[JOB- 31345]SENIOR DEVOPS ENGINEER (CLOUD NETWORK FOUNDATION), BRAZIL
Ciandt
Homeofficesenior
Sign in to applyFree account, takes a minute.
Job description
At CI&T, we help large enterprises transform the potential of AI into real business impact with AI Deployment, AI-native execution, and tech-integrated business solutions.
With 30 years of experience in technological transformation, we accelerate innovation with expertise in Agentic SDLC, Application modernization, Data & AI, Martech and Business strategy.
We are 8,000 CI&Ters across more than 25 countries, collaborating to build solutions with real impact. AI is already part of how we work, evolve, and innovate every day.
You will co-own a multi-account AWS network foundation: hub and spoke on Transit Gateway, centralised inspection, controlled egress, hybrid connectivity into a client's SD-WAN estate through a third-party vendor. You will be in the room when the client's cloud architect asks why a subnet is a /25 and not a /24 — and the answer has to be yours.
The work is unglamorous in the way that matters. Most of what goes wrong in a landing zone does not go wrong in a module — it goes wrong at the seams. We want someone who has been burned by those and now checks for them by reflex.
Responsabilidades:
Own the network foundation end to end: Transit Gateway with separated inspected and uninspected route tables, VPC design across inspection, egress, ingress, shared services, and workload tiers
Define and enforce the routing posture that makes traffic pass a firewall rather than merely sit near one
Verify that posture by test, not by reading your own plan
Design and implement Transit Gateway Connect over GRE with BGP, two peers for availability, ASNs agreed in advance
Extract precise inputs from third-party SD-WAN vendors who are not on your team and do not share your deadline
Manage AWS IPAM with a delegated organisation administrator, pool hierarchy mapped to accounts, RAM shares to spoke accounts
Justify every prefix — "it looked tidy" is not an answer
Implement AWS Network Firewall with stateful rule groups, default drop posture, domain allowlisting, and managed threat signatures
Be the person who knows whether an application failing to reach the internet is the firewall working correctly
Write and maintain Terraform across multiple accounts with per-phase state separation, deployed through GitHub OIDC
Implement drift detection, static validation, and a pipeline that a client can inherit
Manage log delivery into governance accounts, resource policies, KMS key policies, and service-linked roles
Understand that these accept broken configurations silently — and prove delivery by watching a log arrive
Write down why: why a prefix is what it is, why an option was rejected, what a deviation is
Prevent the next engineer from reversing a deliberate choice because nobody recorded the reasoning
Write down why: why a prefix is what it is, why an option was rejected, what a deviation is
Prevent the next engineer from reversing a deliberate choice because nobody recorded the reasoning
Requisitos:
Transit Gateway: association vs. propagation (no hedging), appliance mode, and why it exists
VPC design: Network Firewall, NAT and egress control, PrivateLink, Route 53 Resolver
Hands-on with hub and spoke and centralised inspection — built it, broke it, and fixed it (non-negotiable)
Ability to describe a routing asymmetry you diagnosed or a firewall you had to prove was in the path
Organizations, Control Tower, OUs, SCPs, delegated administrators, RAM
Experience inheriting a landing zone someone else deployed
Module design, state layout across accounts and phases
Read a plan and know before applying whether you are renaming or destroying a resource
Site-to-site VPN or Direct Connect, GRE, BGP peering, route advertisement, ASN allocation
Default to checking the environment rather than trusting a report — including your own
Every serious problem was found by someone querying the account instead of reading a summary
Clear, precise, unhedged prose — a delivery skill, not a nice-to-have
Inglês Avançado/Fluente é obrigatório
Diferencial:
AWS Advanced Networking Specialty certification — or the equivalent scar tissue
Experience with SD-WAN platforms on AWS (Cisco, Fortinet, Palo Alto) and Transit Gateway Connect
Exposure to manufacturing or industrial environments
Familiarity with AWS Account Factory for Terraform (AFT)
Working fluency in both Portuguese and English — client conversations in English; team works in Portuguese
#LI-AM2
Our benefits:
-Health and dental insurance
-Meal and food allowance
-Childcare assistance
-Extended paternity leave
-Partnership with gyms and health and wellness professionals via Wellhub (Gympass) TotalPass;
-Profit Sharing and Results Participation (PLR);
-Life insurance
-Continuous learning platform (CI&T University);
-Discount club
-Free online platform dedicated to physical, mental, and overall well-being
-Pregnancy and responsible parenting course
-Partnerships with online learning platforms
-Language learning platform
And many more!
More details about our benefits here: https://ciandt.com/br/pt-br/carreiras
At CI&T, inclusion starts at the first contact. If you are a person with a disability, it is important to present your assessment during the selection process. See which data needs to be included in the report by clicking here.This way, we can ensure the support and accommodations that you deserve. If you do not yet have the assessment, don't worry: we can support you in obtaining it.
We have a dedicated Health and Well-being team, inclusion specialists, and affinity groups who will be with you at every stage. Count on us to make this journey side by side.