云工程师 AWS(CDK / 无服务器)(102-09SENG-01)
Cloud Engineer AWS ( CDK / Serverless) ( 102-09SENG-01 )
这个职位需要在生产环境中修改一个实时的无服务器网关——不中断服务,不改变行为——为下游由 Terraform 管理的构建留下一个干净的交接点。这是一次对有活跃外部消费者的生产基础设施进行的谨慎操作,而不是从零开始的开发。
范围包括现代化由四个堆栈、六个 Lambda 函数、一个 WAF 网站 ACL、一个 mTLS 自定义域名/信任库和一个 REST API 组成的 CDK 基地,在整合过程中保留资源身份,并协调两次顺序部署并测试回滚路径。
你将负责
- 清点 CDK 基地并制定现代化计划:升级 CDK 库/CLI,替换已弃用的结构,将硬编码的上下文移至按环境配置。
- 将重复的堆栈整合为共享结构,同时不丢失资源身份——在整合前后映射逻辑 ID,选择保留方法,并在接触生产环境前确认没有内容被替换。
- 作为两个独立、有序的部署运行库升级和堆栈重构,先在开发和测试环境中测试回滚路径。
- 将所有六个 Lambda 函数从 Node 18 迁移到 Node 24,关闭一个开放的 PII 日志问题,并对每个函数进行回归测试。
- 在两次部署后重新验证安全边界——WAF、mTLS 域名和信任库、X-Ray 跟踪、上游超时时间——与客户 POS 团队合作,覆盖所有六个外部调用者。
- 为开发/测试/生产环境构建部署流水线,包含 OIDC 联邦、审批门禁和 ServiceNow 变更步骤。添加 CDK 断言测试、漂移检测和 API 访问日志保留。
- 通过参数存储发布 SQS 队列 ARN 和 KMS 密钥 ARN,并授予下游由 Terraform 管理的系统发送权限——这是该团队构建的关键依赖项。
- 与客户的内部标准对齐命名、标签和文档,并清晰地记录你的身份保留决策,以便下一位工程师能够理解。
要求
- 5 年以上 AWS 经验,其中 3 年以上从事基础设施即代码相关工作。
- 具备实际的 AWS CDK 使用经验,使用 TypeScript —— 构造树、逻辑 ID 衍生,以及构造路径变化时发生的情况。
- 具有真实的 CloudFormation 资源身份经验:堆栈重构、逻辑 ID 覆盖、cdk diff 与已部署状态对比、漂移检测。
- 熟悉 Terraform —— 能够在 CDK/Terraform 边界上自如操作。
- 熟练掌握 AWS 无服务器后端
查看英文原文
This role modifies a live serverless gateway in production — no downtime, no change in behaviour — leaving a clean handoff point for a downstream build managed in Terraform. This is careful surgery on production infrastructure with active external consumers, not a greenfield build.
The scope includes modernizing a CDK estate made up of four stacks, six Lambda functions, a WAF web ACL, an mTLS custom domain/truststore, and a REST API — preserving resource identity during consolidation and coordinating two sequenced deployments with a tested rollback path.
What you will do
- Inventory the CDK estate and build a modernization plan: upgrade the CDK library/CLI, replace deprecated constructs, move hardcoded context into per-environment config.
- Consolidate duplicated stacks into shared constructs without losing resource identity — map logical IDs before and after, pick a preservation method, and confirm nothing gets replaced before touching production.
- Run the library upgrade and the stack refactor as two separate, ordered deployments, with a rollback path tested in dev and test first.
- Migrate all six Lambda functions from Node 18 to Node 24, close an open PII logging finding, and regression-test each one.
- Re-verify the security perimeter after both deployments — WAF, the mTLS domain and truststore, X-Ray tracing, upstream timeouts — working directly with the customer's POS team across all six external callers.
- Build deployment pipelines for dev/test/prod with OIDC federation, approval gates, and a ServiceNow change step. Add CDK assertion tests, drift detection, and API access log retention.
- Publish the SQS queue ARN and KMS key ARN via Parameter Store, and grant send permission to the downstream Terraform-managed system — this is the key ordering dependency for that team's build.
- Align naming, tagging, and documentation with the customer's internal standards, and document your identity-preservation decisions clearly enough for the next engineer to follow.
Requirements
- 5+ years with AWS, including 3+ years working in infrastructure-as-code.
- Hands-on AWS CDK experience in TypeScript — construct trees, logical ID derivation, and what happens when a construct path changes.
- Real experience with CloudFormation resource identity: stack refactoring, logical ID overrides, cdk diff against deployed state, drift detection.
- Working Terraform knowledge — comfortable operating across the CDK/Terraform boundary.
- Solid AWS serverless background: Lambda, API Gateway (REST), SQS and DLQs, Parameter Store, KMS, Secrets Manager.
- Experience with AWS edge and security services — WAF web ACLs, mutual-TLS custom domains and truststores, cross-account/cross-boundary IAM.
- Practical experience migrating Nodejs runtimes (e.g. Node 18 → 24), including dependency and deprecation handling.
- CI/CD pipeline experience with OIDC federation and approval gates (GitHub Actions or equivalent).
- Working knowledge of observability tools — X-Ray, CloudWatch metrics and alarms, log retention.
- Comfortable communicating clearly with non-engineers, and working well when parts of the scope are still being figured out.
- Fluent English (C1 level) for daily communication with the client.
Engagement details
- Hourly contractor
- 100% remote
- Estimated duration: 6–8 weeks
- Time zone: EST or MST
Highlights
AWS CDK , CloudFormation, Terraform, AWS Serverless (Lambda, API Gateway REST, SQS/DLQ, Parameter Store, KMS, Secrets Manager), AWS Edge & Security (WAF, mTLS, cross-account IAM), Node.js, CI/CD
Originally posted on Himalayas