
Sr. Backend Cloud Engineer - Golang + AWS
ValueBase Consulting
Job description
** We need Visa Independent Candidates | Locals to CA **
Role: Sr. Backend Cloud Engineer – Golang + AWS
Location: Brea, CA - Hybrid
Duration: 12+ Months Contract
About the Role
We're looking for a Cloud Backend Engineer to design, build, and operate the backend services behind a multi-tenant, event-driven cloud platform. You'll work across cloud services and device/edge connectivity, building reliable, scalable systems and owning them end-to-end — from architecture and infrastructure-as-code through to production operations.
This is a hands-on, high-ownership role on a small, senior team. You'll write Go services, define your own AWS infrastructure in CDK, secure the API edge, and reason about the boundary between the device edge and the cloud.
Required:
Strong professional experience building backend services in Go and Node/Typescript (services, middleware, concurrency, testing).
Hands-on experience with AWS — Lambda, API Gateway, SQS, DynamoDB, S3, IAM, Cognit
What You'll Do
Design, build, and maintain backend services and APIs in Go, with supporting code and infrastructure in TypeScript.
Define and operate cloud infrastructure on AWS using CDK — API Gateway, Lambda, SQS (including dead-letter/redrive queues), DynamoDB, S3, RDS/Aurora PostgreSQL, Cognito, CloudFront, and WAF.
Build and scale event-driven and device-to-cloud pipelines — telemetry and data ingestion, content/command delivery, retries, and offload/consolidation processing.
Work across the cloud/edge boundary — services and agents running on edge/embedded Linux, using AWS IoT Greengrass and MQTT messaging.
Strengthen multi-tenant isolation, identity, and security — PostgreSQL Row-Level Security, OAuth2/JWT, API gateway authorizers and middleware, edge protection (CloudFront/WAF/Lambda@Edge), and encryption in transit and at rest (KMS/Secrets Manager).
Own reliability and observability — structured logging with secret redaction, retry/back-off and idempotency, latency tracing, and diagnosing concurrency and load problems in ingestion and delivery paths.
Write and maintain CI/CD and security scanning — Jenkins pipelines, Docker, and remediation of dependency/container findings (e.g., BlackDuck, Sysdig) across multiple environments.