Overview:
HealthEdge® offers AI-powered operational infrastructure for health insurance companies, guaranteeing an enduring financial edge in an increasingly competitive market. We're experiencing strong market momentum, with a growing number of health plans choosing HealthEdge to modernize their operations and compete more effectively. As we expand, we're investing in the people who power that growth, making this a pivotal moment to join us and shape the future of healthcare technology. Learn more at HealthEdge.com.
We're looking for a Senior Cloud Infrastructure Engineer to own the design, resilience, and day-to-day health of HealthEdge's infrastructure across AWS and our hybrid on-prem/Azure/GCP estate. This role sits at the intersection of cloud engineering and infrastructure engineering spanning AWS migration execution, disaster recovery, patching and platform currency, and the security/compliance controls that keep our security obligations intact. It's a hands-on senior IC role for someone who wants deep ownership of infrastructure resilience across a large, multi-account, multi-platform environment that's actively migrating off legacy on-prem infrastructure.
Areas of Responsibility:
Infrastructure and Hybrid Cloud Architecture
- Design, build, and maintain infrastructure across AWS (primary), with supporting work in Azure and GCP, plus the on-prem estate still in active retirement
- Own infrastructure across the environments including secure configuration baselines and patch management for OS images and on-prem hardware
- Build and maintain reusable, auditable Infrastructure as Code for cloud deployments, and for remaining on-prem server deployment.
- Support cloud networking execution, VPC provisioning, security group standards, and related connectivity work.
- Manage storage across cloud and legacy on-prem storage as workloads migrate; contribute to on-prem retirement and datacenter decommissioning efforts.
- Support AWS migration execution for in-flight waves, including server deployments and resource change requests via IaC.
Disaster Recovery & Resilience
- Own disaster recovery architecture and execution across cloud environments.
- Maintain DR solutions and backup strategy and run DR drills on a regular cadence; document gaps and drive remediation.
- Design for resilience from the start and treat recoverability as a first-class requirement, not an afterthought.
Security, Compliance & Vulnerability Management
- Contribute to vulnerability management triage across infrastructure teams, threat detection, and infra security findings review.
- Support PHI/PII classification scanning, penetration test coordination, and security exception approvals.
- Maintain compliance controls; support HIPAA and SOC 2 audit readiness, access review and recertification, evidence collection, and change freeze coordination.
- Maintain EKS container runtime security sensor coverage as part of ongoing platform hardening.
Cloud Infrastructure Operations
- Design and manage roles and cross-account access controls following least-privilege principles across multi-account, multi-cloud environments.
- Own cloud execution: load balancers, DNS (), VPC provisioning, and security group standards.
- Manage compute resources at scale with an eye toward right-sizing and long-term maintainability.
- Administer cloud storage and database services with attention to cost, performance, and resilience.
- Own infrastructure health, cost, and performance monitoring using native and third-party tooling, building the observability that lets issues surface before they become incidents.
- Administer and harden Linux and Windows Server environments across cloud and on-prem, including patching, performance tuning, troubleshooting, Active Directory integration, Group Policy, DNS, and certificate services.
- Manage hybrid identity and authentication across on-prem and cloud workloads, and maintain OS-level security baselines and hardening standards across the estate.
CI/CD, Automation & Delivery
- Build and evolve CI/CD pipelines for secure, repeatable infrastructure deployments.
- Write automation to reduce manual toil and enforce operational consistency across cloud and on-prem environments.
- Take solutions from proof-of-concept to production with an eye toward long-term maintainability, not just getting it working once.
Reliability, Monitoring & Incident Response
- Monitor, scale, and maintain production infrastructure with availability, performance, and security as top priorities.
- Participate in on-call rotation; serve as L2 escalation point for cross-team infrastructure support; lead root cause analysis and drive incident retrospectives to closure.
- Author and maintain runbooks that hold up under pressure, not just at handoff.
Cost & Tagging Governance
- Contribute to FinOps efforts: identify and remediate cost anomalies, own tagging remediation against enterprise tagging standards, and make pragmatic cost/performance/resilience tradeoffs.
AI-Enabled Engineering
- Use AI coding assistants to accelerate IaC development, scripting, and troubleshooting.
- Use AI tooling to draft first-pass runbooks, DR documentation, and incident retrospectives to validate and refine before publishing.
Collaboration & Documentation
- Document architecture, DR runbooks, and standard operating procedures others can actually follow under pressure.
- Provide technical guidance to product teams on infrastructure resilience, migration sequencing, and recovery design.
Required Qualifications
- 5+ years of hands-on cloud infrastructure engineering experience, with deep expertise in AWS and in other cloud environments.
- Direct experience with disaster recovery design and execution.
- Strong Infrastructure as Code experience (CDK, Terraform, or CloudFormation).
- Experience with containerized environments and Kubernetes/EKS, including version upgrade and lifecycle management.
- Linux and Windows Server administration experience, including patching and OS lifecycle management at scale.
- Solid IAM design experience, including cross-account access and least-privilege enforcement.
- Strong scripting ability (Python, Bash, or PowerShell).
- Experience building and maintaining CI/CD pipelines.
- Comfortable being the primary on-call and L2 escalation point for infrastructure incidents.
Preferred Qualifications
Experience operating in regulated environments (FedRAMP, HIPAA, SOC 2) and understanding of what that means for infrastructure and DR design specifically.
- AWS certification (Solutions Architect or SysOps, Associate or Professional).
- Experience with hybrid infrastructure, bridging on-prem virtualization with cloud-native services during active migration.
- Familiarity with DISA STIG or CIS benchmark hardening, and vulnerability management/triage workflows.
- FinOps or cost governance experience, including tagging standards enforcement.
- Healthcare technology or digital health platform background.
- Experience with AI-assisted engineering workflows as part of daily practice.
Behaviors & Traits
- Raises risk early rather than waiting for it to become an incident.
- Comfortable with ambiguity in a large, multi-account, evolving cloud environment.
- Strong sense of ownership; closes gaps rather than escalating and waiting.
- Communicates technical tradeoffs clearly to both engineers and non-technical stakeholders.
Geographic Responsibility: Remote, US
Type of Employment: Full-time, permanent
FLSA Classification (USA Only): Exempt
Work Environment: The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job:
- The employee is occasionally required to move around the office. Specific vision abilities required by this job include close vision, color vision, peripheral vision, depth perception, and ability to adjust focus.
- Work across multiple time zones in a hybrid or remote work environment.
- Long periods of time sitting and/or standing in front of a computer using video technology.
- May require travel dependent on company needs.
The above statements are intended to describe the general nature and level of the job being performed by the individual(s) assigned to this position. They are not intended to be an exhaustive list of all duties, responsibilities, and skills required. HealthEdge reserves the right to modify, add, or remove duties and to assign other duties as necessary. In addition, reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of this position in compliance with the Americans with Disabilities Act of 1990. Candidates may be required to go through a pre-employment criminal background check.
HealthEdge is an equal opportunity employer. We are committed to workforce diversity and actively encourage all qualified persons to seek employment with us, including, but not limited to, racial and ethnic minorities, women, veterans and persons with disabilities.
#LI-Remote
**The annual US base salary range for this position is $110,000 to $118,000. This salary range may cover multiple career levels at HealthEdge. Final compensation will be determined during the interview process and is based on a combination of factors including, but not limited to, your skills, experience, qualifications and education.