Modoante
DenmarkFull TimeSoftware Developers

Senior Cloud Platform Engineer (AWS)

Anthill | Copenhagen, Denmark | Salary not specified

Source: JobsPipe

Required Skills

awscommunicationterraformdockerkubernetesnode.jsjenkins
View company

Role snapshot

Work model
Remote
Language
Not specified
Experience
Not specified
Posted
Posted 1 day ago
Application deadline
2026-10-19

What you'll do

Copenhagen, on site. Permanent, full time. Senior. Reporting to the CTPO. Start no later than 1 December 2026. Pharma communication is slow for a good reason. Every claim needs a reference, every asset needs approval, and every market has its own rules. We think the software that wins in this industry treats those rules as part of the product rather than something to work around, and that is what we build. Anthill builds the software pharmaceutical companies use to create, approve and run their digital communication. At some of the world's largest pharma companies, commercial and medical teams rely on our products to produce and distribute regulated content. We're around 70 people, headquartered in Copenhagen, with four products: Activator, Arcane, Amplify and Anthill Cloud. Our products are already delivering GenAI-powered capabilities to Enterprise customers around the world. We're growing fast, and it's a good time to join. In our Copenhagen office, engineers, designers, product people and strategists all sit in the same room. We're 15+ nationalities, so English is the official and everyday language in the office and in the codebase. Engineering runs on AWS with Terraform, Buildkite and a mono repo for our newest platform. THE ROLE Our product teams own their own infrastructure. They write their own Terraform, run their own pipelines and deploy themselves, and we intend to keep it that way. This role owns the platform layer they build on: the AWS account model, identity and access, secrets, agent infrastructure, guardrails, observability, reliability and cost across a multi-account AWS organisation serving regulated customers. It is a hands-on individual role. If the platform function grows, you are the natural person to lead it, but we are not hiring a manager and we would rather say so now. WHAT YOU OWN

  • The AWS account model: provisioning, service control policies, region policy, tagging and naming conventions across the organisation
  • Identity and access across the full lifecycle, creation, review and removal, through single sign-on
  • Secrets management: one place secrets live, with automated rotation for service credentials
  • Vulnerability management and hardening of the infrastructure itself: baselines, image and runtime currency, segregation and isolation, and the scanning and enforcement point for container and dependency findings
  • Agent infrastructure: secure, reliable infrastructure connecting AI agents to internal systems, balancing autonomy with control. You control who can invoke what and that it is logged, not what is asked
  • One observability standard across products for logging, alerting, monitoring and tracing, and an alerting model where cost, security and infrastructure alerts have a named owner and a defined action
  • Reliability and continuity: backup policy, scheduled restore testing, disaster recovery, infrastructure and container health monitoring, and the escalation path when something breaks
  • Cost: visibility per account and service, anomaly response, and the budgets and spending limits that prevent a surprise rather than report one
  • Cross-product services outside application code: CI, DNS, certificates and domains. The CI platform decision sits with this role. We run Buildkite today

WHAT GOOD LOOKS LIKE AT 90 DAYS The target design for our AWS organisation implemented: account structure, guardrails and identity in Terraform in our repositories, with our newest platform running under them. The migration of our accounts onto it under way and run by you. From there you own the organisation end to end. Alongside that, one observability standard live, and the access lifecycle automated to the point where offboarding is a single action. WHAT WE ARE LOOKING FOR Required:

  • Deep AWS rather than broad cloud, including Organizations and service control policies
  • Infrastructure as code in production, Terraform in particular
  • Real experience with identity and single sign-on

Useful, not required:

  • Landing zones on AWS, Control Tower and Account Factory for Terraform in particular
  • Containers in production, Docker and orchestration on AWS
  • Kubernetes
  • Auth0
  • Infrastructure hardening and vulnerability management as an operational discipline rather than a report you forward
  • Comfort in Node.js or Bash, because this role automates manual work away rather than absorbing it
  • Observability tooling such as CloudWatch, Better Stack or Datadog, with enough judgement to standardise on one and defend the choice
  • CI systems: Buildkite, GitHub Actions, GitLab CI, Jenkins or similar. We use Buildkite
  • Comfort defining standards that other teams build against

We also want someone who has thought seriously about agent infrastructure. We are connecting AI agents to internal systems, and the hard problems there are credential scoping, audit and blast radius rather than prompts. If you have opinions about what a non-human identity should and should not be allowed to hold, we want to hear them. Having supported a compliance or certification effort, ISO 27001 or similar, is a strong plus. So is being able to explain an infrastructure trade-off and what it costs to someone who does not work in infrastructure. Experience with regulated customers is useful but not required. We do not expect you to be fluent in everything on the useful list, and some of it will be learned on the job. If you meet the three requirements and have an instinct for where a boundary belongs, apply and we will talk about the rest. WHAT WE OFFER

  • A permanent Danish employment contract, pension and health insurance.
  • A salary set from our salary bands, the same way for everyone at the same level. Where you land in the range depends on your experience and skills, and on pay equity with colleagues at that level.
  • Five days a week in our Copenhagen office, with two work from home days a month as the default. We are on site because most of what engineers learn from each other happens in conversation at someone's desk.
  • Colleagues who have shipped software into pharma and know how demanding that audience is.
  • Clients whose problems are specific and constrained, which is more interesting than it sounds.
  • Occasional office dogs, who expect to be petted.

On the office: being in the room matters for this one in particular, because you are building the layer everyone else depends on and most of that work happens next to other engineers rather than in a ticket. APPLYING If you can recognise yourself in just some of these requirements or skills and simply want to learn the rest, we would love to receive your application. We offer an open environment with freedom under responsibility, where you have the opportunity to grow professionally. Apply through LinkedIn, or get in touch directly if you would rather have a conversation before a formal application. We read everything ourselves. Your CV does not need a photo, your age or anything else that is not about your work. If there is a repository, a component library, a design document or a postmortem that tells us more than a cover letter would, send that too. We review applications as they arrive. Where the role has a closing date, it is stated at the top of the ad. Otherwise the role stays open until we find the right person. We only work with recruitment and search firms under a written agreement, and we do not pay fees for candidates we did not ask for. Please do not send CVs to the hiring manager.

Work resources

Helpful work resources for this job

Sign in to read

Application checklist

Review your application before submitting

A quick checklist to help candidates submit a clearer, more complete application.

Read resource