
Cloud Engineer AWS ( CDK / Serverless) ( 102-09SENG-01 )
- Terraform
- WAF
- mTLS
- REST API
- Node.js
- X-ray
- POS
- OIDC
- ServiceNow
- SQS
- KMS
- AWS
- IaC
- AWS CDK
- TypeScript
- CloudFormation
- API Gateway
- ACLS
- IAM
- CI/CD
- GitHub Actions
- CloudWatch
This role modifies a live serverless gateway in production โ no downtime, no change in behaviour โ leaving a clean handoff point for a downstream build managed in Terraform. This is careful surgery on production infrastructure with active external consumers, not a greenfield build.
The scope includes modernizing a CDK estate made up of four stacks, six Lambda functions, a WAF web ACL, an mTLS custom domain/truststore, and a REST API โ preserving resource identity during consolidation and coordinating two sequenced deployments with a tested rollback path.
What you will do
Inventory the CDK estate and build a modernization plan: upgrade the CDK library/CLI, replace deprecated constructs, move hardcoded context into per-environment config.
Consolidate duplicated stacks into shared constructs without losing resource identity โ map logical IDs before and after, pick a preservation method, and confirm nothing gets replaced before touching production.
Run the library upgrade and the stack refactor as two separate, ordered deployments, with a rollback path tested in dev and test first.
Migrate all six Lambda functions from Node 18 to Node 24, close an open PII logging finding, and regression-test each one.
Re-verify the security perimeter after both deployments โ WAF, the mTLS domain and truststore, X-Ray tracing, upstream timeouts โ working directly with the customer's POS team across all six external callers.
Build deployment pipelines for dev/test/prod with OIDC federation, approval gates, and a ServiceNow change step. Add CDK assertion tests, drift detection, and API access log retention.
Publish the SQS queue ARN and KMS key ARN via Parameter Store, and grant send permission to the downstream Terraform-managed system โ this is the key ordering dependency for that team's build.
Align naming, tagging, and documentation with the customer's internal standards, and document your identity-preservation decisions clearly enough for the next engineer to follow.
5+ years with AWS, including 3+ years working in infrastructure-as-code.
Hands-on AWS CDK experience in TypeScript โ construct trees, logical ID derivation, and what happens when a construct path changes.
Real experience with CloudFormation resource identity: stack refactoring, logical ID overrides, cdk diff against deployed state, drift detection.
Working Terraform knowledge โ comfortable operating across the CDK/Terraform boundary.
Solid AWS serverless background: Lambda, API Gateway (REST), SQS and DLQs, Parameter Store, KMS, Secrets Manager.
Experience with AWS edge and security services โ WAF web ACLs, mutual-TLS custom domains and truststores, cross-account/cross-boundary IAM.
Practical experience migrating Nodejs runtimes (e.g. Node 18 โ 24), including dependency and deprecation handling.
CI/CD pipeline experience with OIDC federation and approval gates (GitHub Actions or equivalent).
Working knowledge of observability tools โ X-Ray, CloudWatch metrics and alarms, log retention.
Comfortable communicating clearly with non-engineers, and working well when parts of the scope are still being figured out.
Fluent English (C1 level) for daily communication with the client.
Engagement details
Hourly contractor
100% remote
Estimated duration: 6โ8 weeks
Time zone: EST or MST
Cloud Engineer AWS ( CDK / Serverless) ( 102-09SENG-01 ) ยท Cloudary SAS