Live opening · Posted 9 days ago

Senior AWS Systems Administrator

MaxiCare · United States (Remote)
Linkedin No
You are 9 days behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 9 days ago
CompanyMaxiCare
LocationUnited States (Remote)
Work modeNo
SourceLinkedin
Listed9 days ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
119 min from Linkedin publishing this role to us finding it
11 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
68,095 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

About MaxiCare
MaxiCare is an AI native EMR platform built for operators of skilled nursing and assisted living facilities. The EMR that thinks. We are an early stage, fast moving company building product alongside our first cohort of facility partners. The team is small, and the work is real.
About the role
We are looking for a Senior AWS Systems Administrator who owns the AWS environment end to end. Production, development, staging, the organization root, the billing alarms, the network topology, the audit trails, the keys, the access controls. If it lives in AWS at MaxiCare, this seat is responsible for it being correctly configured, properly monitored, and ready for an auditor to walk through.
The platform runs on AWS and it handles PHI. That sentence carries the whole job. You configure the environments so PHI moves only where it should, encrypted at rest and in transit, audited at every hop, and tied to a real identity a HIPAA assessor can trace. You configure the networking so a facility partner can route on premises traffic into MaxiCare through a secure tunnel that holds up to scrutiny.
This seat also owns business continuity and workforce identity. Backups either ran clean or they did not. Every employee and contractor has exactly the access they should have, or they do not. You own those answers, every day.
You partner with the Lead Product Architect on infrastructure decisions and own the operational reality once they are made.
What you will own
• AWS accounts and organization. AWS Organizations, account structure, service control policies, the landing zone, and the separation between production, staging, and development.
• Networking and connectivity. The heart of the seat. VPC design, subnets, route tables, security groups, NACLs, and Transit Gateway topology. You build site to site VPN tunnels and Transit Gateway attachments that let facility and integration partners reach MaxiCare without exposing PHI to the public internet. You can explain BGP on a whiteboard and have configured customer gateways for all kinds of edge devices.
• Secure cross organization tunneling for PHI. You design the tunnels, configure the encryption, document what flows where, and defend it to a compliance auditor. When a new facility partner integrates, you walk their network team through the connection plan and get it working.
• Compute and data. EC2 fleets, Aurora PostgreSQL, RDS, DynamoDB, ElastiCache, and the MSK Kafka event spine. Capacity planning, scaling, patching, and broker health. You know what to do when Aurora misbehaves at 3 AM or Kafka consumer lag starts climbing.
• DNS and certificates. Route 53 zones, records, and routing rules. ACM certificates, renewal automation, and the certificate inventory.
• Identity, access, and Microsoft Entra ID. IAM and its bridge to the company directory. Conditional Access, MFA enforcement, SSO federation into AWS IAM Identity Center, SCIM provisioning into GitHub Enterprise Managed Users and the rest of the SaaS stack, and least privilege as it plays out in a real organization. You can answer who has access to what without a spreadsheet.
• Microsoft 365 administration. You run the tenant. Exchange Online, SharePoint, Teams, OneDrive, and license assignments. Group membership drives access, not hand granted permissions. Retention, sharing rules, and licensing all sit inside the same HIPAA boundary as the platform.
• Workforce and contractor provisioning. Onboarding means an Entra ID identity, group membership, NordLayer, a GitHub EMU seat, IAM Identity Center entitlement, MaxiCare application access, MFA enrollment, and a hardware security key where required. Offboarding means revoking all of it cleanly, on time, with audit evidence.
• Business continuity and backups. You watch AWS Backup jobs across Aurora, RDS, DynamoDB, EBS, and S3 every day. You run restore drills on a defined cadence. You back up configuration state, including CDK or Terraform state, Route 53 zones, IAM policies, AWS Config snapshots, and the secrets inventory, so the platform can be rebuilt from code rather than tribal memory. You own the recovery time and recovery point objectives and can prove the platform meets them.
• Monitoring and alerting. CloudWatch dashboards, alarms, log aggregation, and SNS notifications that page the right person at the right time. Billing alarms that catch a runaway resource early. Performance alerts that fire before a clinician notices latency.
