Haystack
← Back to Jobs
Other
AC

AWS Cloud Foundation Engineer (Control Tower, AWS Organizations, SCP, Governance)

ARMO ConsultantsCamden, NJ🇺🇸United StatesPosted 2 Sept 2026

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
Camden, NJ, United States
Posted
2 days ago
AWSComplianceGitHub ActionsTerraform

Job Description

We are seeking a hands-on AWS Cloud Platform Engineer to operate and improve an enterprise AWS landing zone. This position is focused on the platform layer: AWS Organizations, Control Tower, account provisioning, governance policies, identity, networking, security controls, and reusable infrastructure automation.
The right candidate has worked inside a complex, multi-account AWS environment and understands how to give development teams-controlled access to the cloud without weakening enterprise security or governance standards.
Best fit: An AWS Platform, Cloud Foundation, Landing Zone, or Cloud Governance Engineer who has supported a centralized AWS platform across multiple development teams.
Not a fit: Candidates whose AWS experience is primarily application deployment, migrations, basic resource provisioning, or pipeline-only DevOps work.
What You Will Own
  • AWS Organizations, organizational units, account structure, and account lifecycle
  • AWS Control Tower and automated account-provisioning processes
  • Service Control Policies, guardrails, tagging standards, and account compliance
  • Terraform-based cloud infrastructure and reusable platform components
  • GitHub Actions pipelines supporting AWS infrastructure deployments
  • IAM, IAM Identity Center, least-privilege access, and KMS controls
  • Enterprise AWS networking, including VPCs, Transit Gateway, PrivateLink, VPC endpoints, security groups, flow logs, AWS Network Firewall, and load balancers
  • Foundational AWS services such as S3, CloudWatch, and KMS
  • Platform monitoring, incident support, security remediation, and cost visibility
  • Reference architectures and approved cloud patterns that application teams can use safely
What We Need
  • 10+ years of hands-on AWS engineering experience
  • Strong production experience with AWS Organizations and AWS Control Tower
  • Direct experience designing or maintaining AWS multi-account governance
  • Hands-on implementation of Service Control Policies
  • Strong Terraform experience for AWS infrastructure provisioning
  • Experience maintaining GitHub Actions deployment pipelines
  • Solid knowledge of IAM, IAM Identity Center, role design, and least-privilege access
  • Strong AWS networking troubleshooting skills
  • Experience supporting security controls, monitoring, and remediation
  • Ability to troubleshoot platform, identity, networking, and deployment issues across AWS accounts
  • Clear technical documentation and the ability to work with application engineering teams
Strongly Preferred
  • Account Factory for Terraform, also known as AFT
  • AWS Config, Security Hub, and GuardDuty
  • FinOps or AWS cost-optimization experience
  • ECS exposure
  • Experience creating reusable AWS reference architectures
  • Experience operating a shared enterprise cloud platform used by multiple development teams

In-person Interview. No Relocation, only locals within commutable distance

Similar jobs