AWS Cloud Engineer

location_onStockholm, Swedenscheduleför 6 timmar sedan
Ansök nuopen_in_new

Arbetsbeskrivning

About the role

At 0TO9 (Zero to Nine) you’ll build the cloud foundation behind the licensed financial companies we start & scale. Every new venture lands on this platform, in a regulated market where resilience, security and evidence matter as much as speed. It’s a chance to shape that foundation while it’s still young enough to shape.

The role covers three areas:

  • The organisation layer. Design and run our AWS landing zone with AWS Control Tower and AWS Organizations: guardrails, service control policies, and preventive and detective controls enforced from the top and applied the same way to every account.
  • The venture layer. Create new accounts for new ventures and roll out our infrastructure blueprint in each one, so every venture goes from an empty account to production-grade hosting the same way, every time.
  • Resilience and compliance. Define recovery objectives (RTO and RPO) for every critical service, build disaster recovery that meets them, and prove it with recurring tests. Keep the platform compliant with DORA, and be the person who walks auditors and supervisors through our controls and the evidence behind them.

You’ll work closely with our CTO and CISO on a daily basis.

Day to day you will:

  • Build and evolve our infrastructure as code in AWS CDK (TypeScript), reviewed and deployed through pipelines, never by hand.
  • Run containerised .NET microservices on ECS Fargate, with RDS (SQL Server and PostgreSQL), S3 and DynamoDB behind them.
  • Own identity and access: Okta as our identity provider, federated into IAM Identity Center for SSO, with least-privilege roles and no long-lived keys.
  • Run the security baseline across every account: centralised logging, threat detection, configuration compliance, WAF at the edge, KMS encryption everywhere.
  • Run recurring disaster recovery and restore tests against our recovery objectives, and turn the results into evidence an auditor can follow.
  • Run recurring compliance checks, so we know we’re still compliant between audits rather than finding out during one.
  • Keep cost visible: budgets, anomaly detection and tagging, so a surprise on the bill shows up as an alert rather than at month-end.
  • Work with security, compliance and risk to turn regulatory requirements, DORA included, into controls that are built, tested and documented.

How we build

Agentic coding is our default, not an experiment. Across the group, we run a Claude-Code-native workspace:

  • Engineering standards loaded as a skill, so agents apply them automatically.
  • A git-backed knowledge base that agents read and extend.
  • Agent workflows that take a change from branch to reviewed PR, infrastructure included.
  • An automated reviewer in CI that counts as an approving review on a pull request.

We’re looking for someone who already works this way and makes agents a normal part of how they build, including against live cloud accounts, with the judgement to know when a change needs a human eye first.

About you

We think you’ll be a great fit if you:

  • Have hands-on experience designing and running production workloads on AWS, ideally across many accounts.
  • Have built or operated an AWS landing zone with Control Tower or Organizations, SCPs, account vending and centralised security accounts.
  • Write infrastructure as code by default. CDK is preferred; Terraform or CloudFormation is welcome.
  • Take ownership, challenge unclear requirements, and put reliability and security ahead of shortcuts.
  • Can explain a control to an engineer and to an auditor, and know the difference between configuring a control and evidencing it.
  • Already lean on LLMs and agentic tools daily, and see them as leverage, not a shortcut.

Technical Requirements

We build on AWS, with .NET and SQL on the backend. This role lives in the platform, and AWS is a requirement.

Cloud & Infrastructure

  • AWS-native: Organizations, Control Tower, ECS/Fargate, RDS, S3, least-privilege IAM.
  • Infrastructure as code: CDK in TypeScript, with stacks you can diff, review and roll back.
  • Multi-account by design: environments separated by account, not by naming convention.
  • EU data residency: you know why region matters, and how to enforce it rather than hope for it.

Security & Compliance

  • Security by default: WAF, encryption at rest and in transit, customer-managed KMS keys where it matters.
  • Zero hardcoded secrets: Secrets Manager with rotation, always.
  • Detection that leads somewhere: GuardDuty, Security Hub and Config, with every finding routed to an owner.
  • Audit-ready: organisation CloudTrail, log retention by design, and every change traceable to a reviewed PR.

Resilience & Operations

  • Disaster recovery: RTO and RPO defined per service, DR designs that meet them, and tests on a schedule that prove it.
  • Backup and restore: AWS Backup, cross-region copies, and restores rehearsed rather than assumed.
  • Observability: CloudWatch and Datadog, with alarms that reach a human.
  • Cost control: budgets, anomaly detection and cost allocation tags.

Delivery & Quality

  • CI/CD fluency: GitHub Actions and CDK Pipelines, or equivalent.
  • Reviewable PRs: small diffs, no self-merges, no console changes in production.
  • Tested infrastructure: unit-tested constructs and synthesised templates.
  • Supply-chain hygiene: dependency and image scanning before ship.

Nice to have

  • Knowledge of DORA and how it works in practice: ICT risk management, resilience testing, third-party risk and incident reporting.
  • Previous fintech or banking industry experience. You’ll ramp faster in a regulated market.
  • AWS certifications, for example Solutions Architect Professional or Security Specialty.
  • Experience with event-driven platforms (ideally NATS), or with hosting AI workloads on Amazon Bedrock.

Färdigheter som nämns


Stockholm, Sweden

Ansök om detta jobb

Use the application link supplied with this listing to apply to 0TO9. Check the destination before entering personal information.

Ansök nuopen_in_new