Kuala Lumpur, Malaysia | Posted on 04/24/2026
Job Description: Senior AWSLanding Zone Architect/Engineer
Experience: 7 years (5 Years Minimum in AWS)
Role Overview
We are seeking a Senior AWS Landing ZoneArchitect/Engineer to lead the design and implementation of a greenfield,well-architected, and governed AWS platform. Your mission is to bridge the gapbetween technology, operations, and security by establishing a securefoundation for cloud workloads. This is a highly consultative and technicalrole, requiring you to transition from high-level discovery workshops tohands-on implementation of a non-production environment. You will beresponsible for ensuring that every architectural decision is justified,documented, and automated via a robust GitOps framework, setting the standardfor regional expansion into Malaysia, Indonesia, and Singapore.
- Stakeholder Facilitation: Lead discovery workshops todefine requirements for organization structure, account strategy, securitygovernance, and business alignment.
- Strategic Advisory: Advise on the AWS SharedResponsibility Model, security capabilities frameworks, and enterprise securityprinciples to support a successful cloud transformation.
- Architecture Design: Develop the Target StateArchitecture for the Landing Zone, specifically covering account strategy,multi-region networking, and shared services.
- Minimum Security Baseline(MSB): Definethe MSB covering identity and access management (IAM), detection, logging,monitoring, infrastructure security, data protection, and incident response.
- Decision Governance: Maintain a comprehensiveDecision Register, documenting and justifying architectural trade-offs acrosstechnology and operations.
- Documentation: Deliver high-fidelityarchitectural diagrams and translate designs into actionable technical epicsand user stories for implementation.
Key Responsibilities:Infrastructure & Network Implementation
- Core Platform Deployment: Implement AWS Control Tower andAWS Organizations, configuring a scalable Organizational Unit (OU) structureand core accounts (Management, Network, Shared Services).
- Hub-and-Spoke Networking: Design and implement acentralized hub-and-spoke network architecture usingAWS Transit Gateway and the AWS Network Orchestration for AWS Transit Gateway S olution.
- Traffic Inspection: Configure north-south andeast-west traffic inspection utilizingAWSNetwork FirewallandAWS Firewall Managerfor up to fivenon-production accounts.
- IP & DNS Management: Manage CIDR allocation viaAmazon VPC IP Address Manager (IPAM) and implement hybrid DNS solutions usingAmazon Route 53 outbound resolver rules.
- Service Connectivity: Establish centralized VPCendpoint strategies and baseline routing to enable secure egress, ingress, andinspection capabilities.
Key Responsibilities: Security,Governance, and Operations
- Advanced Policy Management: Define and implement up to five(5) Service Control Policies (SCPs), along with Resource Control Policies,Declarative policies , Amazon S3policies, and Tag policies.
- Identity & Access: Implement SAML federation forIAM Identity Center and manage up to fifteen (15) complex permission sets.
- Automated Guardrails: Enable and automate theauto-enrollment of security services-including Amazon GuardDuty, AWS SecurityHub, and Amazon Inspector for all new accounts.
- Operational Security: Implement a robust"break-glass" access solution for AWS Control Tower and defineoperational guardrails based on AWS best practices.
- Financial Governance: Develop CloudFormationtemplates for AWS Budgets to provide email alerts based on customer-definedthresholds for five non-production accounts.
Key Responsibilities: Automation& DevSecOps
- Account Vending: Automate account provisioningby implementing a Terraform-based Account Vending Machine (AVM).
- Module Development: Design and implement five (5)centralized, reusable Terraform modules for core services (Amazon EKS, EC2, S3,RDS, and Auto Scaling Groups).
- GitOps& CI/CD: Establish effective GitOpsworkflows, including repository structures, Gitbranching strategies for infrastructure versioningandCI/CD pipelines for module testing.
- Access Control: Define and implement granularaccess controls for infrastructure code to manage the boundary between System operations and application teams.
- Developer Enablement: Provide sample code andcomprehensive documentation to demonstrate the usage and maintenance of thecentralized module library.
Requirements
Required Technical Skills & Qualifications
Must-Have Core Skills
- Advanced IaC: Deep expertise in HashiCorpTerraform (module development, state management, and AVM).
- Orchestration & Networking: Proven experience with AWSControlTower, AWS Organizations, and the AWS Network Orchestration for TransitGateway solution.
- Security Governance: Hands-on experience with SCPs,Declarative policies, and IAM Identity Center (SAML).
- DevOps Pipelines: Strong command of GitOps, CI/CDpipeline construction, and version control branching strategies.
Technical Domain Knowledge
- AWS Security Services: Security Hub, GuardDuty,Inspector, and Network Firewall.
- AWS Management Tools: IPAM, Firewall Manager, AWS Budgets,and Route 53 Resolver.
- Architecture Frameworks: Thorough understanding of theAWS Well-Architected Framework and the Shared Responsibility Model.
Nice-to-Have Skills
- AWS Certified Solutions Architect- Professional or AWS Certified Security - Specialty.
- Experience in multi-regiondeployments specifically involving Indonesia and Singapore data residencyrequirements.
- Knowledge of Amazon EKSinfrastructure base lining.