Role overview/requirements
- Design and maintain secure, scalable, resilient, and highly available AWS cloud architectures.
- Define and implement Zero Trust architecture principles, including identity-centric access, least privilege, strong authentication, network segmentation, and continuous verification.
- Design and govern multi-account AWS environments, including account structures, organisational units, guardrails, Service Control Policies, security controls, and account provisioning.
- Automate infrastructure provisioning and configuration using Terraform and Infrastructure as Code best practices.
- Develop reusable Terraform modules, automation patterns, and deployment standards.
- Support and enhance enterprise landing zone capabilities, preferably using AWS Landing Zone Accelerator (LZA).
- Design AWS networking solutions including VPCs, Transit Gateway, Direct Connect, VPN, routing, DNS, firewalls, private connectivity, and network segmentation.
- Work with AWS Organizations, Control Tower, IAM, SCPs, security services, logging, and compliance controls.
- Integrate infrastructure automation with CI/CD pipelines and engineering delivery processes.
- Work closely with engineering teams to troubleshoot issues, solve technical problems, and turn architectural designs into working solutions.
- Take an active role in delivery and implementation, rather than operating solely at a high-level architecture or advisory level.
- Participate in technical design reviews, proof-of-concepts,solution validation, and platform improvements.
- Present architecture, technical designs, recommendations, and trade-offs clearly to both technical and non-technical stakeholders.
- Communicate complex technical concepts in a clear, practical, and outcome-focused manner.
- Review existing AWS environments and recommend improvements across security, resilience, performance, operability, and cost optimisation.
- Produce architecture documentation, standards, reference patterns, decision records, and technical roadmaps.
Seniority Level:
Not Specified