MTF Institute Research Report · 7 October 2026
Technical report number: MTF-CF-RR-CE-2026-01
Author: MTF Institute Research Team
Editorial and methodological review: MTF Institute Research QA (internal)
Vacancy retrieval date: 7 October 2026
Research geography: U.S.-eligible employer postings
Research archive: The exact Zenodo version DOI contains the seven-page PDF report, the 100-posting source index and the methodology and data dictionary.
Abstract
What do current U.S. cloud and platform engineering vacancies ask practitioners to build, deliver and operate? We examined a structured purposive sample of 100 distinct employer postings from 88 employer labels, with public role detail and an application path checked on 7 October 2026. The postings describe infrastructure provisioning, automated configuration and deployment, monitoring, reliability work and handoffs, but they differ in platform ownership, seniority, operating environment and decision scope. Federal or restricted settings introduce applicant conditions that must be read separately from commercial roles and from one another. This report distinguishes assigned duties from candidate qualifications, named tools from required methods, and explicit statements from fields the posting leaves unclear. Its counts, where independently reviewed, describe only the selected postings and their stated text. The sample is not a representative census of U.S. vacancies, and the adjacent BLS occupations are not Cloud Engineer-specific forecasts.
Question and method
This study examines what selected U.S. employer vacancies ask cloud, cloud infrastructure, and platform engineers to build, deliver, and operate. We used a structured purposive sample to capture a range of employers, role levels, locations, and operating environments. A posting entered the principal sample only when an employer-controlled detail page identified the employer and substantial cloud-infrastructure or service-platform responsibility, an exact publisher-linked listing established a U.S. work location or explicit U.S. remote option, and the individual role showed a live application path when checked. That responsibility could include provisioning, infrastructure as code, deployment systems, observability, reliability, or operational handoff. DevOps and site reliability roles were included only when the posting gave them meaningful cloud or platform infrastructure ownership. Search results were used to find candidates, not as substitutes for individual employer postings. Some retained postings also allowed applicants outside the United States, but each had an exact U.S. work option; non-U.S. vacancies did not fill gaps in the U.S. sample. The selected corpus contains 100 distinct postings from 88 employer labels, all checked on 7 October 2026.
We excluded closed or inaccessible pages, roles without verifiable U.S. geography, and jobs where cloud technology was incidental to generic application development, product security, data-platform administration, hardware operations, sales, or release coordination alone. We checked employer and requisition identifiers, canonical URLs, locations, and substantive role text for duplicates. The same role advertised for more than one location counted once, even if the employer assigned different posting IDs. The assembled ledgers contained 129 source rows; nine exact cross-lane URL duplicates and twenty further records were removed, leaving 100 selected postings. Those twenty were outside the final denominator: three adjacent specialties, three whose exact U.S. work location could not be bound to the requisition, and fourteen whose full source-field coding did not pass independent review. These exclusions followed the same role, geography and coding rules for every source. Separate roles at one employer remained separate only where their duties or requirements supported that distinction. Each retained record carries a source URL, the date it was checked, the observed application signal, and a short role-content excerpt; the URL, location and observed application route together support inclusion. A retrieval date establishes that the listing was readable then; it is not treated as the date the role was first posted.
We coded duties and expected work products separately from technical methods, named tools, and observable ways of working. We also recorded stated education and experience, required and preferred qualifications, role level, work cadence, team interfaces, decision authority, and escalation routes. A technology named as one option in an “or” list was coded as an alternative, not as a separate mandatory requirement. Generic product examples in application questions and benefit descriptions were not treated as employer stack or job requirements. Where an application question explicitly stated U.S. citizenship or a certification preference, we recorded that condition with its application-question provenance and stated status. Where a field was absent or could not be resolved from the posting, we marked it unknown rather than coding a negative. The count table below shows both explicit observations and the number of postings fully reviewed for each narrow category; the complete selected sample is shown separately. We checked co-mentions and contrary cases so a broad code would not erase role-specific context.
