About StackFloss
StackFloss is software for independent dental practices. It connects to the practice management system (PMS) and finds care patients are eligible for but haven’t received: care that is already approved, already due, or already covered. Much of it belongs to patients already on the schedule. Find it. Act on it. Automate it.
We build on five beliefs: people first, work inside what you have, earn every step, patient data comes first, and plain talk. In this role, that means HIPAA isn’t a checkbox. It’s how the infrastructure is built.
We are an early-stage team moving our MVP toward production, and we want an experienced engineer to make our AWS environment solid, reproducible and well documented.
The role
We're looking for a senior AWS infrastructure engineer to inspect our existing AWS environment, identify problems quickly, implement improvements directly, and leave behind reproducible infrastructure and clear documentation.
You set your own methods, tools and working hours. We agree on deliverables and milestones up front and review progress weekly. You will work with our CTO, the founders and our front-end developer.
Initial scope
You will help us:
- Review and stabilize the existing AWS environment
- Troubleshoot AWS networking and application routing
- Improve VPC, subnet, Security Group, DNS, TLS and load-balancer configuration
- Implement or improve Infrastructure as Code
- Configure ECS/Fargate or equivalent container infrastructure
- Improve CI/CD deployment workflows
- Review IAM and establish least-privilege access
- Implement secrets management and encryption
- Configure CloudWatch logging, metrics and alerting
- Enable and review CloudTrail and other AWS security logging
- Establish AWS Bedrock application access and permissions
- Improve AWS cost visibility and budget controls
- Document the resulting infrastructure and operating procedures
What you bring
Required AWS experience
Strong, hands-on production experience with:
| Area | Services |
|---|---|
| Networking | VPC, subnets and route tables, Security Groups, NAT and Internet Gateways, Application Load Balancers, Route 53, AWS Certificate Manager |
| Identity & security | IAM, KMS, Secrets Manager, CloudTrail |
| Compute & containers | ECS / Fargate, ECR, EC2, Docker |
| Storage & observability | S3, CloudWatch |
Infrastructure as Code
- Strong Terraform experience (preferred); OpenTofu welcome
- AWS CDK or CloudFormation experience is also acceptable
- You believe production infrastructure should be reproducible and version controlled — not dependent on manual AWS Console configuration
CI/CD
Experience building secure deployment pipelines with GitHub Actions or similar tooling. A typical workflow should support:
Source control → Validation → Container build → Security checks → ECR → AWS deployment
Security
Experience securing production AWS workloads is required. You should understand:
- Least-privilege IAM, MFA and administrative access controls
- Encryption at rest and in transit; secrets management
- Centralized logging, audit trails and VPC Flow Logs
- GuardDuty, Security Hub and AWS Config
- Backup and recovery
Strong plus: healthcare, HIPAA, SOC 2 or other regulated-environment experience.
AWS Bedrock (preferred)
Experience with Bedrock IAM permissions, model access, inference APIs, logging, quotas, cost monitoring and application authentication. Deep machine-learning experience is not required.
Ideal background
- 5+ years of cloud infrastructure, DevOps or SRE experience
- 3+ years of substantial AWS production experience
- Strong Linux, networking and Docker fundamentals
- Terraform or OpenTofu, ECS/Fargate in production, CI/CD and AWS security experience
- Startup or early-stage product experience is highly valuable
What you will leave us with
| Deliverable | What “done” looks like |
|---|---|
| Documented AWS architecture | Current-state and target-state diagrams and a written architecture overview |
| Infrastructure as Code | Version-controlled Terraform (or agreed alternative) that reproduces the environment |
| Reliable deployment workflow | CI/CD pipeline from source control through security checks to AWS deployment |
| IAM configuration | Least-privilege roles, MFA enforcement and documented administrative access |
| Secrets management | Secrets in Secrets Manager/KMS; none in code or pipeline logs |
| Logging and monitoring | CloudWatch logs, metrics, alarms and alert routing |
| Basic security controls | CloudTrail, GuardDuty, Security Hub, AWS Config, VPC Flow Logs and backups enabled and reviewed |
| Cost monitoring | Budgets, alerts and cost-allocation tagging |
| Bedrock connectivity | Scoped application access to approved models with logging and quotas |
| Operational documentation | Deployment, rollback, access and incident runbooks |
Contract terms
| Term | Detail |
|---|---|
| Classification | Independent contractor (1099); W-9 required |
| Location | Remote (US time zones preferred, with overlap to US Central for weekly reviews) |
| Hours | About 20–30 hours per week |
| Duration | Through MVP infrastructure delivery, with the option to extend as the platform moves toward production |
| Compensation | Cash only, hourly or milestone-based, with the rate discussed on the scoping call; no salary, bonus, equity or benefits |
| Equipment | Contractor provides their own equipment and tools |
| IP | All work product is assigned to StackFloss |
| Compliance | Contractor signs the agreements listed below, including an NDA and a HIPAA Business Associate Agreement |
| Start | As soon as possible |
Confidentiality and intellectual property
This project involves proprietary technology. Detailed architecture, customer integrations, internal data flows, source code and implementation methods are disclosed only after the appropriate agreements are in place. Selected contractors will sign:
- A Mutual Non-Disclosure Agreement (before the project scoping call)
- An Independent Contractor Agreement and Statement of Work
- A Confidential Information and Invention Assignment Agreement
- A Business Associate Agreement, as required for HIPAA
- The StackFloss Acceptable Use & Security Acknowledgment
All infrastructure code, Terraform, automation, scripts, deployment pipelines, technical documentation, diagrams and other project-specific work produced under the engagement will be owned by StackFloss, as defined in the contractor agreement. Access to AWS, repositories, credentials and internal systems is granted on a least-privilege basis.
Our process
| Step | What happens | Length |
|---|---|---|
| 1. Intro call | Background, availability and fit | 30 min |
| 2. Technical interview | Hands-on AWS, Terraform, CI/CD and security discussion | 30 min |
| 3. Mutual NDA | Signed before any non-public details are shared | — |
| 4. Project scoping call | Walk through the environment and agree scope and engagement terms | 60 min |
| 5. Agreements and onboarding | Contract documents, then least-privilege access | — |
StackFloss is an equal opportunity organization and welcomes applicants from all backgrounds.
StackFloss