
- Top 10% of respondersIAM Global Alliance is in the top 10% of companies in terms of response time to applications
- Responds within two weeksBased on past data, IAM Global Alliance usually responds to incoming applications within two weeks
Cloud Engineer
- 1.0% – 2.0%
- |Remote (Everywhere)
- |1 year of exp
- |Cofounder
Remote only
Not Available
About the job
We're building a next-generation training platform combining hands-on labs, real-world scenarios, and guided learning experiences. Learners will work through lab exercises where they configure users, roles, policies, and identity services while observing the outcomes in a safe cloud environment.
We're looking for someone who is interested in becoming a long-term, founding member of the team. The initial engagement will focus on designing and standing up the cloud sandbox environment that will power our training platform. This setup phase will also provide an opportunity to become familiar with our content, training approach, and cloud IAM curriculum.
While the immediate scope is a well-defined project with clear deliverables, our goal is to identify someone who is excited about the vision and interested in growing with the platform over time as we expand our cloud, identity, security, and AI training offerings.
What we need
Build one shared, pre-provisioned [CLOUD] sandbox tenant that multiple learners use and that resets to a clean baseline between cohorts. We own the lab content and instructions; you build the environment it runs in, delivered entirely as code so we own and can rebuild it after the engagement.
Deliverables
- One sandbox tenant on [CLOUD], pre-provisioned with a representative set of users, groups, roles, and policies for learners to inspect and manipulate.
- Guardrails: region lock, a hard budget cap with alerts, and service restrictions (SCPs / Azure Policy) so learners cannot create expensive resources or operate outside the sandbox.
- Reset mechanism: a script that wipes learner changes and restores the tenant to its clean baseline between cohorts — this is what makes the environment reusable.
- Learner access: a simple, safe way to issue each learner scoped credentials (read / limited-write as labs require), with no access to billing or to other learners.
- Infrastructure as code: the entire environment defined in Terraform (or equivalent), version-controlled, so it can be rebuilt or handed off.
- Runbook: a short (1–2 page) operations guide covering how to reset, add a learner, tear down, and rebuild.
Explicitly out of scope
- Lab content, instructions, or curriculum (we provide these)
- Any attack, privilege-escalation, or adversarial scenarios
- Multi-cloud (single cloud only)
- Per-learner isolated accounts (this is a shared tenant)
Required experience
- Hands-on [CLOUD] IAM (users, groups, roles, policies) and account/tenant guardrails (SCPs or Azure Policy, budget controls)
- Terraform (or equivalent IaC) as a default way of working
- Comfort delivering a right-sized solution — a shared tenant with a reset script, not an over-engineered platform
Engagement & timeline
- Estimated effort: ~3–8 days.
How to apply
In your application, please include:
A 2–3 sentence description for the following questions
"How would you reset the sandbox to a clean baseline between cohorts — and how do you make sure it removes things a learner created that aren't in your Terraform?"
"If you finished and disappeared, how would we rebuild this environment ourselves six months later?"
"How do you prevent a learner from running up a large bill or creating resources outside the sandbox?"
One example of a similar cloud environment or IaC project you've delivered.
About the company

IAM Global Alliance
- Top 10% of respondersIAM Global Alliance is in the top 10% of companies in terms of response time to applications
- Responds within two weeksBased on past data, IAM Global Alliance usually responds to incoming applications within two weeks
Similar Jobs








