Position: Cloud Engineer AWS & Automation
Job Type: Contract
Location: Remote
Level: Mid-Level
Job OverviewWe are seeking a skilled and proactive Cloud Engineer (AWS & Automation) with deep hands-on expertise in AWS Control Tower and multi-account environment governance. In this role, you will execute infrastructure and IAM backlog items, build self-service capabilities, and develop automated security and compliance remediation workflows. You will collaborate closely with engineering teams to manage, scale, and secure enterprise AWS environments using modern Infrastructure as Code (IaC) and pipeline automation.
Quick SummaryExperience: 3 5 years in Cloud Engineering (including 2+ years dedicated to AWS)
Education: Bachelor's degree in CS, IT, or a related field
Certifications: AWS Certified Solutions Architect Associate (Preferred)
Core Requirement:AWS Control Tower experience is MANDATORY.
Infrastructure & Backlog Execution: Deliver backlog items for cloud infrastructure, networking, and IAM following organizational best practices.
Multi-Account Governance: Provision, baseline, and customize accounts via Account Factory for Terraform (AFT) and author Service Control Policies (SCPs) across AWS Organizations.
Self-Service & Provisioning: Maintain and expand AWS Service Catalog portfolios and products to streamline developer self-service.
Security & Compliance Automation: Develop event-driven AWS Lambda automation (Python/Boto3) to enforce compliance and trigger auto-remediation workflows.
Documentation: Build and maintain clear technical architecture diagrams, operational runbooks, and deployment guides.
AWS Control Tower & Organizations: Setting up, governing, and managing multi-account AWS environments following AWS best practices.
Account Factory for Terraform (AFT): Hands-on experience working in existing AFT setups, writing/maintaining Terraform modules for account baselining, managing AFT repositories, and troubleshooting Step Functions/CodeBuild failures.
Service Control Policies (SCPs): Authoring and managing SCPs across AWS OUs (deny/allow lists, region/service restrictions, root lockdown, encryption enforcement) without production disruption.
Terraform: Proficient (2+ years) with modules, state management, and workspaces.
CloudFormation: Experience with StackSets, nested stacks, and custom resources.
AWS Service Catalog: Managing portfolios/products, implementing launch constraints, TagOptions, and sharing across accounts/OUs.
CI/CD & IaC Testing: Proficiency with GitHub Actions, GitLab CI, or AWS CodePipeline, alongside security scanners like Checkov, tfsec, or OPA/Rego.
Strong experience writing Python (Boto3) scripts for AWS Lambda.
Building auto-remediation workflows (detecting public S3 buckets, unused IAM keys, unencrypted resources, or missing tags).
Integration with EventBridge, AWS Config Rules, Security Hub, and AWS Step Functions.
Following serverless standards: dead-letter queues (DLQ), error handling, idempotency, and structured logging.
Networking: Solid understanding of VPC architecture, subnets, route tables, Internet/NAT Gateways, Transit Gateway connectivity, and multi-account Route 53 DNS resolution.
IAM & Security: Custom JSON policies, permission boundaries, cross-account role assumption, temporary credentials (STS), Security Groups, and NACLs.
Identity & SSO: Hands-on experience with SAML/OIDC integrations and AWS IAM Identity Center configuration.
Containerization: Experience with Amazon EKS / Kubernetes (IRSA, Pod Identity).
Compliance & Security: Knowledge of CIS Benchmarks, AWS Well-Architected Framework, or regulated environments (SOC 2, PCI-DSS, HIPAA, AWS GovCloud).
Cost Optimization: Awareness of FinOps principles and AWS cost governance techniques.