24 Sep
|
Caracal Technologies
|
Vancouver
24 Sep
Caracal Technologies
Vancouver
Cloud/System Administrator
VenTek — Vancouver, BC (Onsite) — Full-Time
About VenTek
VenTek is growing fast, and our AWS infrastructure needs to grow up with us. We're investing in a modern, well-governed cloud foundation that gives our engineering teams real autonomy to ship — while keeping production safe, secure, and cost-effective. This is a newly created role and a rare chance to build a cloud platform the right way from the ground up, rather than inheriting someone else's mess.
About the Role
We're looking for an System/Cloud (AWS) Administrator to own our AWS environment end to end and to assure company compliance with PCI-DSS: account structure, security guardrails, identity and access, networking, and cost. You'll be responsible for how our AWS Organization is set up — and the person who makes it possible for development teams to deploy, configure, and monitor their own applications without waiting on you for every change.
This is a hands-on, high-trust role. You'll design the guardrails, not just enforce them, and you'll be the final word on account structure and security — while acting as an enabler for the organization.
What You'll Do
- Own AWS Organizations: account structure, organizational units, and provisioning new accounts as products and environments grow
- Design and maintain Service Control Policies (SCPs) and other guardrails (AWS Config, Security Hub) that keep every account secure by default
- Operate a multi-account “landing zone” using AWS Control Tower or Landing Zone Accelerator on AWS
- Own AWS IAM Identity Center: permission sets, group assignments, and single sign-on for every account
- Define scoped, least-privilege access for engineering teams — full deploy/configure/monitor control in their own environments,
without standing access to production
- Own core security services: CloudTrail, GuardDuty, Security Hub, and centralized log archiving
- Own shared networking foundations (VPCs, Transit Gateway, DNS) and the shared CI/CD account that pipelines use to deploy into workload accounts
- Own consolidated billing, budgets, cost allocation, and cost anomaly detection across the AWS environment
- Maintain clear documentation and runbooks so guardrails and access decisions are transparent, not tribal knowledge
- Provision resources that allow for onboarding of new customers
- Assist in troubleshooting application issues in support of engineering and customer service.
- Management of on-premise resources in Vancouver office.
- Assisting in daily, weekly, monthly, quarterly, and semi-annual tasks related to the on-going PCI-DSS compliance program. Tasks include monitoring, scanning, logging, and reporting to PCI-DSS program manager.
What We're Looking For
- 3+ years of hands-on AWS administration experience, including experience with AWS Organizations or a multi-account environment
- Working knowledge of Service Control Policies and either AWS Control Tower or Landing Zone Accelerator on AWS
- Experience with AWS IAM Identity Center (or AWS SSO) and permission-set-based access models
- Proficiency with an Infrastructure-as-Code tool (Terraform, CloudFormation, or CDK)
and command-line/API automation
- Familiarity with CI/CD pipelines and cross-account deployment patterns
- Solid understanding of core AWS networking (VPCs, routing, DNS) and security services (GuardDuty, Security Hub, Config, CloudTrail)
- Comfortable owning a control-plane function solo — confident saying no to scope creep into IAM, networking, or account settings, while staying genuinely helpful to engineering teams
- Strong written communication — you'll document guardrails and decisions clearly for both engineers and leadership
- Experience with management and maintenance of office network environment
- Familiarity with Microsoft Windows server and Linux Ubuntu environments
Nice to Have
- AWS certification: SysOps Administrator – Associate, Solutions Architect – Associate/Professional, or Security – Specialty
- Experience migrating or consolidating separate AWS accounts into a single Organization
- Experience standing up a landing zone from scratch at a small or mid-size company
- Scripting ability (Python, Bash, or PowerShell)
- FinOps or cloud cost-optimization experience
- Experience with PCI-DSS and/or other security standards such as SOC II
Compensation & Benefits
- Salary: $130,000–$150,000 per year, based on experience and qualifications
This position is for in-office work (not hybrid work). We will only be reviewing local candidates as relocation assistance is not available.
Please only apply if you meet all of the mandatory qualifications and abilities.
Please forward a cover letter and resume.
Pay: $130,000.00-$150,000.00 per year
Benefits
- Extended health care
- Paid time off
Work Location: In person
📌 Cloud/System Administrator (Vancouver)
🏢 Caracal Technologies
📍 Vancouver