Now hiring

Senior Cloud Engineer (Toronto, ON, CA, M5J 2P1) @ GFT Technologies SE - Job Offerings

Toronto, ON, CA, M5J 2P1OnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

<p style="text-align:center"><span style="font-size:18.0pt"><strong>**This is a contract role with a contract duration of 6-12 months at a pay rate of 90-95$/hr 40 hrs a week**</strong></span></p> <div> <h1><span style="font-size:14.0pt"><strong>Senior Cloud Engineer (AWS / Terraform / Security &amp; Production Readiness)</strong></span></h1> <h3><span style="font-size:14.0pt"><strong>Location:</strong> Toronto / Montreal (Hybrid – mandatory)</span></h3> <h3><span style="font-size:14.0pt"><strong>Experience:</strong> 7–10+ years</span></h3> <h3><span style="font-size:14.0pt"><strong>Employment Type:</strong> Full-time / Contract</span></h3> <hr> <h2><span style="font-size:14.0pt"><strong>Role Overview</strong></span></h2> <p><span style="font-size:14.0pt">We are looking for a <strong>Senior Cloud Engineer</strong> to lead <strong>production readiness, secure cloud deployment, and live cutover of a regulated, high-assurance platform</strong>.</span></p> <p><span style="font-size:14.0pt">This role is critical in ensuring that <strong>AWS production environments are secure, compliant, and operationally resilient</strong>, with a strong focus on <strong>infrastructure as code (Terraform), security controls, key management, and production deployment practices</strong>.</span></p> <p><span style="font-size:14.0pt">You will work at the intersection of <strong>cloud engineering, security, and platform operations</strong>, supporting a <strong>high-stakes production launch and vendor integrations</strong>.</span></p> <hr> <h2><span style="font-size:14.0pt"><strong>Key Responsibilities</strong></span></h2> <h3><span style="font-size:14.0pt"><strong>1. Production Environment Setup &amp; Governance</strong></span></h3> <ul> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Establish and configure <strong>AWS production environments (ca-central-1)</strong> separated from non-production accounts</span></li> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Implement <strong>multi-account governance and federation models</strong> aligned with enterprise standards</span></li> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Apply <strong>infrastructure-as-code (Terraform)</strong> modules to enforce:</span> <ul> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Service Control Policies (SCPs)</span></li> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Data residency controls</span></li> <li style="font-size:14.0pt"><span style="font-size:14.0pt">MFA enforcement and root access restriction</span></li> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Public access protections (e.g., S3 hardening)</span></li> </ul> </li> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Configure <strong>monitoring, alerting, and centralized logging</strong> using CloudWatch and log aggregation solutions</span></li> </ul> <h3><span style="font-size:14.0pt"><strong>2. Security &amp; Key Management Infrastructure</strong></span></h3> <ul> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Implement and manage <strong>customer-managed KMS keys</strong>, including asymmetric key configurations</span></li> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Deploy and maintain <strong>secure key custody frameworks</strong>, including:</span> <ul> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Application service keys (rotating)</span></li> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Blockchain validator keys</span></li> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Privacy/encryption keys for sensitive transaction layers</span></li> </ul> </li> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Ensure secure handling of secrets via <strong>AWS Secrets Manager with automated rotation</strong></span></li> </ul> <hr> <h3><span style="font-size:14.0pt"><strong>3. CI/CD &amp; Production Deployment</strong></span></h3> <ul> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Activate and manage <strong>production CI/CD pipelines with environment gating and approvals</strong></span></li> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Deploy applications and infrastructure using <strong>controlled release mechanisms</strong></span></li> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Lead <strong>production deployments</strong> of pre-validated components (from dev &amp; staging) including:</span> <ul> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Encryption and signing mechanisms</span></li> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Security-sensitive platform components</span></li> </ul> </li> </ul> <hr> <h3><span style="font-size:14.0pt"><strong>4. Production Readiness &amp; Runbook Validation</strong></span></h3> <ul> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Validate and refine <strong>production runbooks</strong> against real-world system behaviour</span></li> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Identify and address gaps between staging and production environments</span></li> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Ensure <strong>operational readiness, incident response alignment, and monitoring coverage</strong></span></li> </ul> <hr> <h3><span style="font-size:14.0pt"><strong>5. Vendor Integration &amp; Cutover</strong></span></h3> <p><span style="font-size:14.0pt">Own the <strong>end-to-end integration and production cutover</strong> of critical third-party services:</span></p> <ul> <li style="font-size:14.0pt"><span style="font-size:14.0pt"><strong>KYC systems (e.g., Persona)</strong></span> <ul> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Transition from mock → sandbox → production</span></li> </ul> </li> <li style="font-size:14.0pt"><span style="font-size:14.0pt"><strong>Compliance platforms (e.g., sanctions, PEP screening)</strong></span> <ul> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Ensure secure data flows and operational stability</span></li> </ul> </li> <li style="font-size:14.0pt"><span style="font-size:14.0pt"><strong>Custody / MPC platforms (multi-party computation)</strong></span> <ul> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Support secure key ceremonies and production rollout</span></li> </ul> </li> </ul> <hr> <h3><span style="font-size:14.0pt"><strong>6. Hypercare &amp; Production Support</strong></span></h3> <ul> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Support <strong>live production cutover</strong> and stabilization phases</span></li> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Monitor platform health, performance, and security posture</span></li> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Rapidly respond to incidents during <strong>hypercare period</strong></span></li> </ul> <hr> <h2><span style="font-size:14.0pt"><strong>Required Skills &amp; Experience</strong></span></h2> <ul> <li style="font-size:14.0pt"><span style="font-size:14.0pt">7+ years in <strong>cloud engineering / platform engineering roles</strong></span></li> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Strong hands-on experience with <strong>AWS (multi-account environments)</strong></span></li> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Deep expertise in <strong>Terraform (modular design, IaC best practices)</strong></span></li> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Proven experience implementing:</span> <ul> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Cloud security frameworks (IAM, SCPs, KMS, Secrets Manager)</span></li> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Monitoring &amp; observability (CloudWatch, logging pipelines)</span></li> </ul> </li> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Experience with <strong>CI/CD pipelines and controlled production deployments</strong></span></li> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Strong understanding of:</span> <ul> <li style="font-size:14.0pt"><span style="font-size:14.0pt"><strong>Production readiness and release management</strong></span></li> <li style="font-size:14.0pt"><span style="font-size:14.0pt"><strong>Secure architecture and data protection controls</strong></span></li> </ul> </li> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Experience supporting <strong>high-risk production cutovers or regulated environments</strong></span></li> </ul> <hr> <h2><span style="font-size:14.0pt"><strong>Nice to Have</strong></span></h2> <ul> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Experience with <strong>blockchain or cryptographic key management systems</strong></span></li> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Exposure to <strong>MPC (multi-party computation) or custody platforms</strong></span></li> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Familiarity with <strong>compliance/KYC integrations</strong></span></li> <li style="font-size:14.0pt"><span style="font-size:14.0pt">AWS certifications (Solutions Architect / DevOps / Security)</span></li> </ul> <hr> <h2><span style="font-size:14.0pt"><strong>What You Bring</strong></span></h2> <ul> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Ownership mindset with ability to <strong>lead production-critical initiatives</strong></span></li> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Strong problem-solving skills in <strong>high-pressure environments</strong></span></li> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Ability to work across <strong>engineering, security, and vendor teams</strong></span></li> <li style="font-size:14.0pt"><span style="font-size:14.0pt">Clear communication and documentation skills</span></li> </ul> </div>

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores