S
AWS Senior Cloud Infrastructure Engineer
Remote · Full Time
Be the first to apply
- Experience
- 10+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 1 week ago
- Work mode
- Work from home
- Resume
- Required to apply
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Role Summary
We are looking for a seasoned AWS Senior Cloud Infrastructure Engineer / Architect to design, deploy, and enhance enterprise-scale AWS cloud infrastructure. This architect-level position demands deep expertise in AWS architecture and operational excellence, strong technical leadership, and hands-on capability across cloud, infrastructure, security, and application domains.
Core Responsibilities
- Lead and manage AWS architecture and set technical standards ensuring secure, scalable, resilient, supportable, and cost-effective enterprise cloud setups.
- Architect, deploy, operate, and refine enterprise AWS Landing Zones leveraging AWS Control Tower, Organizations, Organizational Units (OUs), Account Factory, and multi-account designs.
- Oversee full lifecycle of Landing Zones including account provisioning, baseline setup, security mechanisms, upgrades, drift remediation, central logging, network and identity integration, plus decommissioning.
- Establish preventive and proactive cloud guardrails with Control Tower, Service Control Policies, AWS Config, IAM, and policy-as-code principles.
- Develop and maintain enterprise-grade Terraform modules, Infrastructure as Code (IaC) frameworks, reusable components, coding standards, and automated deployment pipelines.
- Provide technical guidance and oversight on critical AWS infrastructure and application workloads ensuring availability, performance, capacity planning, security, and operational stability.
- Design and manage AWS networking and hybrid connectivity, covering VPCs, Transit Gateways, Direct Connect, VPNs, DNS, load balancing, micro-segmentation, PrivateLink, and VPC endpoints.
- Collaborate with cybersecurity and risk teams to enforce IAM, encryption, threat detection, vulnerability scanning, secrets management, network security, and compliance controls.
- Create secure CI/CD pipelines integrating testing, security audits, policy validation, approval processes, and deployment governance.
- Implement centralized monitoring, logging, alerting, dashboards, and observability frameworks across AWS accounts and workloads.
- Design high availability (HA) and disaster recovery (DR) strategies, backup policies, failover processes, recovery time and point objectives (RTO/RPO), and conduct DR testing.
- Drive cost optimization (FinOps) initiatives while preserving essential reliability, security, and performance standards.
- Lead troubleshooting and resolution activities for complex AWS infrastructure, networking, security, Landing Zone, deployment, and platform incidents.
- Perform architecture reviews, Terraform/IaC code assessments, security checks, and operational readiness evaluations.
- Create and sustain high-level and low-level design documents, architecture diagrams, Landing Zone and Terraform standards, runbooks, standard operating procedures (SOPs), and disaster recovery documentation.
- Mentor and provide technical leadership to Cloud, DevOps, Infrastructure, and application engineering teams.
- Continuously assess AWS service offerings, automation opportunities, and evolving cloud engineering best practices.
Essential Experience and Qualifications
- Minimum ten years of experience in IT infrastructure and cloud engineering.
- Extensive hands-on experience as a Senior Engineer or Architect within AWS ecosystem.
- Strong knowledge of AWS architecture principles and the Well-Architected Framework.
- Proven ability to design, implement, and manage enterprise AWS Landing Zones.
- Hands-on expertise with AWS Control Tower, AWS Organizations, Organizational Units, multi-account approaches, and Account Factory implementations.
- Experience managing governance, guardrails, Service Control Policies, AWS Config, and IAM controls in Landing Zones.
- Advanced Terraform skills including creating reusable modules, managing remote states, version control, environment segregation, and CI/CD integration.
- Comprehensive understanding of AWS networking concepts: VPCs, subnets, routing, security groups, Network ACLs, Transit Gateway, PrivateLink, Direct Connect, VPN, Route 53 DNS services.
- Expertise in AWS security and compliance tools such as IAM, KMS, CloudTrail, Config, Security Hub, GuardDuty, Inspector, WAF, Shield, and Secrets Manager.
- Experience with production AWS resources like EC2, Auto Scaling groups, Elastic Load Balancers, S3, EBS, EFS, RDS/Aurora, Lambda, CloudFront, Systems Manager, Backup, and ACM.
- Proficiency in automation and scripting using Python, Bash, and/or PowerShell.
- Strong background in CI/CD and AWS DevOps tools including CodePipeline, CodeBuild, Lambda, and EventBridge.
- Container expertise with ECS, ECR, Fargate; EKS/Kubernetes experience is highly valued.
- Knowledgeable in monitoring, logging and observability using CloudWatch, CloudTrail, Config, and enterprise SIEM or monitoring platforms.
- Experienced in designing HA, multi-AZ/multi-region architectures and conducting backup, disaster recovery, and failover testing focusing on RTO/RPO objectives.
- Skilled in AWS cost management and FinOps practices.
Preferred Qualifications
- AWS Certified Solutions Architect – Professional level preferred.
- AWS Certified DevOps Engineer – Professional.
- AWS Certified Security Specialty or equivalent certification.
- Experience with AWS Landing Zone Accelerator (LZA) and custom Control Tower enhancements.
- Familiarity with Control Tower Account Factory for Terraform (AFT), Terraform Cloud/Enterprise and enterprise module registries.
- Knowledge of Internal Developer Platforms, platform engineering, and self-service cloud provisioning methods.
- Enterprise-grade EKS/Kubernetes experience.
- Exposure to serverless and event-driven architecture models.
- Experience with AWS migration, cloud modernization, and hybrid cloud environments.
- Knowledge of identity federation using Entra ID, Azure AD or Active Directory via SAML/OIDC.
- Understanding of compliance frameworks such as ISO 27001, SOC 2, PCI DSS, NIST and CIS AWS Foundations Benchmark.
- Experience participating in AWS Well-Architected Reviews and establishing Cloud Centers of Excellence (CCoE).
Key Competencies
- Strong analytical aptitude and architectural design capabilities.
- Excellent problem-solving and troubleshooting skills.
- Effective communication and stakeholder management.
- Leadership in managing complex technical projects.
- Profound documentation and technical design skills.
- Ability to collaborate across Cloud, Infrastructure, Security, DevOps, and Application teams.
- Mentorship skills to guide fellow engineers and foster engineering best practices.
- Committed to production support and operations mindedness.
Skills
How they work
Teamwork & Collaboration
Problem Solving
Leadership