Datavant is the data collaboration platform trusted for healthcare. We are seeking a Staff Cloud Infrastructure Engineer to design, optimize, and secure the cloud infrastructure that powers our organization’s cloud environments.
Responsibilities:
- Design, implement, and optimize cloud-native infrastructure using best practices for security, scalability, and high availability
- Integrate newly acquired cloud environments into the organization’s cloud footprint, ensuring security and consistency
- Develop and implement hybrid-cloud and cross-cloud connectivity strategies to ensure interoperability
- Architect, optimize, and maintain secure network infrastructure in Azure, AWS, & GCP – including DNS, routing, and low-latency cross-cloud communication
- Collaborate with security teams to enforce Zero Trust networking, IAM, and data encryption standards, as well as general security framework adherence
- Maintain and expand a modular network security edge that provides for integration testing among development teams while remaining flexible enough to unify additional environments as M&A requires
- Automate cloud infrastructure provisioning using Terraform and Ansible, writing IaC that supports Simple, Secure, and Scalable deployments
- Implement policy-based automation (AWS SCPs, Azure Policy) to maintain governance across cloud environments
- Support observability teams with infrastructure monitoring and alerting using CloudWatch, Datadog, and Log Analytics
- Drive transformation and standardization of our foundational infrastructure services as the environment evolves and the business grows, including optimizing processes, developing policies, and enabling secure, self-service infrastructure for our engineering partners
Requirements:
- 10+ years of experience in cloud infrastructure engineering, platform engineering, or infrastructure architecture
- Strong expertise in cloud infrastructure, including networking, security, compute, storage, and IAM
- Experience migrating workloads from on-prem to cloud and integrating new cloud environments into existing architectures
- Deep understanding of multi-cloud networking (AWS VPCs, Azure VNets, Transit Gateway, ExpressRoute, PrivateLink, DNS, hybrid connectivity)
- Hands-on experience with Infrastructure as Code and automation cloud infrastructure (Terraform and Ansible)
- Strong security knowledge, including IAM, encryption, network security, PKI, certificate management, and compliance frameworks (SOC2, HITRUST, NIST, FedRAMP)
- Experience managing multi-account cloud governance and security policies (AWS Organizations, Azure Policy, SCPs)
- Excellent problem-solving skills, with the drive to bring clarity to vague situations and a desire to constantly expand your skills
- Strong communication skills, including the ability to describe complex problems to non-technical staff, paired with the curiosity, adaptability, and flexibility needed to navigate a growing enterprise
- Experience leveraging AI agents to accelerate daily workload
- Competency with the following technologies: Compute: Azure VMs, EC2, VMware vSphere; Network security: Azure (VNets, NSG, AGW); AWS (VPC, TGW, Peering, SG, ALB, NLB); NextGen FW, VPN; Storage: Azure Files & Blob, Amazon S3, AWS FSxN; Automation: Ansible Automation Platform, Terraform, GitHub; Core: Windows & Linux, DNS / IPAM, Active Directory; Observability: Datadog, CloudWatch, Azure Log Analytics, Aria; IAM: Azure Roles, AWS IAM
- Group Policy, PowerShell, CIFS & NFS storage protocol, Palo Alto, F5
- Deep knowledge of cloud services, containerization, and/or Kubernetes
- Experience driving environment consolidation and integration, bringing order to disparate hybrid and multi-cloud architectures as the business grows
- Experience driving technical initiatives end-to-end
- Knowledge of multi-region architecture and disaster recovery strategies
- Background in cloud cost optimization and FinOps methodologies
- Experience with cloud-native identity management (AWS IAM Identity Center, Entra ID, RBAC)