We are looking for an experienced Cloud Engineer with deep expertise in AWS and strong hands‑on skills using Terraform to architect, deploy, and operate cloud environments at scale. This position will collaborate closely with the Cloud Center of Excellence (CCoE) to build secure, scalable, and cost‑efficient cloud platforms.
Key responsibilities
- Architect, deploy, and support AWS infrastructure using Infrastructure as Code (Terraform)
- Design, implement, and operate AWS Landing Zone solutions (AWS Control Tower or custom-built), including multi‑account AWS environments, automated account provisioning and environment separation (Production, UAT, Development), and standardized networking, security, and logging frameworks
- Create and maintain reusable Terraform modules while promoting IaC standards and best practices
- Administer and support core AWS services, including networking (VPCs, Transit Gateway, subnets, route tables), security & identity (IAM, IAM Identity Center (SSO), Service Control Policies (SCPs)), compute & integration (EC2, Auto Scaling, ALB/NLB, Lambda), and data services (S3, RDS, DynamoDB)
- Apply security controls and compliance measures aligned with AWS-recommended best practices
- Integrate Terraform workflows into CI/CD pipelines such as CodeCommit, CodeDeploy, and CodePipeline
- Monitor usage, optimize cloud costs, and improve performance and reliability
- Diagnose and resolve infrastructure issues while supporting live production systems
- Collaborate with business and technical teams to convert requirements into cloud architecture solutions
- Maintain clear documentation, architecture diagrams, and operational procedures
About you
- Extensive hands‑on experience operating AWS environments in production
- Demonstrated expertise using Terraform with AWS
- Practical experience implementing or managing AWS Landing Zones (Control Tower or custom)
- Strong knowledge of AWS governance models and security best practices
- Strong knowledge of IAM, SCPs, and least‑privilege access principles
- Strong knowledge of AWS networking concepts (Transit Gateway, CIDR, routing, NACLs, DNS)
- Experience managing infrastructure across multiple AWS accounts
- Understanding of cloud security frameworks and compliance standards
- Ability to work autonomously and take full ownership of cloud platforms
- Strong analytical and troubleshooting abilities, effective communication skills for both technical and non‑technical audiences, and proactive approach with a strong focus on security, stability, and reliability