Delivery Tech Lead (DTL) – AWS Landing Zone & Cloud Governance

Avenue Code

Brasil

Presencial

BRL 240 000 - 360 000

Tempo integral

Há 4 dias
Torna-te num dos primeiros candidatos
Gerador de candidaturas

Não envies um currículo genérico — gera um currículo e uma carta de apresentação adaptados a esta função específica.

Ultrapassa os filtros ATS

Resumo da oferta

Avenue Code is seeking an experienced Delivery Tech Lead to steer the design, governance, and implementation of enterprise AWS Landing Zones. You will act as the technical authority for cloud platform delivery, partnering with executives and cross-functional teams to establish secure, scalable multi-account environments that enable large-scale cloud adoption.

You will focus on platform architecture, governance, security, identity, networking, automation, and operational readiness, rather than

Qualificações

  • Extensive experience designing and delivering enterprise AWS Landing Zones.
  • Deep expertise in AWS Control Tower, AWS Organizations, and SCPs.
  • Strong experience with cloud security, compliance, hybrid networking, DNS, and identity federation.
  • Hands-on with Infrastructure as Code and automated deployment pipelines.
  • Experience building secure AWS foundations for enterprise migrations.
  • Proven consulting and executive stakeholder management.
  • Ability to lead multidisciplinary teams across security, networking, and compliance.
  • Excellent written and verbal English communication.
  • Familiarity with AWS Well-Architected Framework.
  • AWS CSA – Associate certification.

Responsabilidades

  • Own end-to-end architecture and delivery of enterprise AWS Landing Zone engagements.
  • Define OU structure, account hierarchy, delegated admin, and governance models.
  • Design and govern Control Tower environments, including upgrades and drift remediation.
  • Establish SCPs and guardrails aligned with compliance requirements.
  • Define account provisioning, baselining, and lifecycle automation frameworks.
  • Create scalable patterns for shared services, security, logging, networking, testing, and production environments.
  • Ensure landing zones are ready for workload onboarding at scale.
  • Lead architecture discussions with executive stakeholders and cloud platform teams.
  • Drive secure, compliant, and auditable platform capabilities across the enterprise.

Conhecimentos

Landing Zones
AWS Control Tower
AWS Organizations
SCPs
IAM Identity Center
Multi-Account
Governance
Cloud Security
Compliance
Hybrid Networking
DNS
Identity Federation
Logging
Monitoring
Infrastructure as Code
Automation Pipelines
AWS Foundations
Stakeholder Management
Team Leadership
Communication
Well-Architected Framework
AWS CSA – Associate

Formação académica

AWS Certified Solutions Architect – Associate

Ferramentas

Terraform
AWS CDK
CloudFormation
AWS Config
AWS Security Hub
Amazon GuardDuty
Amazon Inspector
AWS Firewall Manager
AWS Backup
AWS Service Catalog
CodeBuild
RAM
KMS
ECS
EKS
Lambda

Descrição da oferta de emprego

We are seeking an experienced Delivery Tech Lead (DTL) to lead the design, governance, and implementation of enterprise-scale AWS Landing Zones. This is a senior customer-facing leadership role responsible for defining secure, scalable, compliant, and operationally ready AWS multi-account environments that enable cloud adoption and large-scale migration initiatives.

As the technical authority for AWS platform delivery, you will work closely with executive stakeholders, cloud platform teams, security organizations, networking teams, identity teams, and application owners to establish the foundational AWS architecture that supports enterprise workloads across multiple business units and environments.

This position is primarily focused on cloud platform architecture, governance, security, identity, networking, operational readiness, and automation, rather than application development.

