About this role
Region Services Corporate Infrastructure (RSCI) Core Services owns the foundational Windows infrastructure that every team in Amazon Dedicated Cloud (ADC) depends on — Active Directory, DNS, DHCP, DFS, Group Policy, and Enterprise Configuration Manager (ECM). These services run across multiple isolated environments supporting U.S. Government customers. We are not looking for someone to maintain the status quo. Our team is transforming from a manually-operated infrastructure organization into a DevOps-driven engineering team. We need a Systems Development Engineer who will own the design and implementation of our automation architecture — building the Ansible frameworks, AWS pipelines, and operational tooling that eliminate manual processes and enable our services to scale. This is not a "write a playbook when you get time" role. You will architect how we codify, deploy, configure, and lifecycle-manage Windows infrastructure services through automation. You will design reusable Ansible roles and collections, build CI/CD pipelines using AWS CDK, instrument services with CloudWatch monitoring, and establish the patterns that the rest of the team adopts. You need working familiarity with the Windows services we manage — but your primary value is your ability to engineer the systems that manage them. You will also participate in an on-call rotation, owning incidents for the services your automation manages. When things break, you fix them — and then you build the automation that prevents recurrence. The candidate selected must obtain and maintain a security clearance at the TS/SCI with polygraph level. Upon start, the selected candidate will be sponsored for a commensurate clearance for each government agency for which they perform AWS work. Key job responsibilities Own automation architecture: Design and implement the Ansible automation framework (roles, collections, inventories, execution patterns) that manages Core Services infrastructure at scale • Build delivery pipelines: Develop and maintain AWS CI/CD pipelines (CDK, CodePipeline, CodeBuild) that deliver infrastructure changes through tested, repeatable deployments • Instrument and monitor: Build CloudWatch-based observability — dashboards, alarms, and metrics — that provide proactive visibility into service health across isolated environments • Operate and support: Maintain production Windows infrastructure services (AD, DNS, DHCP, DFS, ECM, Group Policy); participate in on-call rotation and provide escalation support • Eliminate manual operations: Identify, prioritize, and migrate manual runbook processes to code-defined, version-controlled automation • Establish engineering standards: Define patterns for infrastructure-as-code, testing, code What This Role Is NOT: • This is not a desktop support or endpoint engineering role • This is not a "keep the lights on" operations role where automation is a side project • This is not a Linux/Unix position — our infrastructure is Windows, our automation targets Windows, and our scripting is PowerShell-heavy • This is a role where you are expected to write code daily, own systems end-to-end, and drive architectural decisions review, and deployment that the team follows — raise the engineering bar • Mentor and lead technically: Guide junior engineers on automation practices, code quality, and operational excellence; drive technical design reviews • Maintain documentation: Create and maintain architecture documentation, automation design docs, and operational runbooks