---
title: "[Job- 31345]Senior DevOps Engineer (Cloud Network Foundation), Brazil"
company: "CI&T"
company_url: "https://www.remjobs.works/companies/ci-t"
url: "https://www.remjobs.works/job/ci-t-job-31345-senior-devops-engineer-cloud-network-foundation-e36a8d76-2472-4d52-a17d-e2374aa76431"
apply_url: "https://jobs.lever.co/ciandt/8afc856c-736e-49bd-bb65-6424faba8992"
workplace: remote
location: "Brazil"
remote_scope: "Brazil"
employment_type: other
seniority: senior
role: devops-infrastructure
region: latin-america
skills: ["aws", "terraform"]
date_posted: 2026-08-28T12:27:50.911Z
first_seen_by_remjobs: 2026-09-15T15:52:37.851Z
---

# [Job- 31345]Senior DevOps Engineer (Cloud Network Foundation), Brazil

**CI&T** · Brazil

Apply: https://jobs.lever.co/ciandt/8afc856c-736e-49bd-bb65-6424faba8992

## About the role

At CI&T, we help large enterprises transform the potential of AI into real business impact with AI Deployment, AI-native execution, and tech-integrated business solutions.

With 30 years of experience in technological transformation, we accelerate innovation with expertise in Agentic SDLC, Application modernization, Data & AI, Martech and Business strategy.

We are 8,000 CI&Ters across more than 25 countries, collaborating to build solutions with real impact. AI is already part of how we work, evolve, and innovate every day.

You will **co-own a multi-account AWS network foundation**: hub and spoke on Transit Gateway, centralised inspection, controlled egress, hybrid connectivity into a client's SD-WAN estate through a third-party vendor. You will be in the room when the client's cloud architect asks why a subnet is a /25 and not a /24 — **and the answer has to be yours.**

The work is unglamorous in the way that matters. Most of what goes wrong in a landing zone does not go wrong in a module — it goes wrong at the seams. **We want someone who has been burned by those and now checks for them by reflex.**

**Responsabilidades:**

- Own the network foundation end to end: Transit Gateway with separated inspected and uninspected route tables, VPC design across inspection, egress, ingress, shared services, and workload tiers

- Define and enforce the routing posture that makes traffic pass a firewall rather than merely sit near one

- Verify that posture by test, not by reading your own plan

- Design and implement Transit Gateway Connect over GRE with BGP, two peers for availability, ASNs agreed in advance

- Extract precise inputs from third-party SD-WAN vendors who are not on your team and do not share your deadline

- Manage AWS IPAM with a delegated organisation administrator, pool hierarchy mapped to accounts, RAM shares to spoke accounts

- Justify every prefix — "it looked tidy" is not an answer

- Implement AWS Network Firewall with stateful rule groups, default drop posture, domain allowlisting, and managed threat signatures

- Be the person who knows whether an application failing to reach the internet is the firewall working correctly

- Write and maintain Terraform across multiple accounts with per-phase state separation, deployed through GitHub OIDC

- Implement drift detection, static validation, and a pipeline that a client can inherit

- Manage log delivery into governance accounts, resource policies, KMS key policies, and service-linked roles

- Understand that these accept broken configurations silently — and prove delivery by watching a log arrive

- Write down why: why a prefix is what it is, why an option was rejected, what a deviation is

- Prevent the next engineer from reversing a deliberate choice because nobody recorded the reasoning

- Write down why: why a prefix is what it is, why an option was rejected, what a deviation is

- Prevent the next engineer from reversing a deliberate choice because nobody recorded the reasoning

**Requisitos:**

- Transit Gateway: association vs. propagation (no hedging), appliance mode, and why it exists

- VPC design: Network Firewall, NAT and egress control, PrivateLink, Route 53 Resolver

- Hands-on with hub and spoke and centralised inspection — built it, broke it, and fixed it (non-negotiable)

- Ability to describe a routing asymmetry you diagnosed or a firewall you had to prove was in the path

- Organizations, Control Tower, OUs, SCPs, delegated administrators, RAM

- Experience inheriting a landing zone someone else deployed

- Module design, state layout across accounts and phases

- Read a plan and know before applying whether you are renaming or destroying a resource

- Site-to-site VPN or Direct Connect, GRE, BGP peering, route advertisement, ASN allocation

- Default to checking the environment rather than trusting a report — including your own

- Every serious problem was found by someone querying the account instead of reading a summary

- Clear, precise, unhedged prose — a delivery skill, not a nice-to-have

- Inglês Avançado/Fluente é obrigatório

**Diferencial:**

- AWS Advanced Networking Specialty certification — or the equivalent scar tissue

- Experience with SD-WAN platforms on AWS (Cisco, Fortinet, Palo Alto) and Transit Gateway Connect

- Exposure to manufacturing or industrial environments

- Familiarity with AWS Account Factory for Terraform (AFT)

- Working fluency in both Portuguese and English — client conversations in English; team works in Portuguese

#LI-AM2

**Our benefits:**
 
-Health and dental insurance
-Meal and food allowance
-Childcare assistance
-Extended paternity leave
-Partnership with gyms and health and wellness professionals via Wellhub (Gympass) TotalPass;
-Profit Sharing and Results Participation (PLR);
-Life insurance
-Continuous learning platform (CI&T University);
-Discount club
-Free online platform dedicated to physical, mental, and overall well-being
-Pregnancy and responsible parenting course
-Partnerships with online learning platforms
-Language learning platform
And many more!
 
More details about our benefits here: [https://ciandt.com/br/pt-br/carreiras](https://ciandt.com/br/pt-br/carreiras)
 
At CI&T, inclusion starts at the first contact. If you are a person with a disability, it is important** to present your assessment during the selection process. ***See which data needs to be included in the report by [clicking here](https://docs.google.com/presentation/d/12BqYLIGeEyp9t0ZdF2b4bvnjFLza4E8fmbcowWeBlfk/edit?slide=id.g3a9cf52bf2b_0_0#slide=id.g3a9cf52bf2b_0_0)*[.](https://docs.google.com/presentation/d/12BqYLIGeEyp9t0ZdF2b4bvnjFLza4E8fmbcowWeBlfk/edit?slide=id.g3a9cf52bf2b_0_0#slide=id.g3a9cf52bf2b_0_0)This way, we can ensure the support and accommodations that you deserve. **If you do not yet have the assessment, don't worry: we can support you in obtaining it.**
 
We have a dedicated Health and Well-being team, inclusion specialists, and affinity groups who will be with you at every stage. Count on us to make this journey side by side.

---

Source: CI&T's own career page, read by RemJobs. Canonical HTML version: https://www.remjobs.works/job/ci-t-job-31345-senior-devops-engineer-cloud-network-foundation-e36a8d76-2472-4d52-a17d-e2374aa76431
