Senior AWS Control Tower Engineer / AWS Cloud Architect
10+ Years
We are seeking an experienced Senior AWS Control Tower Engineer with over 10 years of IT experience and strong expertise in AWS Cloud, AWS Control Tower, multi-account governance, landing zone implementation, and cloud security. The ideal candidate will lead the design, implementation, and management of enterprise-scale AWS environments, ensuring governance, compliance, security, and operational excellence.
- Design, implement, and manage AWS Control Tower environments for enterprise customers.
- Build and maintain secure AWS Landing Zones using AWS Control Tower and AWS Organizations.
- Configure and manage Organizational Units (OUs), account vending, Service Control Policies (SCPs), and AWS Identity Center (AWS SSO).
- Automate AWS account provisioning and governance using Infrastructure as Code (Terraform or AWS CloudFormation).
- Implement security guardrails, preventive and detective controls, and compliance policies.
- Manage centralized logging, monitoring, and auditing using AWS CloudTrail, AWS Config, CloudWatch, Security Hub, and GuardDuty.
- Design enterprise networking using Amazon VPC, AWS Transit Gateway, Direct Connect, VPN, and Route 53.
- Integrate IAM, identity federation, and role-based access control (RBAC) across AWS accounts.
- Support cloud migration and modernization initiatives following AWS best practices.
- Collaborate with security, infrastructure, DevOps, and application teams to implement governance standards.
- Optimize cloud cost using AWS Cost Explorer, Budgets, Savings Plans, and tagging strategies.
- Lead architecture reviews and ensure compliance with AWS Well-Architected Framework.
- Mentor junior cloud engineers and provide technical leadership.
- AWS Control Tower
- AWS Organizations
- AWS Identity Center (AWS SSO)
- IAM
- Amazon VPC
- AWS Transit Gateway
- Route 53
- AWS Config
- AWS CloudTrail
- Amazon CloudWatch
- AWS Security Hub
- Amazon GuardDuty
- AWS Systems Manager
- AWS Backup
- AWS KMS
- Amazon S3
- AWS Lambda
- Amazon EventBridge
- Terraform
- AWS CloudFormation
- AWS CDK (preferred)
- Git
- GitHub / GitLab / Bitbucket
- Jenkins
- AWS CodePipeline
- CI/CD implementation
- Python
- Bash
- PowerShell
- Multi-account governance
- Landing Zone implementation
- Service Control Policies (SCPs)
- IAM policies and permission boundaries
- Security guardrails
- Compliance frameworks (CIS, NIST, ISO 27001)
- Encryption and key management
- Cloud security best practices
- CloudWatch
- AWS Config
- CloudTrail
- Security Hub
- GuardDuty
- Trusted Advisor
- Incident management
- Operational excellence
- Bachelor's degree in Computer Science, Information Technology, or a related field.
- 10+ years of overall IT experience.
- 5+ years of hands-on experience with AWS Cloud.
- 3+ years of experience implementing AWS Control Tower in enterprise environments.
- Strong understanding of cloud governance, security, and compliance.
- Experience managing large-scale AWS multi-account environments.
- Excellent communication, documentation, and stakeholder management skills.
- AWS Certified Solutions Architect – Professional
- AWS Certified Security – Specialty
- AWS Certified Advanced Networking – Specialty
- AWS Certified DevOps Engineer – Professional
- AWS Certified SysOps Administrator – Associate
- Experience with cloud migration programs.
- Experience in regulated industries (Healthcare, Banking, Retail, or Life Sciences).
- Knowledge of FinOps and cloud cost optimization.
- Experience with Kubernetes/EKS and container platforms.
- Familiarity with enterprise identity providers such as Microsoft Entra ID (Azure AD) or Okta.
- Strong leadership and mentoring abilities.
- Excellent problem-solving and analytical skills.
- Ability to work with global teams and stakeholders.
- Strong documentation and presentation skills.
- Ability to drive cloud governance initiatives and architecture decisions.