- Location
- Brazil
- Workplace
- Remote
- Department
- Centaurus+
- Seniority
- Senior
- Experience
- 30+ years
- Source
- Lever
Description
At CI&T, we help large enterprises transform the potential of AI into real business impact with AI Deployment, AI-native execution, and tech-integrated business solutions.
With 30 years of experience in technological transformation, we accelerate innovation with expertise in Agentic SDLC, Application modernization, Data & AI, Martech and Business strategy.
We are 8,000 CI&Ters across more than 25 countries, collaborating to build solutions with real impact. AI is already part of how we work, evolve, and innovate every day.
You will co-own a multi-account AWS network foundation: hub and spoke on Transit Gateway, centralised inspection, controlled egress, hybrid connectivity into a client's SD-WAN estate through a third-party vendor. You will be in the room when the client's cloud architect asks why a subnet is a /25 and not a /24 — and the answer has to be yours.
The work is unglamorous in the way that matters. Most of what goes wrong in a landing zone does not go wrong in a module — it goes wrong at the seams. We want someone who has been burned by those and now checks for them by reflex.
Responsabilidades:
- Own the network foundation end to end: Transit Gateway with separated inspected and uninspected route tables, VPC design across inspection, egress, ingress, shared services, and workload tiers
- Define and enforce the routing posture that makes traffic pass a firewall rather than merely sit near one
- Verify that posture by test, not by reading your own plan
- Design and implement Transit Gateway Connect over GRE with BGP, two peers for availability, ASNs agreed in advance
- Extract precise inputs from third-party SD-WAN vendors who are not on your team and do not share your deadline
- Manage AWS IPAM with a delegated organisation administrator, pool hierarchy mapped to accounts, RAM shares to spoke accounts
- Justify every prefix — "it looked tidy" is not an answer
- Implement AWS Network Firewall with stateful rule groups, default drop posture, domain allowlisting, and managed threat signatures
- Be the person who knows whether an application failing to reach the internet is the firewall working correctly
- Write and maintain Terraform across multiple accounts with per-phase state separation, deployed through GitHub OIDC
- Implement drift detection, static validation, and a pipeline that a client can inherit
- Manage log delivery into governance accounts, resource policies, KMS key policies, and service-linked roles
- Understand that these accept broken configurations silently — and prove delivery by watching a log arrive
- Write down why: why a prefix is what it is, why an option was rejected, what a deviation is
- Prevent the next engineer from reversing a deliberate choice because nobody recorded the reasoning
- Write down why: why a prefix is what it is, why an option was rejected, what a deviation is
- Prevent the next engineer from reversing a deliberate choice because nobody recorded the reasoning
- Transit Gateway: association vs. propagation (no hedging), appliance mode, and why it exists
- VPC design: Network Firewall, NAT and egress control, PrivateLink, Route 53 Resolver
- Hands-on with hub and spoke and centralised inspection — built it, broke it, and fixed it (non-negotiable)
- Ability to describe a routing asymmetry you diagnosed or a firewall you had to prove was in the path
- Organizations, Control Tower, OUs, SCPs, delegated administrators, RAM
- Experience inheriting a landing zone someone else deployed
- Module design, state layout across accounts and phases
- Read a plan and know before applying whether you are renaming or destroying a resource
- Site-to-site VPN or Direct Connect, GRE, BGP peering, route advertisement, ASN allocation
- Default to checking the environment rather than trusting a report — including your own
- Every serious problem was found by someone querying the account instead of reading a summary
- Clear, precise, unhedged prose — a delivery skill, not a nice-to-have
- Inglês Avançado/Fluente é obrigatório
- AWS Advanced Networking Specialty certification — or the equivalent scar tissue
- Experience with SD-WAN platforms on AWS (Cisco, Fortinet, Palo Alto) and Transit Gateway Connect
- Exposure to manufacturing or industrial environments
- Familiarity with AWS Account Factory for Terraform (AFT)
- Working fluency in both Portuguese and English — client conversations in English; team works in Portuguese
#LI-AM2