AI summary
This role involves owning and managing a multi-account AWS network foundation, focusing on design and implementation of Transit Gateway and ensuring proper routing and security measures. You'll need to handle hybrid connectivity, validate configurations, and document decisions thoroughly.
Job Description
You will co-own a multi-account AWS network foundation: hub and spoke on Transit Gateway, centralised inspection, controlled egress, hybrid connectivity into a client's SD-WAN estate through a third-party vendor. You will be in the room when the client's cloud architect asks why a subnet is a /25 and not a /24 — and the answer has to be yours.
The work is unglamorous in the way that matters. Most of what goes wrong in a landing zone does not go wrong in a module — it goes wrong at the seams. We want someone who has been burned by those and now checks for them by reflex.
Responsabilidades:
- Own the network foundation end to end: Transit Gateway with separated inspected and uninspected route tables, VPC design across inspection, egress, ingress, shared services, and workload tiers
- Define and enforce the routing posture that makes traffic pass a firewall rather than merely sit near one
- Verify that posture by test, not by reading your own plan
- Design and implement Transit Gateway Connect over GRE with BGP, two peers for availability, ASNs agreed in advance
- Extract precise inputs from third-party SD-WAN vendors who are not on your team and do not share your deadline
- Manage AWS IPAM with a delegated organisation administrator, pool hierarchy mapped to accounts, RAM shares to spoke accounts
- Justify every prefix — "it looked tidy" is not an answer
- Implement AWS Network Firewall with stateful rule groups, default drop posture, domain allowlisting, and managed threat signatures
- Be the person who knows whether an application failing to reach the internet is the firewall working correctly
- Write and maintain Terraform across multiple accounts with per-phase state separation, deployed through GitHub OIDC
- Implement drift detection, static validation, and a pipeline that a client can inherit
- Manage log delivery into governance accounts, resource policies, KMS key policies, and service-linked roles
- Understand that these accept broken configurations silently — and prove delivery by watching a log arrive
- Write down why: why a prefix is what it is, why an option was rejected, what a deviation is
- Prevent the next engineer from reversing a deliberate choice because nobody recorded the reasoning
- Write down why: why a prefix is what it is, why an option was rejected, what a deviation is
- Prevent the next engineer from reversing a deliberate choice because nobody recorded the reasoning
- Transit Gateway: association vs. propagation (no hedging), appliance mode, and why it exists
- VPC design: Network Firewall, NAT and egress control, PrivateLink, Route 53 Resolver
- Hands-on with hub and spoke and centralised inspection — built it, broke it, and fixed it (non-negotiable)
- Ability to describe a routing asymmetry you diagnosed or a firewall you had to prove was in the path
- Organizations, Control Tower, OUs, SCPs, delegated administrators, RAM
- Experience inheriting a landing zone someone else deployed
- Module design, state layout across accounts and phases
- Read a plan and know before applying whether you are renaming or destroying a resource
- Site-to-site VPN or Direct Connect, GRE, BGP peering, route advertisement, ASN allocation
- Default to checking the environment rather than trusting a report — including your own
- Every serious problem was found by someone querying the account instead of reading a summary
- Clear, precise, unhedged prose — a delivery skill, not a nice-to-have
- Inglês Avançado/Fluente é obrigatório
- AWS Advanced Networking Specialty certification — or the equivalent scar tissue
- Experience with SD-WAN platforms on AWS (Cisco, Fortinet, Palo Alto) and Transit Gateway Connect
- Exposure to manufacturing or industrial environments
- Familiarity with AWS Account Factory for Terraform (AFT)
- Working fluency in both Portuguese and English — client conversations in English; team works in Portuguese
#LI-AM2
About the job
- Posted on
- Aug 28, 2026
- Job type
- Full-time
- Location
- BrazilRemote
Keep looking
Related roles you might like
[Job-30394] Senior Fullstack Developer (Java / React), Brazil
Ci&T
[Job-31292] Mid Level Kotlin/Go/ Java Developer, Brazil
Ci&T
[Job - 31359]Sr. Developer FullStack (.Net/React) , Brazil
Ci&T
[Job - 31363] Sr. Developer (.Net / IA), Brazil
Ci&T
[Job - 31251] Senior Data Architect (Databricks), Brazil
Ci&T
[Job - 31116] Mid Level/ Sênior | Backend Java Developer | Brazil
Ci&T
[Job -31294] Mid-Level Developer Fullstack (Java + Angular), Brazil
Ci&T
Explore more
Browse more jobs like this
Disclaimer: Real Jobs From Anywhere is an independent platform dedicated to providing information about job openings. We are not affiliated with, nor do we represent, any company, agency, or agent mentioned in the job listings. Please refer to our Terms of Services for further details.
