Senior Cloud Engineer

MaarutToronto, ON
Onsite

About The Position

This role involves setting up and managing a production AWS environment, deploying and configuring various AWS services, implementing CI/CD pipelines with environment-gated deploys, and managing vendor cutovers. The engineer will be responsible for ensuring the security and operational integrity of the production environment, including key management, data residency, and compliance with security policies. The position also requires validating and revising production runbooks and overseeing the deployment of critical infrastructure for applications, blockchain nodes, and transaction layers.

Requirements

  • AWS Organization administrator credentials required for initial setup.
  • Experience with AWS services including IAM, KMS, CloudWatch, S3, and Secrets Manager.
  • Proficiency in Terraform for infrastructure as code.
  • Experience with CI/CD pipelines and environment-gated deployments.
  • Familiarity with key management and security best practices.
  • Experience with vendor integrations and cutovers.
  • Understanding of blockchain technology and related infrastructure (validator keys, multi-party computation).
  • Experience with compliance and screening tools (KYC, Comply Advantage).
  • Ability to work within active windows for critical operations.

Nice To Haves

  • Experience with AWS multi-factor authentication and service-control policies.
  • Knowledge of Object Lock retention for S3.
  • Experience with rotation lambdas for AWS Secrets Manager.
  • Familiarity with asymmetric encryption and migration strategies.
  • Experience with permissioned blockchain nodes.
  • Experience with private-transaction layers.
  • Experience with S-anchored hyper-care.

Responsibilities

  • Create the production AWS account in the Canadian region (ca-central-1), organizationally separate from staging, with Organization-level federation.
  • Apply Parx-built Terraform modules to the production account for baseline service-control policies, KMS keys, IAM roles, CloudWatch alarms, S3 retention, and AWS Secrets Manager.
  • Activate the CI/CD production pipeline with environment-gated deploys (manual approval required for production).
  • Deploy the signed-receipt KMS asymmetric migration to production.
  • Deploy the operational key-custody infrastructure to production, including rotating service keys, validator keys, and privacy keys.
  • Validate and revise Parx-drafted production runbooks against the live environment.
  • Perform live vendor cutovers, including KYC (Persona sandbox) and Comply Advantage integrations.
  • Integrate with Balance Custody testnet and perform production cutover at the production key ceremony.
  • Oversee production cutover and hyper-care (S-anchored).
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service