Responsibilities
  • Own the end-to-end architecture and technical delivery of enterprise AWS Landing Zone engagements.
  • Define AWS Organizations strategy, Organizational Unit (OU) structure, account hierarchy, delegated administration, and governance models.
  • Design and govern AWS Control Tower environments, including customization, lifecycle management, upgrades, and drift remediation.
  • Establish Service Control Policies (SCPs), organizational guardrails, and governance controls aligned with business and compliance requirements.
  • Define account vending, account baselining, and lifecycle automation frameworks.
  • Create scalable patterns for shared services, security, logging, networking, sandbox, development, testing, and production environments.
  • Ensure landing zones are fully prepared to support workload onboarding and migration activities at scale.
Identity & Access Management
  • Define enterprise identity federation and Single Sign-On (SSO) strategies.
  • Design AWS IAM Identity Center permission models, role mappings, and least-privilege access patterns.
  • Guide integrations with Active Directory, SAML, OIDC, AWS Directory Service, and other enterprise identity providers.
  • Establish privileged access, break-glass access, and access governance models.
  • Ensure identity and security controls are implemented as foundational platform capabilities.
Networking & Connectivity
  • Lead AWS network foundation architecture, including:Amazon VPC AWS Transit Gateway AWS Direct Connect VPN Connectivity AWS Resource Access Manager (RAM)
  • Define enterprise IP addressing, CIDR allocation, segmentation, and routing strategies.
  • Architect hybrid DNS solutions using Amazon Route 53 Resolver and private hosted zones.
  • Partner with networking teams to establish secure connectivity between AWS and on-premises environments.
Security, Compliance & Governance
  • Define enterprise cloud security baselines and governance frameworks.
  • Establish centralized logging, monitoring, compliance, and threat detection capabilities.
  • Lead implementation and adoption of:AWS CloudTrail AWS Config AWS Security Hub Amazon GuardDuty Amazon CloudWatch Amazon Inspector AWS Firewall Manager
  • Define KMS key management and encryption strategies.
  • Map customer regulatory requirements to AWS controls and services.
  • Support frameworks such as CIS, SOC 2, PCI-DSS, HIPAA, FedRAMP, NERC CIP, and similar compliance standards.
Infrastructure as Code & Automation
  • Define Infrastructure as Code (IaC) standards and deployment strategies.
  • Lead Landing Zone Accelerator (LZA) implementations.
  • Drive automation using CloudFormation, AWS CDK, Terraform, and StackSets.
  • Establish CI/CD, GitOps, change control, drift management, and deployment governance practices.
  • Ensure platform changes are repeatable, auditable, secure, and well-governed.
Operational Excellence & FinOps
  • Define backup, retention, disaster recovery, and cross-account protection strategies.
  • Establish enterprise tagging standards and cost allocation models.
  • Enable centralized monitoring, observability, and operational governance.
  • Support FinOps foundations through budgeting, reporting, cost visibility, and accountability frameworks.
  • Define operational ownership, support boundaries, and escalation processes.
Customer & Delivery Leadership
  • Serve as the primary technical advisor for customer cloud platform engagements.
  • Lead architecture discussions with CTOs, CISOs, Enterprise Architects, Security Leaders, and Cloud Platform stakeholders.
  • Communicate security, compliance, operational, and architectural trade-offs to both technical and business audiences.
  • Drive architecture governance and strategic technical decision-making.
  • Manage cross-functional dependencies across security, networking, identity, compliance, migration, and application teams.
  • Lead RAID management, risk mitigation, status reporting, and escalation activities.
  • Contribute to Statements of Work (SOW), effort estimation, delivery planning, assumptions, and scope management.
Required Qualifications
  • Extensive experience designing and delivering enterprise AWS Landing Zones.
  • Deep expertise with:AWS Control Tower AWS Organizations Service Control Policies (SCPs) AWS IAM Identity Center Multi-Account AWS Governance
  • Strong experience with cloud security, compliance, hybrid networking, DNS, identity federation, logging, and monitoring.
  • Proven background implementing platform solutions through Infrastructure as Code and automated deployment pipelines.
  • Experience designing secure and scalable AWS foundations supporting enterprise migration programs.
  • Strong consulting and executive stakeholder management experience.
  • Experience leading multidisciplinary teams across security, networking, cloud infrastructure, identity, operations, and compliance.
  • Excellent written and verbal communication skills in English.
  • Working knowledge of the AWS Well-Architected Framework.
  • AWS Certified Solutions Architect – Associate
Nice To Have Skills
Technical Skills
  • Landing Zone Accelerator on AWS (LZA)
  • Terraform
  • AWS CDK
  • AWS CloudFormation
  • AWS Config
  • AWS Security Hub
  • Amazon GuardDuty
  • Amazon Inspector
  • AWS Firewall Manager
  • AWS Backup
  • AWS Service Catalog
  • AWS CodeBuild
  • AWS Resource Access Manager (RAM)
  • AWS KMS
  • Amazon ECS
  • Amazon EKS
  • AWS Lambda
  • Cross-account observability and monitoring
  • Disaster Recovery and Business Continuity Planning
  • FinOps and Cloud Cost Governance
Preferred Certifications
  • AWS Certified Solutions Architect – Professional
  • AWS Certified Security – Specialty
  • AWS Certified Advanced Networking – Specialty
  • AWS Certified SysOps Administrator – Associate
  • HashiCorp Terraform Associate
  • CISSP
  • CCSP
  • TOGAF
  • PMP
  • PRINCE2
  • Agile Certifications
Ideal Candidate Profile
  • Proven expertise in AWS Control Tower, AWS Organizations, SCP design, IAM Identity Center, and Landing Zone governance.
  • Strong understanding of cloud security, compliance, networking, identity federation, and operational excellence.
  • Ability to influence executive stakeholders and lead complex cloud transformation initiatives.
  • Experience working within regulated and highly governed enterprise environments.
Obtém a tua avaliação gratuita e confidencial do currículo.

ou arrasta e larga o ficheiro aqui.

Similar jobs

Ofertas semelhantes que vale a pena comparar

Cloud Infrastructure Engineer
Cloud Infrastructure Engineer

Platform Science, Inc. • Londrina

Presencial
BRL 180 000 - 300 000
Cloud Architect
Cloud Architect

Espire Infolabs (Singapore) Pte Ltd • Região Norte

Híbrido
BRL 180 000 - 320 000
Cloud Infrastructure Architect
Cloud Infrastructure Architect

Avenue Code • Brasil

Presencial
BRL 611 000 - 917 000
Delivery Consultant - Cloud Security, Professional Services, Professional Services
Delivery Consultant - Cloud Security, Professional Services, Professional Services

Amazon • São Paulo

Presencial
BRL 180 000 - 300 000
Disability accommodations
Solutions Architect
Solutions Architect

Avenue Code • Brasil

Teletrabalho
BRL 300 000 - 540 000
Delivery Consultant - Cloud Security, Professional Services, Professional Services (AWS)
Delivery Consultant - Cloud Security, Professional Services, Professional Services (AWS)

Amazon • São Paulo

Presencial
BRL 120 000 - 210 000
Senior Cloud Infrastructure Engineer
Senior Cloud Infrastructure Engineer

Platform Science • Brasil

Presencial
BRL 280 000 - 420 000
Cloud Infrastructure Engineer
Cloud Infrastructure Engineer

Platform Science • Brasil

Presencial
BRL 180 000 - 360 000
Cloud Architect
Cloud Architect

ITMC Systems, Inc • Brasil

Presencial
BRL 350 000 - 700 000
AWS Cloud Infrastructure Architect with IRS MBI Clearance
AWS Cloud Infrastructure Architect with IRS MBI Clearance

Jobgether • Brasil

Teletrabalho
BRL 772 000 - 875 000
Fully remote
Full-time employment
High compensation