Federal and restricted-environment postings were analysed as a distinct segment. We kept U.S. citizenship, U.S.-person status, eligibility to obtain a clearance, an active Secret clearance, active Top Secret with SCI eligibility, active TS/SCI, and polygraph conditions separate. When one requisition described different conditions for different work arrangements, it remained one posting with each condition attached to the relevant opening. One Amazon posting uses different wording between its description and Basic Qualifications for active TS/SCI versus active Top Secret with SCI eligibility. We preserved the conflict and did not assign it an exact active-TS/SCI count. BLS Computer Network Architects and O*NET Computer Systems Engineers/Architects were used only as adjacent occupational context; neither defines this vacancy sample or supplies a Cloud Engineer-specific forecast. Findings are written as original synthesis, with brief necessary excerpts and links back to employer pages rather than reproduced job descriptions, vendor certification objectives, or standards text.
What the selected postings explicitly state
The table uses one distinct employer requisition as its unit. Each row has its own complete-review denominator; an unresolved category decision is excluded from that row's denominator. ‘Not stated in the reviewed posting’ does not mean that the employer lacks the practice or that a hired engineer never performs it. The six categories overlap, and the container-orchestration row describes a method capability, not a mandatory Kubernetes requirement.
| Narrow category in the posting text | Explicitly stated | Possible-only wording | Not stated after full review | Unresolved | Fully reviewed |
|---|---|---|---|---|---|
| Assigned infrastructure-as-code implementation or upkeep | 54 | 1 | 44 | 1 | 99 |
| Assigned cloud or platform deployment-pipeline work | 61 | 2 | 36 | 1 | 99 |
| Assigned monitoring, telemetry, alerting or SLI/SLO mechanism work | 60 | 2 | 37 | 1 | 99 |
| Assigned production reliability, availability, recovery or incident work | 79 | 1 | 19 | 1 | 99 |
| Intended runbook, operating procedure or comparable handoff document | 22 | 0 | 73 | 5 | 95 |
| Stated container-orchestration design or operating capability | 63 | 0 | 31 | 6 | 94 |
Among the 98 postings fully reviewed for both definite-duty categories, 42 explicitly assigned both infrastructure-as-code implementation or upkeep and cloud/platform deployment-pipeline work. In a separately reviewed intersection of 98 postings, 53 explicitly assigned both observability work and at least one production reliability, availability, recovery or incident responsibility. These are within-posting co-mentions, not causal relationships or a standard role bundle.
The production reliability row is a composite of explicit reliability, availability, recovery or incident responsibilities. It is not an incident-response or on-call count. The operating-document row includes named procedures and comparable handoff documents, not only documents literally titled ‘runbook’; it records intended outputs, not completed deliverables. Possible-only wording is shown separately from definite duties. No percentage is inferred because at least one decision in every category remained unresolved after full source review.
Sample composition and interpretation
The 100 selected requisitions carry 88 employer labels. Seven labels contribute more than one distinct requisition, and the largest label contributes 4. Several postings from the same employer count as separate roles only when their requisitions and substantive work differ. These labels are not a population frame or a measure of how many independent employers require a capability. Public source links and the source index identify every selected posting.
These examples come from a structured purposive set of individual U.S.-eligible employer postings checked on 7 October 2026. They illustrate how particular employers describe intended work; they do not estimate the prevalence of any duty or qualification in the U.S. labor market or prove that an artifact was produced after hiring.
Where the role begins and ends
The common center of these examples is responsibility for the infrastructure on which services run. Qrypt's Senior Cloud Engineer is asked to build and run an AWS environment with Terraform, develop supporting cloud services, extend deployment into customer environments, and make service health visible. Rockstar Games describes a different setting: its Cloud Platform Engineer evaluates cloud services, maintains cloud-platform usage patterns and supports development teams while also operating on-premises Kubernetes and Linux systems. Together, these postings show that “cloud” can refer to a production platform and its hybrid connections, rather than only to resources hosted by a public-cloud vendor.
