Senior AWS Cloud Engineer- VDI Platform

APEX Fintech ServicesAustin, TX
Hybrid

About The Position

APEX Fintech's AWS WorkSpaces platform is a production-grade, multi-region AWS serverless system that automates the full lifecycle of Amazon WorkSpaces virtual desktops for a multi-tenant VDI program spanning hundreds of active desktops. We're hiring a Senior AWS Cloud Engineer who will take full ownership of the platform's architecture — designing, building, and automating the systems that keep it running — while serving as the go-to expert for day-to-day production incidents. You'll bring a security- and compliance-first mindset to every decision, ensuring the platform holds up to the standards our regulated fintech environment demands.

Requirements

  • At least 5 years of hands-on AWS experience, including 3+ years with serverless or event-driven architecture in production.
  • 2+ years of experience with Amazon WorkSpaces in a production environment.
  • Multi-region AWS deployment experience; CCR or active-active DR experience is a strong plus.
  • Must have written, deployed, and debugged Python Lambda functions in production.
  • 2+ years of work experience with Terraform to manage real production AWS infrastructure, including remote state.
  • Must demonstrate working experience with WorkSpaces lifecycle management, including create, update, delete, and rebuild operations.
  • Expertise with Python 3.14 Lambda development — handlers, environment variables, error handling.
  • Experience with Lambda concurrency, timeouts, retries, and DLQ behavior.
  • Ability to create, update, and troubleshoot AWS Step Functions, including STANDARD workflows, states, Wait, Choice, and Task.
  • API Gateway — EDGE endpoints, SQS service integration, API key authentication.
  • Experience with DynamoDB single-table design, including partition keys, sort keys, GSIs, and related access patterns.
  • Must demonstrate expertise with SNS, including topic subscriptions, message filtering, and error notification patterns.
  • Experience working with Terraform in multi-region deployments and provider configuration.
  • Configuration management using Ansible, including playbooks, roles, inventory management, idempotent task design, and Ansible Vault.
  • Hands-on experience with observability and resilience tooling (CloudWatch Logs Insights/metrics/alarms, Route53 health checks/failover routing) as well as Datadog for serverless observability.
  • AWS KMS Multi-Region Keys, including replication, key policy, and encryption context.
  • AWS IAM administration — users, groups, roles, permission boundaries, and cross-account role assumption.

Nice To Haves

  • VPC design for WorkSpaces (subnets, route tables, NAT Gateway, Transit Gateway, security groups)
  • Custom domain management (Route53, ACM certificates, API Gateway custom domains)
  • Cost optimization for WorkSpaces.
  • Infrastructure security scanning (Checkov, tfsec)
  • Knowledge of security frameworks and controls, including CIS benchmarks, NIST, device compliance, and conditional access.
  • Experience supporting regulated environments, such as FINRA, SEC, FedRAMP, NIST, or SOC environments.
  • Strong communication skills, with the ability to explain technical decisions to both engineering peers and non-technical stakeholders.
  • AWS Solutions Architect – Professional
  • AWS DevOps Engineer – Professional
  • AWS SysOps Administrator – Associate
  • Cross-Region Replication (CCR) design patterns / multi-region DR architecture
  • Experience with ITIL practices, service management tooling, and building actionable SLOs and SLIs.
  • Familiarity with compliance and regulatory requirements in financial services.
  • Experience with DLP (Data Loss Prevention) and endpoint security in regulated environments.

Responsibilities

  • Own the architecture, code quality, and evolution of the platform — driving decisions on new capabilities, DR testing, scaling, and Terraform IaC.
  • Serve as the primary escalation point for engineering questions related to the system.
  • Diagnose and resolve production incidents quickly, tracing failures end-to-end across Lambda, SQS, DynamoDB, SNS, and CloudWatch Logs.
  • Support day-to-day VDI operations: image builds, bundle management, directory configuration, client connectivity, and user-facing troubleshooting.
  • Bridge the gap between infrastructure automation and end-user desktop experience.
  • Mentor junior engineers on AWS serverless architecture, operational best practices, and production troubleshooting.
  • Own the deployment and integration of Datadog monitoring for the AWS VDI stack, including metrics, logs, traces, dashboards, SLOs, and alerting.

Benefits

  • healthcare benefits (medical, dental and vision, EAP)
  • competitive PTO
  • 401k match
  • parental leave
  • HSA contribution match
  • paid subscription to the Calm app
  • generous external learning and tuition reimbursement benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service