S

AWS Senior Cloud Infrastructure Engineer

SG Consulting Limited

Remote · Full Time

Be the first to apply

Experience
10+ yrs
Salary
Openings
1
Posted
1 week ago
Work mode
Work from home
Resume
Required to apply

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

Role Summary

We are looking for a seasoned AWS Senior Cloud Infrastructure Engineer / Architect to design, deploy, and enhance enterprise-scale AWS cloud infrastructure. This architect-level position demands deep expertise in AWS architecture and operational excellence, strong technical leadership, and hands-on capability across cloud, infrastructure, security, and application domains.

Core Responsibilities

  • Lead and manage AWS architecture and set technical standards ensuring secure, scalable, resilient, supportable, and cost-effective enterprise cloud setups.
  • Architect, deploy, operate, and refine enterprise AWS Landing Zones leveraging AWS Control Tower, Organizations, Organizational Units (OUs), Account Factory, and multi-account designs.
  • Oversee full lifecycle of Landing Zones including account provisioning, baseline setup, security mechanisms, upgrades, drift remediation, central logging, network and identity integration, plus decommissioning.
  • Establish preventive and proactive cloud guardrails with Control Tower, Service Control Policies, AWS Config, IAM, and policy-as-code principles.
  • Develop and maintain enterprise-grade Terraform modules, Infrastructure as Code (IaC) frameworks, reusable components, coding standards, and automated deployment pipelines.
  • Provide technical guidance and oversight on critical AWS infrastructure and application workloads ensuring availability, performance, capacity planning, security, and operational stability.
  • Design and manage AWS networking and hybrid connectivity, covering VPCs, Transit Gateways, Direct Connect, VPNs, DNS, load balancing, micro-segmentation, PrivateLink, and VPC endpoints.
  • Collaborate with cybersecurity and risk teams to enforce IAM, encryption, threat detection, vulnerability scanning, secrets management, network security, and compliance controls.
  • Create secure CI/CD pipelines integrating testing, security audits, policy validation, approval processes, and deployment governance.
  • Implement centralized monitoring, logging, alerting, dashboards, and observability frameworks across AWS accounts and workloads.
  • Design high availability (HA) and disaster recovery (DR) strategies, backup policies, failover processes, recovery time and point objectives (RTO/RPO), and conduct DR testing.
  • Drive cost optimization (FinOps) initiatives while preserving essential reliability, security, and performance standards.
  • Lead troubleshooting and resolution activities for complex AWS infrastructure, networking, security, Landing Zone, deployment, and platform incidents.
  • Perform architecture reviews, Terraform/IaC code assessments, security checks, and operational readiness evaluations.
  • Create and sustain high-level and low-level design documents, architecture diagrams, Landing Zone and Terraform standards, runbooks, standard operating procedures (SOPs), and disaster recovery documentation.
  • Mentor and provide technical leadership to Cloud, DevOps, Infrastructure, and application engineering teams.
  • Continuously assess AWS service offerings, automation opportunities, and evolving cloud engineering best practices.

Essential Experience and Qualifications

  • Minimum ten years of experience in IT infrastructure and cloud engineering.
  • Extensive hands-on experience as a Senior Engineer or Architect within AWS ecosystem.
  • Strong knowledge of AWS architecture principles and the Well-Architected Framework.
  • Proven ability to design, implement, and manage enterprise AWS Landing Zones.
  • Hands-on expertise with AWS Control Tower, AWS Organizations, Organizational Units, multi-account approaches, and Account Factory implementations.
  • Experience managing governance, guardrails, Service Control Policies, AWS Config, and IAM controls in Landing Zones.
  • Advanced Terraform skills including creating reusable modules, managing remote states, version control, environment segregation, and CI/CD integration.
  • Comprehensive understanding of AWS networking concepts: VPCs, subnets, routing, security groups, Network ACLs, Transit Gateway, PrivateLink, Direct Connect, VPN, Route 53 DNS services.
  • Expertise in AWS security and compliance tools such as IAM, KMS, CloudTrail, Config, Security Hub, GuardDuty, Inspector, WAF, Shield, and Secrets Manager.
  • Experience with production AWS resources like EC2, Auto Scaling groups, Elastic Load Balancers, S3, EBS, EFS, RDS/Aurora, Lambda, CloudFront, Systems Manager, Backup, and ACM.
  • Proficiency in automation and scripting using Python, Bash, and/or PowerShell.
  • Strong background in CI/CD and AWS DevOps tools including CodePipeline, CodeBuild, Lambda, and EventBridge.
  • Container expertise with ECS, ECR, Fargate; EKS/Kubernetes experience is highly valued.
  • Knowledgeable in monitoring, logging and observability using CloudWatch, CloudTrail, Config, and enterprise SIEM or monitoring platforms.
  • Experienced in designing HA, multi-AZ/multi-region architectures and conducting backup, disaster recovery, and failover testing focusing on RTO/RPO objectives.
  • Skilled in AWS cost management and FinOps practices.

Preferred Qualifications

  • AWS Certified Solutions Architect – Professional level preferred.
  • AWS Certified DevOps Engineer – Professional.
  • AWS Certified Security Specialty or equivalent certification.
  • Experience with AWS Landing Zone Accelerator (LZA) and custom Control Tower enhancements.
  • Familiarity with Control Tower Account Factory for Terraform (AFT), Terraform Cloud/Enterprise and enterprise module registries.
  • Knowledge of Internal Developer Platforms, platform engineering, and self-service cloud provisioning methods.
  • Enterprise-grade EKS/Kubernetes experience.
  • Exposure to serverless and event-driven architecture models.
  • Experience with AWS migration, cloud modernization, and hybrid cloud environments.
  • Knowledge of identity federation using Entra ID, Azure AD or Active Directory via SAML/OIDC.
  • Understanding of compliance frameworks such as ISO 27001, SOC 2, PCI DSS, NIST and CIS AWS Foundations Benchmark.
  • Experience participating in AWS Well-Architected Reviews and establishing Cloud Centers of Excellence (CCoE).

Key Competencies

  • Strong analytical aptitude and architectural design capabilities.
  • Excellent problem-solving and troubleshooting skills.
  • Effective communication and stakeholder management.
  • Leadership in managing complex technical projects.
  • Profound documentation and technical design skills.
  • Ability to collaborate across Cloud, Infrastructure, Security, DevOps, and Application teams.
  • Mentorship skills to guide fellow engineers and foster engineering best practices.
  • Committed to production support and operations mindedness.

How they work

Teamwork & Collaboration Problem Solving Leadership
🤖
Online · instant AI help
Broxer