Sobre esta vaga de AWS Cloud Infrastructure Engineer - WSTE na Valsoft Corporation
Aspire Software is looking for a AWS Cloud Infrastructure Engineer to join our team in Lebanon.
Here is a little window into our company: Aspire Software operates and manages wholly owned software companies, providing mission-critical solutions across multiple verticals. By implementing industry best practices, Aspire delivers a time sensitive integration process, and the operation of a decentralized model has allowed it to become a hub for creating rapid growth by reinvesting in its portfolio.
About the Role:
We're hiring a Cloud Infrastructure Engineer to join our Professional Services team and take real ownership of the AWS environment that runs WeSuite and our hosted customer environments.
This is an AWS-first role — our entire platform runs on AWS, and you'll be working in it every day.
This is a hands-on engineering role, not a ticket queue. You'll work directly with the Head of Professional Services on a live roadmap: migrating workloads off our legacy AWS account, driving down run-rate cost, hardening our security posture, modernizing our deployment pipelines, and standing up infrastructure for new products. The work is mostly internal-facing — supporting employees and the customers whose environments we host — but you'll also work directly with customers during new deployments, on networking and connectivity questions, and occasionally alongside our sales team when a prospect is evaluating a move onto our hosted platform.
If you like owning problems end to end, writing the automation that keeps them from recurring, and documenting it so the next person doesn't have to rediscover it; this role will suit you.
What You'll Work On
These are real projects on our current roadmap:
- Legacy account migration. Move remaining workloads off our legacy AWS account into our
- Landing Zone Accelerator environment — Elastic Beanstalk environments, EC2 instances, associated networking and Elastic IP strategy.
- Cost optimization. Continue an active effort to reduce our AWS run rate: right-sizing, storage tiering, reserved capacity strategy, decommissioning idle resources, and keeping anomaly detection and budget alerting in front of the people who need to see it.
- Security and compliance. Work through Security Hub findings across our production accounts, tune GuardDuty and Inspector, tighten IAM Identity Center permission sets, and support our ongoing SOC 2 program.
- Deployment automation. Improve and extend our release pipelines, including database refresh automation against RDS SQL Server and configuration-encryption tooling for IIS-hosted sites.
- You'll also make active revisions to our CloudFormation templates, so newly provisioned resources come up consistently and with less manual work each time.
- Customer environments. Provision and troubleshoot hosted customer infrastructure — SQL Server and RDS, IIS sites, SSL/TLS certificates, VPC and Transit Gateway routing, Route 53 private hosted zones.
- New product infrastructure. Support the platform behind our AI product line, including Elastic Beanstalk environments, logging and observability, and infrastructure cost modeling for new services.
Responsibilities
- Administer and improve AWS infrastructure across multiple accounts: EC2, RDS, S3, VPC/Transit
- Gateway, Route 53, Elastic Beanstalk, IAM/IAM Identity Center, CloudFormation, Systems Manager, CloudWatch, and CloudTrail.
- Plan and execute migrations between accounts, regions, and platforms with minimal customer disruption.
- Administer SQL Server on both RDS and EC2: backup/restore, upgrades, permissions, performance troubleshooting, and migration work.
- Manage Windows Server and IIS hosting, including SSL/TLS certificate lifecycle, bindings, and renewals.
- Write and maintain PowerShell and AWS CLI automation for recurring operational work.
- Build and maintain automated deployment processes for internal and customer-facing releases.
- Maintain and extend CloudFormation templates for repeatable, consistent resource provisioning.
- Investigate and resolve infrastructure incidents end to end and produce clear internal documentation and runbooks afterward.
- Monitor and report on cloud spend; identify and implement savings opportunities.
- Support security findings for remediation, access reviews, and evidence gathering for SOC 2.
- Interface directly with hosted customers during project deployments, networking and
- connectivity questions, and pre-sales technical discussions about our hosted platform.
- Provide escalation support to internal teams for infrastructure-related issues.
Requirements
- 2–3+ years of hands-on, direct AWS experience in a production environment — day-to-day console and CLI work, not adjacent exposure through a managed provider.
- Working knowledge across core AWS services: EC2, VPC and networking, RDS, S3, IAM,
- CloudWatch, and at least one infrastructure-as-code or deployment tool.
- Solid Windows Server administration experience, including IIS.
- SQL Server administration experience: backups, restores, logins and permissions, and basic performance troubleshooting.
- Practical PowerShell scripting ability — you can automate a repetitive task without turning it into a framework.
- Comfort with certificate management, DNS, and general network troubleshooting.
- Clear written communication. You'll document what you build and explain it to both engineers and non-technical stakeholders.
- Ability to work directly with customers professionally and calmly, including during incidents.
Nice to Have
- Experience with AWS Control Tower, Landing Zone Accelerator, or multi-account organizational structures.
- Security Hub, GuardDuty, Inspector, or similar security tooling experience.
- Octopus Deploy, or comparable release automation (Azure DevOps, TeamCity, Jenkins).
- AWS cost management experience (Cost Explorer, budgets, Savings Plans/RIs).
- Exposure to SOC 2 or similar compliance programs.
- AWS certification (Solutions Architect Associate, SysOps Administrator, or equivalent).
- SaaS or MSP background where infrastructure directly serves external customers.
What Success Looks Like
First 90 days: You're comfortable navigating our AWS accounts and customer environments; you've taken ownership of a defined slice of the migration or cost-optimization roadmap, and you're handling routine infrastructure requests independently.
First year: You own a meaningful portion of our cloud operations, you've led at least one significant migration or platform improvement project start to finish, and internal teams come to you directly rather than through escalation.