AWS Architect

Compunnel, Inc.

Fort Lauderdale (FL)

On-site

USD 140,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Compunnel, Inc. is looking for a Principal AWS Enterprise Architect to establish scalable cloud foundations and implement AWS architecture for enterprise application teams. This role involves designing landing zones, implementing governance, and enforcing security standards in the cloud environment.

The ideal candidate will have over 15 years of experience in cloud architecture, expertise in AWS services, and a strong background in Infrastructure as Code. This position is integral to enhancing internal engineering practices and ensuring compliance with best practices.

Qualifications

  • 15+ years in enterprise infrastructure and cloud architecture.
  • 7+ years with enterprise-scale AWS environments.
  • Experience with AWS Landing Zones.

Responsibilities

  • Design and implement AWS Organizations and landing zone architecture.
  • Develop reusable Infrastructure as Code (IaC) modules using Terraform.
  • Implement perimeter security with AWS WAF and Shield Advanced.

Skills

AWS Organizations
Infrastructure as Code (IaC)
Terraform
Cloud security
Hybrid cloud connectivity
AWS KMS
Databricks
Compliance frameworks

Education

Bachelor's degree in Computer Science or related field

Tools

AWS
Terraform
Databricks
CloudTrail

Job description

We are seeking a Principal AWS Enterprise Architect to design and implement the AWS foundation that enterprise application teams will build upon. This is a hands‑on architecture role focused on AWS landing zones, identity, networking, security, governance, Databricks, VDI, and Infrastructure as Code (IaC). The ideal candidate will establish scalable cloud foundations, enforce security and compliance standards, and enable internal engineering teams with reusable patterns and best practices.

Key Responsibilities
  • Design and implement AWS Organizations, Organizational Units (OUs), account structures, and landing zone architecture.
  • Define account models for workload, security, networking, shared services, sandbox, and log archive environments.
  • Establish Service Control Policies (SCPs), permission boundaries, and enterprise tagging standards.
  • Implement foundational AWS guardrails including CloudTrail, AWS Config, GuardDuty, Security Hub, IAM Access Analyzer, and centralized logging.
  • Develop reusable Infrastructure as Code (IaC) modules using Terraform to accelerate workload onboarding.
  • Configure AWS IAM Identity Center integrated with the corporate Identity Provider (IdP).
  • Design reusable IAM roles, policies, permission boundaries, and least‑privilege access models.
  • Implement enterprise key management strategies using AWS KMS, including key hierarchy, rotation, and cross‑account access.
  • Design multi‑account networking using Transit Gateway, Shared VPCs, AWS RAM, Route 53 Resolver, and hybrid DNS.
  • Architect hybrid connectivity using AWS Direct Connect, VPN backup, Direct Connect Gateway, and resilient routing strategies.
  • Design secure ingress and egress architectures using CloudFront, API Gateway, ALB/NLB, NAT Gateway, VPC Endpoints, and PrivateLink.
  • Implement perimeter security using AWS WAF, Shield Advanced, and AWS Network Firewall.
  • Develop AWS security reference architectures aligned with NIST CSF 2.0 and other compliance frameworks.
  • Implement enterprise PII protection strategies including encryption, data classification, masking, tokenization, and Amazon Macie.
  • Design centralized logging, monitoring, incident response, and forensic readiness capabilities.
  • Architect secure Databricks deployments on AWS, including customer‑managed VPCs, Unity Catalog, PrivateLink, IAM integration, and governance.
  • Design and justify enterprise Virtual Desktop Infrastructure (VDI) solutions using AWS WorkSpaces, AppStream, or equivalent platforms.
  • Define secure integration patterns between Databricks, S3, RDS, Redshift, and on‑premises systems.
  • Design multi‑region disaster recovery architectures aligned with business RTO and RPO requirements.
  • Implement cloud governance including budgets, cost optimization, tagging enforcement, Savings Plans, Reserved Instances, and FinOps practices.
  • Establish architecture governance processes, Architecture Decision Records (ADRs), and architecture review standards.
  • Lead architecture workshops with infrastructure, networking, security, application, and data teams.
  • Mentor engineering teams and facilitate knowledge transfer to support long‑term ownership.
Required Qualifications
  • Overall 15+ years of professional experience in enterprise infrastructure and cloud architecture.
  • At least 7 years of hands‑on experience designing and supporting enterprise‑scale AWS environments.
  • Experience architecting and implementing at least two production AWS Landing Zones.
  • Strong expertise with AWS Organizations, Control Tower, IAM Identity Center, Transit Gateway, Direct Connect, Shared VPCs, AWS RAM, KMS, CloudTrail, AWS Config, GuardDuty, Security Hub, IAM Access Analyzer, Macie, AWS WAF, Shield Advanced, and AWS Network Firewall.
  • Strong experience designing enterprise AWS landing zones, account governance, and cloud security architectures.
  • Hands‑on experience implementing Infrastructure as Code using Terraform.
  • Experience designing secure hybrid cloud connectivity using Direct Connect, VPN, and enterprise networking.
  • Experience designing enterprise identity and access management solutions using IAM Identity Center and corporate identity providers.
  • Experience implementing enterprise encryption, secrets management, and AWS KMS key strategies.
  • Experience deploying and governing Databricks on AWS within regulated environments.
  • Experience handling PII and regulated data in enterprise cloud environments.
  • Ability to translate compliance frameworks such as NIST CSF, SOC 2, HIPAA, PCI, or FedRAMP into AWS security implementations.
  • Experience creating reference architectures, Architecture Decision Records (ADRs), and technical standards.
  • Strong analytical, leadership, communication, stakeholder management, and documentation skills.
Preferred Qualifications
  • AWS Certified Security – Specialty.
  • Experience supporting large‑scale on‑premises to AWS cloud migrations.
  • Experience with API Gateway, Amazon EKS, and Amazon ECS.
  • Experience integrating AWS environments with Okta, Microsoft Entra ID, ServiceNow, Splunk, Sentinel, CrowdStrike, Wiz, CyberArk, or similar enterprise platforms.
  • Experience in Telecommunications, Service Provider, or similarly regulated industries.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AWS Architect
AWS Architect

TechDigital Group • Raritan (NJ)

On-site
USD 130,000 - 160,000
AWS Cloud Architect
AWS Cloud Architect

Ravh-IT • Irvine (CA)

On-site
USD 180,000 - 250,000
AWS Cloud Platform Architect
AWS Cloud Platform Architect

System One • McLean (VA)

On-site
USD 130,000 - 160,000
AWS Architect
AWS Architect

TechDigital Group • Englewood (CO)

On-site
USD 120,000 - 160,000
Associate Director, Lead Cloud Architect
Associate Director, Lead Cloud Architect

Jobtailor • California (MO)

On-site
USD 150,000 - 210,000
Senior Solutions Architect, WWPS ISV
Senior Solutions Architect, WWPS ISV

Amazon • Arlington (VA)

On-site
USD 150,000 - 210,000
AWS Architect
AWS Architect

Socket.dev • Reston (VA)

Hybrid
USD 140,000 - 210,000
AWS Infrastructure Engineer
AWS Infrastructure Engineer

ISITE TECHNOLOGIES • Austin (TX)

On-site
USD 140,000 - 190,000
Senior AWS Cloud Architect
Senior AWS Cloud Architect

cginfinity • Washington

On-site
USD 120,000 - 150,000
Competitive salary and performance incentives
Professional growth and cloud certification support
Collaborative culture with cutting-edge technologies
AWS Architect
AWS Architect

EXL • New Jersey

On-site
USD 140,000 - 190,000