Sr. AWS Platform Engineer

State of MarylandBaltimore City, MD
Hybrid

About The Position

The Senior AWS Platform Engineer serves as ITB's hands-on platform engineering resource for MSDE's AWS environment, executing platform engineering, migration, and cost-management work on production-critical systems that support MSDE programs, Local Education Agencies (LEAs), and the families and providers those programs serve. Reporting to the Director of IT Infrastructure, this position operates within the technical standards and security baselines established by the Department of Information Technology (DoIT), while working directly with MSDE program divisions to plan and execute infrastructure changes that fit each program's operational needs. This position provides core AWS platform engineering across the services and toolsets MSDE relies on, including identity and access management (RBAC), network and firewall administration, and security-aware development practices. The engineer plans and executes lift-and-shift and environment-to-environment migrations, applying change management discipline to protect interfaces and prevent interruption to production-critical systems. Work is performed within DoIT's established AWS standards, security baselines, and toolchains, and within the operational realities and constraints of each MSDE program division being served. The Senior AWS Platform Engineer is responsible for light architecture guidance, FinOps/cost engineering, and cost forecasting for MSDE's AWS footprint, identifying cost drivers and optimization opportunities and translating them into clear reporting for ITB leadership. The position maintains working familiarity with DevOps toolchains and containerized environments, including AWS Fargate and common CI/CD pipelines, in support of ITB's broader technical operations. This position works directly with an ITB Project Manager and with client contacts in program divisions to plan and sequence infrastructure work, and coordinates directly with DoIT's AWS team to execute MSDE's prioritized list of AWS tasks. The engineer is expected to operate with limited supervision, exercising sound independent judgment on day-to-day platform work while proactively raising questions, risks, and dependencies rather than waiting to be asked, and escalating appropriately when a matter falls to DoIT or exceeds established standards. The position provides extensive troubleshooting support across the AWS platform and is expected to understand the operational stakes of production-critical systems, including the systems and interfaces that connect them, well enough to protect uptime during any change. Familiarity with cloud security posture management tools such as Wiz and SIEM platforms such as Microsoft Sentinel is a plus, supporting this position's security-aware approach to platform engineering and development.

Requirements

  • Bachelor’s degree in Computer Science, Information Technology, Systems Engineering, or a related field is required.
  • Three or more years of direct experience provisioning, securing, and maintaining AWS cloud infrastructure, preferably in a public sector environment.
  • Administering Windows Server EC2 instances and AWS WorkSpaces
  • Foundational tasks like AMI creation, container management with EKS and Fargate, and database backup configuration for systems like IBM DB2.
  • Proven experience executing production lift and shift migrations under formal change control
  • Managing cloud cost optimization
  • Enforcing strict role based access control and network security standards.

Nice To Haves

  • Familiarity with cloud security posture management tools such as Wiz
  • Familiarity with SIEM platforms such as Microsoft Sentinel

Responsibilities

  • Perform hands-on AWS platform engineering across core services and toolsets, including IAM, VPCs, subnets/security groups/NACLs, EC2, RDS, KMS, CloudWatch/CloudTrail, and multi-account management (AWS Organizations)
  • Configure and maintain role-based access controls (RBAC) governing platform and application access
  • Apply security-aware development practices, developing and configuring within frameworks and standards defined by DoIT
  • Coordinate directly with DoITs AWS team to execute MSDE's prioritized list of AWS platform tasks
  • Plan and execute lift-and-shift and environment-to-environment migrations for MSDE workloads in AWS
  • Apply change management discipline to moves and migrations affecting production-critical systems, including sequencing and rollback planning
  • Identify and protect system interfaces and integrations during migrations and other platform changes to prevent interruption
  • Work directly with an ITB Project Manager to sequence and schedule infrastructure initiatives
  • Analyze AWS spend to identify cost drivers and optimization opportunities across MSDE's AWS accounts
  • Produce cost forecasts and regular reporting to ITB leadership on AWS spend and variance
  • Provide light architecture input on resource sizing and configuration to support cost efficiency
  • Maintain awareness of cloud security posture and monitoring tooling (e.g., Wiz, Microsoft Sentinel) relevant to cost and risk visibility
  • Recommend cost optimization actions (rightsizing, scheduling, reserved capacity) within DoIT-approved practices
  • Perform extensive troubleshooting across the AWS platform, diagnosing and resolving issues affecting production-critical systems
  • Configure and administer firewall rules and network security settings within DoIT standards
  • Conduct root-cause analysis on recurring or complex issues and implement durable fixes rather than workarounds

Benefits

  • Subsidized health benefits coverage for themselves and their dependents (contractual employees working 30+ hours/week may be eligible)
  • Dental coverage (employee pays full premium)
  • Accidental death and dismemberment insurance (employee pays full premium)
  • Life insurance (employee pays full premium)
  • Leave granted at a rate of one hour for every 30 hours worked, not to exceed 40 hours per calendar year.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service