Senior Cloud Engineering Architect - Evinova

AstraZenecaGaithersburg, MD
$187,000 - $246,000Hybrid

About The Position

Evinova is a health-tech business focused on accelerating better health outcomes by advancing digital transformation across the life sciences sector. By combining science-based expertise, evidence-led rigor, and deep human insight, we design digital solutions that enable healthcare to work better for everyone. Operating at the intersection of healthcare, technology, data, and analytics, we are helping unlock the full potential of digital health, transforming how clinical research is conducted, how care is delivered, and how patients experience healthcare. Our solutions are built to scale, driving efficiency, improving decision-making, and ultimately delivering better outcomes for patients worldwide. At Evinova, we are driven by a shared purpose to transform health through data and digital innovation. Our teams collaborate across disciplines to solve complex challenges, continuously learning and evolving in a fast-paced, high-impact environment. We also recognize the importance of flexibility and balance. Our ways of working support both individual needs and team collaboration. To foster connection and collaboration, employees are expected to work from the office three days per week, creating opportunities for in-person teamwork, innovation, and meaningful connection. As a DevOps/Cloud Infrastructure leader at Evinova, you'll help design, build, and operate the secure, scalable cloud foundation behind our digital health products. You'll take a hands-on technical leadership role across AWS, Kubernetes/EKS, infrastructure as code, CI/CD, security, observability, and automation, supporting highly available, multi-tenant SaaS platforms. You'll work closely with engineering, product, and security teams to strengthen platform reliability, scalability, and operational excellence while helping establish cloud engineering best practices across the organization.

Requirements

  • 10+ years in DevOps or cloud infrastructure roles, with significant experience in SaaS and multi-tenant platforms.
  • Proven track record of mentoring team members in Cloud infrastructure related projects.
  • Expert knowledge of AWS services, including VPC, IAM, EC2, S3, RDS, Lambda, EKS, AWS WAF, AWS EventBridge, and AWS CloudTrail.
  • Deep proficiency in Docker, Kubernetes, Helm, and associated ecosystem tools.
  • Expertise in CI/CD tools such as ArgoCD and GitHub Actions.
  • Advanced experience with AWS CDK (TypeScript preferred) and CloudFormation.
  • Strong understanding of AWS networking services such as VPCs, Transit Gateway, ALB, and Security Groups.
  • In-depth knowledge of IAM, AWS KMS, encryption standards, AWS WAF, and security compliance frameworks including NIST.
  • Extensive experience with OpenTelemetry, Prometheus, Grafana, AWS CloudWatch, and AWS CloudTrail for monitoring and incident response.
  • Familiarity with AWS Glue and Managed Kafka for real-time and batch data processing.
  • Strong scripting and automation skills using TypeScript and Bash.
  • Experience managing multiple AWS accounts with AWS Control Tower.
  • Exceptional verbal and written communication skills, with the ability to explain complex technical concepts to diverse stakeholders.

Nice To Haves

  • Advanced expertise in AWS CDK, including building complex, reusable constructs and pipelines.
  • Familiarity with Projen for automating CDK project configuration and management.
  • Hands-on experience with Helm charts and Kubernetes manifests.
  • Experience with monitoring and logging tools such as Prometheus, Grafana, and AWS CloudWatch.
  • Exposure to multi-tenant SaaS platforms and best practices.
  • Experience working with AI tools and frameworks.

Responsibilities

  • Architect and manage scalable, multi-tenant AWS-based infrastructure using AWS CDK, ensuring modular and maintainable codebases.
  • Lead the deployment and management of Kubernetes clusters using Amazon EKS, implementing best practices for scalability and security.
  • Build, manage, and enhance automated CI/CD pipelines to ensure efficient, reliable deployments using tools like ArgoCD and GitHub Actions.
  • Design, maintain, and optimize IAM roles, policies, and guardrails to ensure least privilege access across AWS resources.
  • Architect and maintain AWS networking components such as VPCs, Transit Gateway, ALB, and Security Groups, ensuring robust security and performance.
  • Implement DevSecOps best practices, including IAM security, encryption standards, and compliance with industry regulations (GXP, GDPR, HIPAA, NIST).
  • Design and implement firewall policies and AWS WAF configurations to protect applications from web threats.
  • Lead efforts to automate infrastructure provisioning, application releases, and ETL workflows, reducing manual intervention and improving efficiency.
  • Develop and implement comprehensive monitoring, logging, and alerting systems using OpenTelemetry, Prometheus, Grafana, AWS CloudWatch, and AWS CloudTrail.
  • Utilize AWS EventBridge for event-driven automation and troubleshoot security and operational issues using AWS CloudTrail.
  • Drive governance processes, including security reviews, cost optimization, and operational consistency across the platform.
  • Manage multiple AWS accounts using AWS Control Tower and best practices for account isolation.
  • Mentor and guide junior and mid-level engineers, fostering a culture of learning and collaboration. Provide technical leadership in the adoption of AWS CDK and best practices for cloud automation.
  • Partner with cross-functional teams, including product management and security, to align DevOps strategies with business goals and ensure cohesive development and operational workflows.

Benefits

  • short-term incentive bonus opportunity
  • equity-based long-term incentive program
  • qualified retirement program [401(k) plan]
  • paid vacation and holidays
  • paid leaves
  • health benefits including medical, prescription drug, dental, and vision coverage
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service