Description
Role OverviewWe are seeking an experienced AWS Senior Cloud Infrastructure Engineer / Architect to design, implement, operate and continuously improve enterprise-scale AWS cloud infrastructure.
The ideal candidate will have deep hands-on expertise across AWS Architecture, AWS Landing Zones, AWS Control Tower, AWS Organizations, Terraform, networking, security, governance, DevOps and production cloud operations.
This is an architect-level engineering role requiring strong technical ownership, hands-on delivery capability and the ability to provide technical leadership across cloud, infrastructure, security and application engineering teams.
Key Technical SkillsAWS Architecture and AWS Well-Architected FrameworkAWS Landing Zones and multi-account architectureAWS Control Tower and AWS OrganizationsOrganizational Units (OUs), Account Factory and account lifecycle managementInfrastructure as Code (IaC)Terraform, CloudFormation and/or AWS CDKAWS networking and hybrid connectivityIAM, security, governance and cloud guardrailsDevOps and CI/CDContainers and cloud-native platformsMonitoring, logging and observabilityHigh Availability and Disaster RecoveryCloud automation and production workload managementFinOps and AWS cost optimisationKey ResponsibilitiesOwn and drive AWS architecture and technical standards for secure, scalable, resilient, supportable and cost-efficient enterprise cloud environments.Architect, implement, operate and continuously improve enterprise AWS Landing Zones using AWS Control Tower, AWS Organizations, OUs, Account Factory, shared services and multi-account patterns.Manage the complete Landing Zone lifecycle, including account provisioning, baseline configuration, security controls, upgrades, configuration drift, centralised logging, network and identity integration, and account decommissioning.Design and maintain preventive, detective and proactive cloud guardrails using Control Tower controls, Service Control Policies (SCPs), AWS Config, IAM and policy-as-code.Develop and maintain enterprise-grade Terraform modules, IaC frameworks, reusable patterns, coding standards and automated deployment pipelines.Provide technical oversight for mission-critical AWS infrastructure and application workloads, ensuring availability, performance, capacity, security and operational stability.Design and manage AWS networking and hybrid connectivity, including VPCs, Transit Gateway, Direct Connect, VPN, DNS, load balancing, segmentation, PrivateLink and VPC endpoints.Partner with cybersecurity and risk teams to implement IAM, encryption, threat detection, vulnerability management, secrets management, network security and compliance controls.Design secure CI/CD pipelines incorporating testing, security scanning, policy validation, approvals and deployment controls.Implement centralised monitoring, logging, alerting, dashboards and observability across AWS accounts and workloads.Design and validate HA/DR strategies, backup policies, failover mechanisms, RTO/RPO objectives and disaster recovery testing.Drive AWS cost optimisation and FinOps initiatives while maintaining required reliability, security and performance.Lead troubleshooting and resolution of complex AWS infrastructure, networking, security, Landing Zone, deployment and application-platform incidents.Conduct architecture, Terraform/IaC, security and operational-readiness reviews.Create and maintain HLDs, LLDs, architecture diagrams, Landing Zone standards, Terraform standards, runbooks, SOPs and DR procedures.Provide technical leadership and mentoring to Cloud, DevOps, Infrastructure and application engineering teams.Continuously evaluate AWS services, automation opportunities and emerging cloud engineering practices.Essential Experience10+ years of IT infrastructure and cloud engineering experience.Extensive hands-on AWS experience at Senior Engineer / Architect level.Strong expertise in AWS architecture and the AWS Well-Architected Framework.Proven experience designing, implementing and managing enterprise AWS Landing Zones.Strong hands-on experience with AWS Control Tower and AWS Organizations.Experience with OUs, multi-account strategies, Account Factory and shared-services architectures.Demonstrated experience managing Landing Zone governance, guardrails, SCPs, AWS Config and IAM controls.Expert-level Terraform experience, including reusable modules, remote state, versioning, environment segregation and CI/CD integration.Strong AWS networking knowledge covering VPCs, subnets, routing, Security Groups/NACLs, Transit Gateway, PrivateLink, Direct Connect, VPN and Route 53.Strong AWS security and governance experience covering IAM, KMS, CloudTrail, Config, Security Hub, GuardDuty, Inspector, WAF, Shield and Secrets Manager.Experience managing production AWS workloads including EC2, Auto Scaling, ELB, S3, EBS/EFS, RDS/Aurora, Lambda, CloudFront, Systems Manager, Backup and ACM.Strong automation/scripting capability using Python, Bash and/or PowerShell.Experience with CI/CD and AWS DevOps tooling such as CodePipeline, CodeBuild, Lambda and EventBridge.Experience with containers including ECS, ECR and Fargate; EKS/Kubernetes is highly desirable.Strong understanding of monitoring, logging and observability using CloudWatch, CloudTrail, Config and enterprise monitoring/SIEM platforms.Proven experience with HA, Multi-AZ/Multi-Region architecture, backup, DR, RTO/RPO and failover testing.Strong understanding of AWS cost optimisation and FinOps practices.Desirable ExperienceAWS Certified Solutions Architect – Professional.AWS Certified DevOps Engineer – Professional.AWS Certified Security – Specialty or equivalent.AWS Landing Zone Accelerator (LZA).Customizations for AWS Control Tower.Control Tower Account Factory for Terraform (AFT).Terraform Cloud / Terraform Enterprise and enterprise module registries.Internal Developer Platforms (IDPs), platform engineering and self-service cloud provisioning.Enterprise-scale EKS/Kubernetes.Serverless and event-driven architectures.AWS migration and cloud modernisation.Hybrid cloud environments.Entra ID / Azure AD or Active Directory federation using SAML/OIDC.Knowledge of ISO 27001, SOC 2, PCI DSS, NIST and CIS AWS Foundations Benchmark.AWS Well-Architected Reviews and Cloud Centre of Excellence (CCoE) initiatives.Key CompetenciesStrong architectural and analytical thinking.Excellent troubleshooting and problem-solving skills.Strong stakeholder and communication skills.Ability to lead complex technical initiatives.Strong documentation and design skills.Ability to work across Cloud, Infrastructure, Security, DevOps and Application teams.Ability to mentor engineers and establish engineering standards.Strong production ownership and operational mindset.