Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
описание
EPAM is a global provider of digital platform engineering and development services.
задачи
Design and manage AWS IAM roles and policies based on the principle of least privilege, including cross-account access, federation, and access auditing;
Architect VPC network topology with public/private subnets, route tables, gateways, security groups, NACLs, VPC peering, and endpoints;
Provision and maintain EC2 instances, Launch Templates, Auto Scaling Groups, AMI pipelines, and Spot/On-Demand strategies for cost optimization;
Configure ELB, target groups, health checks, routing rules, TLS termination, and certificate integration;
Deploy and maintain container platforms, including Helm, node groups, task definitions, and autoscaling;
Manage ECR image repositories with lifecycle policies, vulnerability scanning, and pipeline access permissions;
Organize S3 buckets with access policies, versioning, lifecycle rules, encryption, and archival strategies;
Deploy RDS/Aurora databases with Multi-AZ, read replicas, backups, snapshots, and point-in-time recovery;
Implement observability through CloudWatch metrics, logs, dashboards, alarms, and alerting;
Manage encryption keys and secrets using KMS and Secrets Manager, integrating them securely into applications and pipelines;
Configure CloudFront CDN distributions, caching policies, and Route 53 DNS zones with weighted, latency-based, and failover routing;
Build and maintain Infrastructure as Code and CI/CD pipelines to automate provisioning and deployment workflows.
требования
5+ Years of experience in DevOps or infrastructure engineering roles, with a strong focus on AWS cloud environments;
At least 1 year of relevant leadership experience;
Expertise in AWS IAM, VPC, and EC2 with Auto Scaling, including network topology, CIDR planning, and environment isolation;
Proficiency in ELB, CloudFront, and Route 53, with an understanding of L4 vs L7 routing and edge delivery;
Background in container orchestration using ECS/Fargate or EKS, Docker, and Kubernetes in production environments;
Skills in managing ECR, S3, and RDS/Aurora, including lifecycle policies, encryption, and high-availability configurations;
Competency in observability using CloudWatch for metrics, logs, dashboards, and alerting;
Knowledge of KMS and Secrets Manager for encryption key management and secure secret storage;
Proficiency in Infrastructure as Code with Terraform or CloudFormation, including modular design and state management;
Qualifications in building CI/CD pipelines with GitLab CI, GitHub Actions, or Jenkins;
Capability to automate operational tasks using Bash and/or Python;
Strong analytical and problem-solving skills, with a structured and proactive approach to work;
Proficiency in English at an Upper-Intermediate level (B2) or higher;
Nice to have: familiarity with EBS/EFS, DynamoDB, and ElastiCache for storage and caching needs, experience building serverless solutions with Lambda, understanding of hybrid connectivity through Direct Connect and Site-to-Site VPN, knowledge of AWS security best practices, WAF/Shield, and SSM Parameter Store for perimeter protection and configuration management, background in cost optimization, high availability, and disaster recovery, along with monitoring tools such as Prometheus, Grafana, or Datadog/ELK Stack.