About the Role
Client is strengthening its enterprise cloud foundations as part of a broader hybrid and multi-cloud strategy. The Principal AWS Landing Zone Architect will own the target architecture and provide hands-on technical leadership through implementation, assurance and transition into operations.
The role requires someone who has previously built enterprise AWS landing zones at scale and can translate security, compliance, networking, identity, delivery and operational requirements into a practical platform that product teams can consume safely.
What success looks like in the role
- Approved AWS target architecture covering identity, networking, security, logging, resilience and cost governance.
- Multi-account AWS foundation using Organizations & Control Tower with automated account onboarding.
- Automated deployment using Terraform/IaC, version control and CI/CD.
- Built-in security & compliance with central monitoring, logging and evidence.
- Clear operating model covering ownership, support, lifecycle and governance.
- Reusable AWS patterns & documentation for fast, secure workload adoption.
Key Accountabilities
Architecture Ownership
- Lead AWS Landing Zone architecture, governance, standards and roadmap.
- Design multi-account, OU structure, SCPs, identity and AWS governance.
- Engage with Cyber, Network, Identity, Risk, Operations and Delivery teams.
Technical Design & Delivery
- Lead AWS Control Tower, Organizations, IAM Identity Center & Account Factory.
- Design Terraform/IaC, CI/CD, networking, Direct Connect, Transit Gateway, VPC & DNS.
- Define security, logging, monitoring, DR, encryption and operational controls.
Required experience
- Significant experience in senior infrastructure, platform or cloud engineering and architecture roles, including substantial recent AWS architecture experience, typically seven years or more.
- Personal leadership of at least two enterprise AWS multi-account landing zone implementations from discovery and detailed design through build, workload onboarding and operational handover.
- At least one landing zone delivered in a regulated, government, financial services, health, insurance or similarly complex environment.
- Deep hands-on knowledge of AWS Organizations, AWS Control Tower, account vending, organisational unit design, service control policies and delegated administration.
- Strong Terraform and automation capability, including reusable modules, testing, Git-based delivery and CI/CD pipelines. The candidate must be able to review implementation quality, not only produce diagrams.
- Strong enterprise networking knowledge spanning hybrid connectivity, routing, DNS, IP address management, network security and traffic inspection.
- Strong cloud security architecture knowledge across identity, encryption, key management, central logging, threat detection, security monitoring, vulnerability management and audit evidence.
- Demonstrated ability to define platform operating models, technical standards, support boundaries, workload onboarding and FinOps controls.
- Excellent stakeholder leadership and communication skills, including the ability to explain complex architecture decisions and trade-offs to senior non-technical stakeholders.
Incase you would like to apply to this job directly from the source, please click here