The role touches several neighboring functions. Delivery pipelines, release controls, identity settings, security guardrails and cost signals appear within infrastructure work, and these examples place the engineer at specific interfaces with other owners. Dragos asks an infrastructure engineer to manage release pipelines and cloud networking while collaborating with engineering teams on observability and security. nCino describes an engineer who supports application teams with AWS infrastructure, security controls, deployment automation and cost decisions. The role boundary is the design and operation of the shared platform and its technical handoffs; an employer's mention of a control or tool does not make the engineer the owner of every release, security, identity or financial-governance decision.
Responsibilities and work products
The work products vary with the platform's stage. Heartflow describes a compute migration from AWS Lambda and ECS workloads to Kubernetes. The role is asked to define a migration roadmap and reference patterns, build Terraform and Helm infrastructure, provide deployment tooling, benchmark migrated services and document operating guardrails. The City and County of San Francisco describes hands-on cloud migration inside established architectures: Terraform configurations, reviewed deployment pipelines, application and database cutovers, testing, and documentation for colleagues. These are examples of intended artifacts and controls, rather than proof that a particular migration has already succeeded.
In a platform operating role, the output is also evidence that a system can be maintained after deployment. OpenTeams asks for reproducible environments, signed and scanned release artifacts, monitoring, runbooks and validation in restricted or disconnected environments. Cadwell asks its cloud reliability engineer to document escalation procedures and routinely test backup and disaster-recovery strategies for hosted healthcare software. The latter posting's remote header conflicts with an application question about working onsite in Kennewick, Washington; this example is about operational work products, with work modality left unresolved.
Interfaces and decision scope
The postings do not assign one uniform level of authority. In a staff-level example, AlphaSense expects an engineer to help shape the Cloud Platform architectural roadmap and lead technical initiatives with product and platform teams. Huntress likewise describes roadmap initiatives and guidance on software architecture choices across engineering teams. Those are positive forms of technical direction; neither page, by itself, establishes a formal sign-off right over every production change.
Other roles describe different decision paths. San Francisco's Cloud Engineer independently delivers assigned work within established architecture and team standards, with senior engineers available for complex design, migration and cutover decisions. Amazon's Systems Development Engineer in its Dedicated Cloud organization participates in design and prioritization discussions under senior guidance and explicitly escalates ambiguous problems or architectural deficiencies to more experienced colleagues. Intellum describes technical direction, mentoring and recommendations on infrastructure priorities. Reading these clauses at their stated level avoids treating ownership, participation, recommendation, escalation and formal approval as interchangeable powers.
Federal and restricted environments
The federal and restricted examples need their own interpretation. Defense Unicorns' platform posting requires active Secret clearance at the start and states U.S. citizenship in its application question. Another Defense Unicorns senior platform posting requires U.S. citizenship but phrases its clearance condition as eligibility or active TS/SCI. These are different applicant conditions within one employer's public postings; they cannot be merged into a general Cloud Engineer minimum.
Amazon's Region Reliability Engineering posting requires current active TS/SCI with polygraph and describes a later agency-specific clearance step. A separate Amazon Region Reliability posting contains a source-level tension: its description says current active TS/SCI, while its Basic Qualifications line says active Top Secret with SCI eligibility or above; it also describes later agency-specific polygraph completion. The exact initial TS/SCI condition for that latter posting remains unresolved. By comparison, Accenture Federal Services' broader cloud/platform posting requires U.S. citizenship without stating an active-clearance minimum. Citizenship, eligibility, active clearance, polygraph timing and work authorization remain separate source facts, and none of these postings establishes a universal rule for commercial cloud engineering roles.
Limitations
This is a purposive collection of publicly accessible employer postings, not a random or representative sample of U.S. cloud-engineering vacancies. Search visibility, employer hiring systems, geographic wording, and the availability of individual job pages affect which roles can be examined. Some employers contribute more than one distinct requisition, and federal or clearance-related roles may be prominent in the accessible set. Within-sample counts describe only the selected postings and the fields that could be coded; they are not national prevalence, employer-adoption, hiring-growth, or wage estimates.
