Cloud Engineer
Join the mission to make the digital world safer.
About Team Cymru
Team Cymru's mission is to make the digital world safer by helping organizations track and disrupt cybercriminals, protect critical infrastructure, and ultimately save lives.
We provide unmatched visibility into global internet activity through our Pure Signal™ platform, giving customers insight into external threats at a scale few organizations can match. Our intelligence is trusted by organizations across government, enterprise, and the broader cybersecurity ecosystem.
As a mission-driven organization, our work has a real-world impact, supporting efforts that protect national security, critical infrastructure, and millions of people worldwide. We are a trusted partner to global leaders in cybersecurity and government, delivering intelligence that helps organizations stay ahead of evolving threats.
Team Cymru is a fast-paced, distribution-focused, private equity–backed company where your work directly supports a mission that protects millions worldwide.
We're hiring a Cloud Engineer to help run and grow our AWS environment. This is a hands-on junior-to-mid-level role: you'll administer our multi-account AWS Organization, build and deploy infrastructure as code, and keep the environment secure, well-governed, and cost-efficient. Your focus is the cloud infrastructure and platform layer itself, the accounts, identity, guardrails, networking, and services that let application engineers thrive, rather than building or operating the applications that run on top of it. You'll also support our on-premises private cloud, working alongside and learning from the Site Reliability Engineering team as you grow your automation skills. You'll participate in a shared on-call rotation, with clear room to develop toward senior cloud and reliability work.
Key Responsibilities:
Cloud Infrastructure & Operations
● Administer the AWS Organization, managing accounts, organizational units, and the multi-account structure day to day
● Administer IAM (users, roles, policies, least-privilege access) along with secrets and key management (Secrets Manager, KMS)
● Implement and maintain governance guardrails, including Service Control Policies (SCPs), Control Tower guidelines, and Account Factory provisioning, under senior guidance
● Design, deploy, and maintain infrastructure as code with CloudFormation, using version control, change sets, and drift detection, and take part in the CI/CD process for templates
● Administer networking and VPCs, including subnets, routing, security groups, and connectivity
● Manage billing and cost: budgets and alerts, cost-allocation tagging, and rightsizing/optimization recommendations
● Maintain resource tagging and governance standards that feed cost allocation and AWS Config rules
Security, Monitoring & Cross-Team Collaboration
● Operate cloud observability, including CloudWatch metrics, logs, and alarms, and CloudTrail, and respond to alerts
● Maintain baseline cloud security services (GuardDuty, Security Hub, AWS Config) and respond to infrastructure-layer security findings in partnership with the Security team
● Support the on-premises private cloud through process-improvement automation, monitoring automation, and application integration, working closely with and learning from the SRE team
● Take part in a shared on-call rotation, responding to incidents and driving resolution
● Maintain documentation and runbooks
Qualifications & Experience
● AWS Certified Cloud Practitioner or an AWS Associate-level certification
● 1-3 years of hands-on AWS experience (junior to mid-level)
● Working knowledge of AWS Organizations, IAM, and multi-account concepts
● Experience with infrastructure as code, especially CloudFormation
● Familiarity with VPC networking (subnets, routing, security groups)
● Exposure to AWS cost management and governance (SCPs, tagging, budgets)
Additional Skills
● Comfortable scripting in Bash and/or Python
● Willingness to learn on-prem virtualization and to join an on-call rotation
● Hands-on Control Tower and Account Factory experience (nice to have)
● CloudWatch/CloudTrail observability and baseline security services like GuardDuty, Security Hub, AWS Config (nice to have)
● Secrets Manager / KMS experience (nice to have)
● Git-based workflows and CI/CD for infrastructure as code (nice to have)
Education and Certifications
● AWS Certified Cloud Practitioner or AWS Associate-level certification required
● Exposure to on-prem hypervisors (Xen, Proxmox) or Linux administration a plus
● Background in a security- or threat-intelligence-conscious environment a plus
Travel
Minimal to occasional travel may be required depending on team needs.
Why Join Team Cymru?
At Team Cymru, we provide unmatched global threat intelligence that empowers organizations to proactively disrupt adversaries. You'll be at the forefront of cybersecurity innovation, helping customers harness the full power of our threat intelligence to achieve critical business and security outcomes.
We offer a collaborative, mission-driven culture where your expertise and impact will directly contribute to improving global security.
Ready to make an impact?
Apply now and help shape the financial future of a company protecting millions worldwide.
This job description is not exhaustive. Responsibilities may evolve as needed. Team Cymru is an equal opportunity employer and welcomes applicants from all backgrounds. This is a remote position.