[Job- 31345]Senior DevOps Engineer (Cloud Network Foundation), Brazil
ciandt
Brazil
Posted Aug 28, 2026
- Other
- Remote
- Centaurus+
Job description
At CI&T, we help large enterprises transform the potential of AI into real business impact with AI Deployment, AI-native execution, and tech-integrated business solutions. With 30 years of experience in technological transformation, we accelerate innovation with expertise in Agentic SDLC, Application modernization, Data & AI, Martech and Business strategy. We are 8,000 CI&Ters across more than 25 countries, collaborating to build solutions with real impact. AI is already part of how we work, evolve, and innovate every day. You will **co-own a multi-account AWS network foundation**: hub and spoke on Transit Gateway, centralised inspection, controlled egress, hybrid connectivity into a client's SD-WAN estate through a third-party vendor. You will be in the room when the client's cloud architect asks why a subnet is a /25 and not a /24 — **and the answer has to be yours.** The work is unglamorous in the way that matters. Most of what goes wrong in a landing zone does not go wrong in a module — it goes wrong at the seams. **We want someone who has been burned by those and now checks for them by reflex.** **Responsabilidades:** - Own the network foundation **end to end**: Transit Gateway with separated inspected and uninspected route tables, VPC design across inspection, egress, ingress, shared services, and workload tiers - Define and enforce the **routing posture** that makes traffic pass a firewall rather than merely sit near one - Verify that posture **by test**, not by reading your own plan - Design and implement **Transit Gateway Connect over GRE with BGP**, two peers for availability, ASNs agreed in advance - Extract precise inputs from **third-party SD-WAN vendors** who are not on your team and do not share your deadline - Manage **AWS IPAM** with a delegated organisation administrator, pool hierarchy mapped to accounts, RAM shares to spoke accounts - Justify **every prefix** — "it looked tidy" is not an answer - Implement **AWS Network Firewall** with stateful rule groups, default drop posture, domain allowlisting, and managed threat signatures - Be the person who knows whether an application failing to reach the internet is **the firewall working correctly** - Write and maintain **Terraform across multiple accounts** with per-phase state separation, deployed through **GitHub OIDC** - Implement drift detection, static validation, and a pipeline that **a client can inherit** - Manage log delivery into governance accounts, resource policies, **KMS key policies**, and service-linked roles - Understand that these accept broken configurations silently — and **prove delivery by watching a log arrive** - Write down **why**: why a prefix is what it is, why an option was rejected, what a deviation is - Prevent the next engineer from reversing a deliberate choice **because nobody recorded the reasoning** - Write down **why**: why a prefix is what it is, why an option was rejected, what a deviation is - Prevent the next engineer from reversing a deliberate choice **because nobody recorded the reasoning** **Requisitos:** - **Transit Gateway**: association vs. propagation (no hedging), appliance mode, and why it exists - **VPC design**: Network Firewall, NAT and egress control, PrivateLink, Route 53 Resolver - Hands-on with **hub and spoke and centralised inspection** — built it, broke it, and fixed it *(non-negotiable)* - Ability to describe a **routing asymmetry you diagnosed** or a firewall you had to prove was in the path - **Organizations, Control Tower, OUs, SCPs**, delegated administrators, RAM - Experience **inheriting a landing zone** someone else deployed - Module design, **state layout across accounts and phases** - Read a plan and know before applying whether you are renaming or **destroying** a resource - **Site-to-site VPN or Direct Connect, GRE, BGP peering**, route advertisement, ASN allocation - Default to **checking the environment** rather than trusting a report — including your own - Every serious problem was found by someone **querying the account** instead of reading a summary - Clear, precise, unhedged prose — a **delivery skill**, not a nice-to-have - ***Inglês Avançado*/Fluente** é obrigatório **Diferencial:** - **AWS Advanced Networking Specialty certification** — or the equivalent scar tissue - Experience with **SD-WAN platforms on AWS** (Cisco, Fortinet, Palo Alto) and Transit Gateway Connect - Exposure to **manufacturing or industrial environments** - Familiarity with **AWS Account Factory for Terraform (AFT)** - **Working fluency in both Portuguese and English** — client conversations in English; team works in Portuguese #LI-AM2