A live application path shows that a role was open to applications when checked. It does not establish when the vacancy was first posted, how long it remained open, how many people were hired, or whether the employer ultimately used the named tools. Job advertisements describe intended responsibilities and candidate criteria, which may differ from day-to-day practice after hiring. Vendor and tool lists may be alternatives, examples, preferences, or actual operating systems; their wording must be read before assigning requirement status. Missing detail, including an unstated degree, cadence, approval right, or escalation route, remains unknown rather than evidence that the condition does not exist.
The study covers U.S. vacancy evidence. Non-U.S. practice, a vendor release, or an adjacent occupation cannot validate a U.S. vacancy-frequency claim. In particular, BLS projections for Computer Network Architects and O*NET descriptions of related engineering work should not be transferred to a Cloud Engineer title. The federal and restricted-environment segment has its own selection effects and eligibility conditions, so its clearance, citizenship, and compliance requirements must not be generalized to civilian cloud-engineering roles. The source index below lists every selected posting URL, and source-linked examples let readers inspect illustrative wording while limiting reproduction of employer text. The complete coded ledger remains part of the research record.
Conclusion
The observed role extends from infrastructure definition and delivery to production operation and handoff, but the precise mix changes across employers, levels and environments. A defensible description of cloud engineering work therefore names the actual platform boundary, assigned activities, expected evidence and decision handoffs. The results are evidence about the text of these selected current postings, not a national forecast, hiring probability, installed-technology estimate or guarantee of workplace practice.
This vacancy report is separate from MTF Institute's current-changes review, which analyzes dated product and project releases rather than using vacancies as trend evidence.
Sources and rights
The source index below lists all 100 employer-controlled or employer-authorized individual posting URLs and their 7 October 2026 retrieval date. Employer postings remain their publishers' material. This report uses original analysis, brief paraphrases and direct links; it does not reproduce job descriptions, logos, vendor training objectives or standards text.
Appendix: selected employer posting index
All URLs below were checked with a role-matched application path on 7 October 2026. The date is a retrieval check, not a first-posted date. A source may change or close later.
- 2K — Staff Platform Engineer (Austin, TX). WA224.
- Accenture Federal Services — Cloud Engineer (Hill AFB, UT). WA317.
- Accenture Federal Services — Cloud Platform Engineer (Washington, DC). WA318.
- Accenture Federal Services — Cloud Platform Engineer (Chantilly, VA). WA319.
- Accenture Federal Services — Senior Cloud Engineer (Hill AFB, UT). WA022.
- AlphaSense — Staff Platform Engineer, Core Cloud Platform (Remote, United States). WA024.
- Amazon Development Center U.S., Inc. — Amazon Dedicated Cloud Engineer, Region Reliability (Denver, CO, USA). MC002.
- Amazon Development Center U.S., Inc. — Amazon Dedicated Cloud Engineer, Region Reliability Engineering (Denver, CO, USA). MC001.
- Amazon Development Center U.S., Inc. — Systems Development Engineer, AI/ML Amazon Dedicated Cloud (Arlington or Herndon, VA, USA). MC003.
- Anduril Industries — Senior Cloud Infrastructure Engineer (Washington, District of Columbia, United States). B068.
- Appnovation Technologies — AWS Cloud Platform Engineer (New York NY; Austin TX; Miami FL; Dallas TX). WA223.
- Arista Networks — FedRAMP Site Reliability Engineer (FedSRE) - CloudVision (Remote, United States). B207.
- Avaloq — Senior Platform Engineer (Cloud Platform) (Fort Lauderdale, FL). WA304.
- Banyan Software — Senior SRE (Canada; United States). B034.
- BarkleyOKRP / MissionOne Media — Senior Infrastructure Engineer (Remote, United States). WA219.
