We're seeking an experienced Platform Engineer to design, build, and operate secure, scalable hybrid cloud network infrastructure on AWS. You'll work across platform, security, and infrastructure teams to deliver highly available cloud connectivity solutions, focusing on automation, reliability, and operational excellence.
Required Qualifications
Bachelor's in Computer Science/Engineering or equivalent professional experience
6-8 years in platform engineering, SRE, or cloud engineering with strong AWS networking focus
AWS Advanced Networking – Specialty Certification or equivalent hands-on expertise with VPCs, subnets, Transit Gateways, Route 53, Direct Connect, and VPNs
Strong system design and troubleshooting skills
Hands-on experience architecting hybrid on-premises ↔ AWS connectivity
Hands-on firewall operations experience (AWS Network Firewall, NACLs, Security Groups, WAF in production environments)
Core Responsibilities
Design and implement secure, scalable AWS network architectures (VPCs, subnets, routing, multi-tenant isolation)
Architect hybrid connectivity solutions using Direct Connect, VPNs, Transit Gateways
Design and implement firewall strategies: Network ACLs, Security Groups, AWS Network Firewall, and WAF rules aligned with security best practices
Advanced understanding of NACLs, Security Groups, WAF, and AWS Network Firewall
Implement Route 53, DHCP, AWS PrivateLink, and DNS/IPAM solutions
Design high-availability and disaster recovery network architectures
Create and maintain network architecture diagrams and SOPs
Collaborate with Infosec team to design network architectures that align with threat models and security controls
Participate in security incident response involving network systems
Develop and maintain Terraform modules for AWS infrastructure with security guardrails embedded (e.g., encryption at rest/transit, least-privilege IAM policies, NACLs, Security Groups)
Partner with Infosec to establish and enforce Terraform coding standards and security controls
Build environment aware Terraform modules for reusability
Implement GitOps workflows and promote infrastructure changes across dev/staging/prod
Automate firewall rule provisioning and updates; implement drift detection for security controls
Automate operational tasks using Python and shell scripting
Manage backup and recovery procedures
Implement CI/CD integration for infrastructure deployments
Audit, maintain, and troubleshoot firewall rules and security controls (NACLs, Security Groups, Network Firewall, WAF) including rule optimization, change management, incident response, and compliance reviews
Design and implement monitoring/alerting using DataDog, Prometheus and AWS CloudWatch
Analyze VPC Flow Logs and AWS networking metrics for performance optimization
Lead troubleshooting of complex network and platform issues
Participate in on-call rotation
Maintain runbooks and operational documentation
Platform Architecture (40%)
Infrastructure Automation (40%)
Operations & Observability (20%)
Mandatory Skills
AWS Networking & Firewall Operations: VPC, peering, subnets, Transit Gateways, Route 53, Direct Connect, VPNs, NACLs, Security Groups, AWS Network Firewall, WAF, AWS PrivateLink, IPAM
Firewall Rule Management: Writing, debugging, and maintaining network ACLs and Security Groups at scale; understanding of stateful vs. stateless filtering AWS Services: EC2, RDS, ECS/EKS, Lambda, IAM, CloudFormation, S3
Infrastructure as Code: Terraform (primary); CloudFormation exposure
Programming: Python + Bash/Shell scripting
Linux fundamentals and networking (TCP/IP, routing, DNS)
On-call operational support
Preferred Qualifications
AWS Advanced Networking – Specialty Certification
Kubernetes / service mesh networking experience (Istio, Envoy)
Multi-account AWS organization management
CI/CD platform experience (GitLab CI, GitHub Actions, Jenkins)
Monitoring/observability tools: Prometheus, ELK stack
Compliance frameworks: SOC 2, ISO 2700
Skills Required
- Bachelor's degree in Computer Science/Engineering or equivalent professional experience
- 6-8 years in platform engineering, SRE, or cloud engineering with strong AWS networking focus
- AWS Advanced Networking - Specialty certification or equivalent hands-on expertise with VPCs, Transit Gateways, Route 53, Direct Connect, VPNs
- Hands-on experience architecting hybrid on-premises to AWS connectivity
- Hands-on firewall operations experience (AWS Network Firewall, NACLs, Security Groups, WAF) in production
- Strong system design and troubleshooting skills
- Experience developing and maintaining Terraform modules for AWS infrastructure with security guardrails
- Experience with Infrastructure as Code and CI/CD integration for infrastructure deployments (GitOps)
- Programming and automation using Python and Bash/Shell scripting
- Linux fundamentals and networking knowledge (TCP/IP, routing, DNS)
- On-call operational support and incident response participation
- Experience with monitoring/observability tools (DataDog, Prometheus, AWS CloudWatch)
- Exposure to CloudFormation and AWS services (EC2, RDS, ECS/EKS, Lambda, S3, IAM)
- Kubernetes / service mesh networking experience (Istio, Envoy)
- Multi-account AWS organization management experience
- CI/CD platform experience (GitLab CI, GitHub Actions, Jenkins)
- Monitoring/observability stack experience (Prometheus, ELK)
- Familiarity with compliance frameworks (SOC 2, ISO 27001)
Smarsh Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Smarsh and has not been reviewed or approved by Smarsh.
-
Leave & Time Off Breadth — Time off is characterized by unlimited PTO, generous vacation allowances, and paid holidays, with policies that support taking time away. These elements are positioned as a core strength that helps balance lower base pay in some roles.
-
Wellbeing & Lifestyle Benefits — Perks include wellness programs, commuter and bike reimbursement, volunteer time off, peer recognition, remote-work support, and a sabbatical option. The variety of non-salary benefits contributes to a supportive work-life environment.
-
Retirement Support — A 401(k) with employer match and profit sharing is offered, with immediate vesting described for the match. This strengthens the long-term financial component of total rewards.
Smarsh Insights
What We Do
Smarsh provides cloud-based archiving and compliance solutions for companies in regulated and litigious industries.









