At Moorepay, we are building a new AI-first HR and payroll platform on AWS from the ground up, and we're looking for a Platform Engineer to join our newly formed Cloud Engineering team. Working with our Lead Cloud Engineer, you'll help build and run the AWS foundation the whole platform sits on, and make it easy for our engineering squads to deploy and run their services safely. It's a broad, hands-on role covering infrastructure as code, golden path deployment templates, pipelines, developer tooling, observability, security and audit, so it suits someone who likes variety and wants real ownership early. Development experience matters here: part of the role is taking on and extending deployment tools our engineers have built in TypeScript.
Moorepay is an established business, but this team works like a startup. We move at pace, we don't let perfect get in the way of good, and we'd rather ship something that works and improve it than spend weeks deliberating. We need someone who can hit the ground running, take action and keep things moving, while still respecting the security and compliance standards a payroll business depends on.
We're AI-first in how we build. Writing things down clearly (standards, patterns, runbooks and context) so that both people and AI tools can work from them is a big part of how we go fast, and it's a big part of this role.
Key Responsibilities:
AWS Platform & Governance
- Build and maintain our AWS accounts, networking and shared services under AWS Control Tower and AWS Organizations.
- Help govern Control Tower guardrails, account provisioning and access through IAM Identity Center.
- Support every area of AWS the squads use, from Lambda, Fargate and API Gateway to DynamoDB, S3 and CloudFront.
Infrastructure as Code
- Write and maintain infrastructure as code using AWS CDK (TypeScript and Python) and CloudFormation.
- Build and maintain our golden paths: reusable CDK constructs and deployment templates that give squads a paved, secure route from new service to production.
- Work with Terraform where it's used.
CI/CD & Developer Tooling
- Build and support deployment pipelines (for example GitHub Actions), with security checks built in.
- Take on, maintain and extend the internal deployment tooling our engineers have built, which is written in TypeScript with some React.
- Make it easy for developers to deploy through the golden path, and help them resolve issues with their pipelines and environments.
- Write and maintain clear context for AI tools and people alike: platform standards, patterns, runbooks and prompts that let squads and AI agents build and deploy correctly first time.
Reliability & Observability
- Set up and maintain monitoring, logging, tracing, dashboards and alerting.
- Help define and track reliability measures for critical services with the squads.
- Take part in incident response and on-call once we're in production, and follow through on post-incident actions.
Security, Identity & Audit
- Help deploy and run the infrastructure behind our shared identity service (IDS).
- Make sure audit logging is in place and working across the estate (CloudTrail, AWS Config and central log storage), so we can evidence it for SOC2, PCI-DSS and GDPR.
- Apply secure-by-design practices: least-privilege access, encryption and security tooling such as GuardDuty and Security Hub.
Cost Management
- Apply our tagging standard, and help with cost reporting and budget alerts.
- Automate scheduling of non-production environments so they switch off out of hours.