- bet365 — Cloud Platform Engineer (Denver, CO; hybrid). WA305.
- Blackpoint Cyber — Sr. Site Reliability Engineer (Remote - United States). B201.
- Cadwell — Cloud Site Reliability Engineer (United States; header says Remote, USA, application asks onsite Kennewick, Washington or relocation). B213.
- Calendly — Staff Platform Engineer (Remote, United States). WA205.
- Capital Solutions Group — Senior DevOps Engineer (Springfield or Herndon, VA). WA013.
- CentralReach — Principal Platform Engineer (Remote - US). B060.
- CentralReach — Site Reliability Engineer (SRE), Data Products (Remote, US). B033.
- CentralReach — Sr. Site Reliability Engineer (Remote, US). B036.
- Chromatic — Senior DevOps Engineer (Remote; US or Canada). B088.
- City and County of San Francisco — Cloud Engineer (1042) (San Francisco, CA). WA306.
- Clair — DevOps Engineer (Remote - United States). B203.
- Cloudnexa — Level 3 - Senior Cloud Support Engineer (Newtown Square, PA). WA320.
- Clover Health / Counterpart Health — Senior Site Reliability Engineer (Remote - USA). B210.
- Constellation Technologies, Inc. — Cloud Engineer (DevOPS) (Springfield, VA). WA003.
- Crypto.com — Senior DevOps Engineer, United States (United States / San Francisco / New York / Chicago). WA009.
- Defense Unicorns — Platform Engineer (FedD180/FedD181) (Remote, United States). WA015.
- Defense Unicorns — Platform Engineer (FedD200/FedD201/FedD202) (Remote, United States). WA014.
- Defense Unicorns — Senior Platform Engineer (Remote, United States). WA016.
- Dragos — Senior Cloud Infrastructure Engineer (United States). WA004.
- Dragos — Senior Cloud Operations Engineer (United States). WA021.
- DRW — Cloud Engineer (Chicago, IL). WA310.
- Dscout — Senior DevOps Engineer (Remote - US). B086.
- EDO — Senior Platform Engineer (Los Angeles, CA; New York, NY; San Francisco, CA; remote U.S.). WA213.
- Ema — Devops Engineer, US (San Francisco / United States Remote). B202.
- Epsilon ASI — Senior Platform Engineer (United States; Denver, Colorado). B020.
- Fantom Corporation — Platform Engineer (Chantilly, VA). WA008.
- First Due — Platform Site Reliability Engineer (Remote - US Only). B031.
- Focused — Senior Platform Engineer (Chicago, IL). WA221.
- Gemini — Senior Platform Engineer (New York, NY; Miami, FL; remote USA). WA218.
- Gemini — Staff Platform Engineer (New York, NY; Miami, FL; remote USA). WA204.
- Gibson Dunn — Platform Engineer - US (Washington, DC). WA214.
- GRVTY — Infrastructure Engineer (Herndon, VA). WA018.
- Heartflow — Senior Platform Engineer (Compute Migration) (San Francisco, CA). WA301.
- HP IQ — Senior Platform Engineer (San Francisco, CA). WA028.
- Hume AI — Senior Platform Engineer (New York, NY). WA025.
- Huntress — Staff Platform Engineer (Remote, United States). WA201.
- iCapital — Cloud Infrastructure Engineer - Vice President (Salt Lake City, Utah, United States). B009.
- iCapital — Lead AI/MLOps Infrastructure Engineer - Senior Vice President (New York, New York, United States). B204.
- Intellum — Lead Site Reliability Engineer (Remote, United States). B205.
- ION Group — Lead DevOps Engineer (New York, NY). WA011.
- Kalepa — Senior Platform Engineer - Infrastructure (USA) (New York, NY; Remote US). B084.
- Keeper Security — Senior Federal Platform Engineer (Remote, US). B063.
- Komodo Health — Senior Infrastructure Engineer (United States; Pacific time zone). WA220.
- Kunai — Senior Cloud Engineer (Remote, United States). WA017.
