Platform Engineer
Indexed description
Position: PLATFORM ENGINEER - SENIOR
Reports to: Head of Platform Engineering Department
Effective Date: 01/08/2026
Approved by: CEO
Position Purpose
We are seeking a Senior Platform Engineer to lead technical execution across cloud transformation engagements in Asia-Pacific. In this role, you will design and own enterprise-grade platform architectures, drive DevSecOps practices, and mentor junior engineers - operating as an architect-operator who owns outcomes across multi-account AWS environments, production Kubernetes clusters, and service mesh deployments. You will also contribute to client-facing consulting: leading workshops, producing architectural decision records, and supporting pre-sales.
Responsibilities
1. Platform Architecture & Engineering
– Design and implement cloud-based platform solutions tailored to banking industry requirements.
– Design and own multi-account AWS architectures - Landing Zone, Control Tower, Service Control Policies, account vending.
– Architect and operate production EKS clusters - autoscaling, node pools, managed add-ons, upgrade strategies.
– Design and implement Service Mesh (Istio) - traffic management, mTLS, observability, multi-cluster federation.
– Lead Hybrid Cloud integration designs (AWS + Azure).
– Drive FinOps practices - cost visibility, chargeback models, right-sizing.
– Architect disaster recovery and high-availability strategies for banking-grade SLAs.
2. DevSecOps & Automation
– Build and maintain enterprise CI/CD platforms - GitOps with ArgoCD, GitHub Actions, GitLab CI, pipeline-as-code, self-hosted runners. Implement IaC and config management at enterprise scale including Terraform module design, remote state management, drift detection, environment consistency, automated provisioning.
– Implement Policy-as-Code (OPA/Kyverno) and automated compliance gates.
– Operationalize DevSecOps pipelines - SAST (SonarQube), SCA (Dependabot/Trivy), DAST, container image scanning (Trivy/Qualys).
– Manage secrets at scale - HashiCorp Vault, AWS Secrets Manager, Kubernetes integration, External Secrets.
3. Observability & Reliability
– Architect full-stack observability - Datadog, Grafana LGTM (Loki, Mimir, Tempo).
– Define SLIs/SLOs and drive SRE practices across client teams.
– Own incident response runbooks, war room facilitation, and post-mortem culture.
4. Client Delivery & Consulting
– Lead technical workshops, architecture reviews, and design sessions with client stakeholders.
– Produce ADRs, solution design documents, and client-facing runbooks.
– Translate business requirements into platform architectures with clear trade-off documentation.
– Mentor Junior and Mid-level engineers on engagements.
– Support pre-sales - technical scoping, effort estimation, solution pitching
Requirements
1. Education
– Diploma or Bachelor's degree in Computer Science, Information Technology or a related field.
2. Experience
– Minimum of 4 years in platform engineering, DevOps, or cloud infrastructure.
– Deep AWS expertise - EKS, VPC, IAM, KMS, GuardDuty, SecurityHub, Config, Control Tower, Organizations.
– Production Kubernetes - cluster operations, RBAC, CNI, CSI, autoscaling.
– Ansible/Terraform - IaC authoring, state management, config management, CI/CD integration.
– Service mesh (Istio) - traffic policies, mTLS, observability.
– GitOps with ArgoCD, GitHub Actions, or GitLab CI - pipelines, app-of-apps, progressive delivery.
– Advanced Linux administration - performance tuning, security hardening, networking.
– Security-first mindset - IAM least privilege, image hardening, secrets management, network policies.
– AI-assisted development tools (e.g. Kiro, Claude, Codex) - daily use for coding, scripting, documentation.
– English: B2 or higher - client presentations and written deliverables.
3. Nice to Have
– Banking or financial services background - regulatory compliance, audit, change
management.
– AWS certifications - Solutions Architect Professional and/or Security Specialty.
– CKA or CKS certification.
– Datadog Certified Professional.
– NIST, CIS Benchmark, OWASP, PCI-DSS, or SOC2 compliance experience.
– Multi-cloud experience (Azure AKS, GKE).
– AI/ML & MLOps platform exposure - SageMaker, MLflow, Kubeflow, vector DBs,
LLM gateways, GPU compute on AWS.
Compensation & Benefits
Salary: Competitive and negotiable based on qualifications, experience, and overall fit.
– Participation in statutory social insurance, health insurance, and unemployment insurance in accordance with Vietnamese labor regulations.
– Performance-based bonuses, holiday bonuses, and other employee benefits in accordance with the Company's policies.
– Excellent opportunities for professional development and career advancement in a professional, transparent, and collaborative work environment
Cách thức ứng tuyển: Vui lòng gửi CV + Bằng cấp/ Chứng chỉ về địa chỉ email: [email protected]
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search