• Security and audit. CloudTrail, AWS Config, GuardDuty, Security Hub, KMS keys with rotation and usage logging, Secrets Manager, and Parameter Store. You can produce HIPAA audit evidence without scrambling for two days.
• Infrastructure as code. Click ops is not part of this seat. Changes live in version control and ship through a pipeline. AWS CDK in TypeScript is the current stack. Terraform translates.
• Cost and capacity. You watch the bill, set the budgets, and bring cost problems to the team with a recommendation rather than a complaint.
• Incident response. You are on the pager rotation, you write the runbooks, and you lead the response and the post mortem.
• Other duties as assigned. This is an early stage company. You go where the work is.
Requirements
• AWS administration depth. Seven or more years administering production AWS, including senior time where you owned outcomes rather than implemented someone else's design.
• VPC, Transit Gateway, and cross organization networking. Deep production experience with VPC design, Transit Gateway, site to site VPN, and customer gateways. You have built and maintained tunnels between AWS and on premises partner networks.
• HIPAA in production AWS. You have administered AWS environments handling PHI. You know what a BAA scope looks like in practice, where the encryption boundaries sit, and what an auditor will ask for.
• Aurora PostgreSQL and RDS. Scaling, parameter tuning, backups, point in time recovery, read replicas, and failover. You have been through a real outage and can describe what you did.
• Backup, restore, and recovery. Scheduled backups, real restore drills, and recovery from a real incident. You can describe a restore you performed, what failed, and what you fixed.
• IAM and identity federation. Expert command of roles, policies, cross account access, identity providers, SSO, MFA, and access boundaries.
• Microsoft Entra ID and Microsoft 365. Production experience with Conditional Access, MFA, SCIM provisioning, the account lifecycle from onboarding through offboarding, and Exchange, SharePoint, Teams, and license management. You have run a directory, not just inherited one.
• Route 53 and DNS. Zone design, routing policies, health checks, and failover patterns.
• Networking fundamentals. You can explain TCP, BGP, IPsec, TLS, and DNS without a search engine, and you can troubleshoot when a packet does not arrive.
• Linux administration. Real production experience with systemd, the network stack, and logs.
• Infrastructure as code. AWS CDK in TypeScript, Terraform, or comparable.
• Monitoring and observability. CloudWatch, log aggregation, distributed tracing, and alerting that does not cry wolf.
• AI tool fluency. Daily use of AI for operations work, documentation, runbooks, and incident analysis. Anthropic Claude in particular.
• On call discipline. You have carried a real production pager and can teach good incident response.
• Education. A four year degree from an accredited institution, or demonstrated engineering depth that makes a degree unnecessary.
Preferred
• AWS administration on an EMR, EHR, or healthcare platform. Bonus for skilled nursing or assisted living experience.
• Time on a team that took a product through a HITRUST, SOC 2, or ONC audit.
• AWS Direct Connect for partner connectivity.
• Control Tower, account vending, and SCP design at scale.
• AWS Solutions Architect Professional, Advanced Networking Specialty, or Security Specialty. The depth matters more than the certificate.
• NordLayer, Tailscale, ZeroTier, or comparable VPN platforms in a HIPAA context.
• Multi region disaster recovery you have designed, tested, and failed over for real.
• GitHub Enterprise Managed Users with Entra ID OIDC and SCIM.
• Python, Bash, or TypeScript scripting beyond IaC.
• Clear written and spoken English. Native fluency is not required. Most team communication is asynchronous and written.
Logistics
• Location. Fully remote, across time zones.
• Time zone overlap. A few hours of overlap with US Central time on most working days. Some change windows happen overnight US time.
• Travel. Occasional, for facility partner network setup, integration testing, or a team gathering.
• On call. You are the primary infrastructure escalation in the rotation. The system runs in real facilities around the clock.
• Camera on policy. Cameras stay on by default for internal meetings, customer calls, and stakeholder reviews.
• Reporting. Reports to the Lead Product Architect. Partners daily with engineering and facility partner IT teams.
• Employment type. Full time. Employee or independent contractor status depends on your jurisdiction and is discussed during interviews.
Compensation
Competitive base compensation calibrated to your experience and the market in your jurisdiction, plus an opportunity for an annual performance bonus tied to individual and company results. Specifics are discussed during the interview process.

Work arrangement
No

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App