- Langan Engineering & Environmental Services — Staff Azure Cloud Engineer (Austin TX; Dallas TX; New York NY). WA316.
- Legion — Principal Software Engineer, DevOps (Remote, United States). B212.
- Manifest — Senior Infrastructure Engineer (Remote, U.S. work authorization required). WA209.
- Metropolis — Senior Central Cloud Infrastructure Engineer (New York, New York, United States). B007.
- Mirantis — Cloud Infrastructure Engineer - Kubernetes & KubeVirt (Austin, TX; telecommuting permitted). WA303.
- Motive — Staff Platform Engineer (Austin, TX; hybrid). WA225.
- MX Technologies — Sr. Cloud Platform Engineer (Lehi, UT). WA313.
- MyFitnessPal — Site Reliability Engineer (Remote - US). B032.
- nCino — Senior Platform Engineer - Cloud Infrastructure (Lehi, UT). WA027.
- New Era Technology — Senior Platform Engineer – AWS / Kubernetes (Chattanooga, TN). WA026.
- NextGen Federal Systems — Cloud Solutions Engineer (Data & Platform) (Falls Church, VA). WA010.
- North Point Technology — Cloud Engineer (Littleton, CO). WA308.
- Northwestern Medicine — Cloud Engineer (Chicago, IL). WA302.
- NTT DATA Services — Kubernetes Engineer (Lead Infrastructure Engineer) (Irving, TX or Charlotte, NC; hybrid). WA314.
- Ookla — Site Reliability Engineer (Engineering Remote - United States). B209.
- OpenTeams — Platform Engineer, AI/ML Infrastructure (United States - Remote OR Hybrid). B001.
- Paperless Parts — Platform Engineer II (Boston, MA). WA217.
- Polymarket — Staff Infrastructure Engineer, US (New York, United States). B071.
- Prelim — Senior DevOps Engineer (Remote | US). B090.
- Qrypt — Senior Cloud Engineer (Austin, TX). WA001.
- Recorded Future — Senior Platform Engineer (Remote - USA). B215.
- Reltio — Staff Platform Engineer (Raleigh-Cary NC; Austin/Dallas TX; Tampa FL; Boston MA). WA208.
- Robots & Pencils — Staff Platform Engineer (Seattle, WA; remote preference Seattle metro). WA207.
- Rockstar Games — Cloud Platform Engineer (Manhattan, New York, United States). B040.
- RxSense — Principal Platform Engineer (Remote, United States). WA202.
- Schrödinger — Senior Cloud Engineer (New York, United States; Portland (state not shown)). B054.
- Skydio — Site Reliability Engineer (San Mateo, California, United States; US Remote). B021.
- Strivacity — Senior Platform Engineer (Remote U.S.; Herndon, VA). WA212.
- Synergy ECP / NetServices — Senior Cloud Platform Engineer (Fairfax, VA). WA023.
- Tempo — Platform Engineer (Remote - USA) (USA (Remote)). B069.
- Terzo Technologies — (Sr/Staff) Platform Engineer (Remote, United States). WA203.
- Together AI — Staff Platform Infrastructure Engineer (San Francisco, CA). WA211.
- Turnkey — Senior Infrastructure Engineer (Remote, United States). WA210.
- Verantos — Senior Platform Engineer (Remote, United States). WA216.
- Very Good Security — Sr. Infrastructure Engineer (United States or Canada; remote). B100.
- Vida Health — Site Reliability Engineer III (United States; remote). B017.
- VulnCheck — Senior Cloud Infrastructure Engineer (Remote; MA, MD, or Austin TX preferred). WA222.
- Vultr — Platform Engineer - Cloud Native (Remote - United States). B114.
- WellSaid — Senior Software Engineer, Site Reliability & Security (Remote - United States). B206.
- Wurl — Staff Platform Engineer (Remote, United States). WA206.
- Wysh — Infrastructure Engineer (DevOps) (United States). B008.