.
- Must be available to work during U.S. East Coast business hours.
Note on fit: the essential screen is genuine, hands-on depth in AWS, Amazon EKS / Kubernetes, and AWS networking (see Priority Tiers). Strong candidates who meet this core and can ramp adjacent tooling will be considered even where they are not expert across every technology listed.
Preferred Certifications
- AWS Certified Solutions Architect – Professional
- Certified Kubernetes Administrator
- Certified Kubernetes Security Specialist
- HashiCorp Certified: Terraform Associate or equivalent Terraform expertise
Ideal Candidate Profile
The ideal candidate combines the architectural depth of a Principal Cloud Architect with the hands-on implementation capabilities of a senior platform engineer.
This individual should be comfortable moving between architecture diagrams, Terraform code, Kubernetes configurations, security reviews, migration planning, and production troubleshooting. Candidates whose experience is limited primarily to CI/CD administration or traditional DevOps support are unlikely to be a fit.
We are specifically seeking someone who can:
- Define the platform architecture.
- Make critical technical decisions.
- Implement the platform directly.
- Establish governance and engineering standards.
- Guide application migrations.
- Successfully lead the platform through cyber and operational-readiness reviews.
Work Arrangement
- Availability during U.S. East Coast business hours is mandatory.
- The role requires close collaboration with multiple distributed technical teams.
- Strong communication, documentation, and stakeholder-management skills are essential.
- This is a hands-on technical leadership position; architecture-only candidates will not be considered.
Location & Eligibility
Listing Details
- Posted
- July 14, 2026
- First seen
- July 14, 2026
- Last seen
- August 1, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 57%
- Scored at
- July 14, 2026
Signal breakdown

Please let atlas group know you found this job on Jobera.
4 other jobs at atlas group
View all →Explore open roles at atlas group.
Similar Platform Architect jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.