Haystack
← Back to Jobs
Other
AC

AWS Cloud Foundation Engineer (Control Tower, AWS Organizations, SCP, Governance)

ARMO ConsultantsCamden, NJ🇺🇸United StatesPosted Sep 17, 2026

Why This Role Stands Out

This role offers a fantastic opportunity to shape and enhance an enterprise AWS landing zone, deepening your expertise in core cloud foundation services and governance. You'll thrive here if you have proven experience managing complex, multi-account AWS environments and a passion for enabling development teams with secure, controlled access. Apply now to make a significant impact on a leading cloud platform!

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
Camden, NJ, United States
Posted
2 weeks ago
AWSComplianceGitHub ActionsTerraform

Job Description

We are seeking a hands-on AWS Cloud Platform Engineer to operate and improve an enterprise AWS landing zone. This position is focused on the platform layer: AWS Organizations, Control Tower, account provisioning, governance policies, identity, networking, security controls, and reusable infrastructure automation.
The right candidate has worked inside a complex, multi-account AWS environment and understands how to give development teams-controlled access to the cloud without weakening enterprise security or governance standards.
Best fit: An AWS Platform, Cloud Foundation, Landing Zone, or Cloud Governance Engineer who has supported a centralized AWS platform across multiple development teams.
Not a fit: Candidates whose AWS experience is primarily application deployment, migrations, basic resource provisioning, or pipeline-only DevOps work.
What You Will Own
  • AWS Organizations, organizational units, account structure, and account lifecycle
  • AWS Control Tower and automated account-provisioning processes
  • Service Control Policies, guardrails, tagging standards, and account compliance
  • Terraform-based cloud infrastructure and reusable platform components
  • GitHub Actions pipelines supporting AWS infrastructure deployments
  • IAM, IAM Identity Center, least-privilege access, and KMS controls
  • Enterprise AWS networking, including VPCs, Transit Gateway, PrivateLink, VPC endpoints, security groups, flow logs, AWS Network Firewall, and load balancers
  • Foundational AWS services such as S3, CloudWatch, and KMS
  • Platform monitoring, incident support, security remediation, and cost visibility
  • Reference architectures and approved cloud patterns that application teams can use safely
What We Need
  • 10+ years of hands-on AWS engineering experience
  • Strong production experience with AWS Organizations and AWS Control Tower
  • Direct experience designing or maintaining AWS multi-account governance
  • Hands-on implementation of Service Control Policies
  • Strong Terraform experience for AWS infrastructure provisioning
  • Experience maintaining GitHub Actions deployment pipelines
  • Solid knowledge of IAM, IAM Identity Center, role design, and least-privilege access
  • Strong AWS networking troubleshooting skills
  • Experience supporting security controls, monitoring, and remediation
  • Ability to troubleshoot platform, identity, networking, and deployment issues across AWS accounts
  • Clear technical documentation and the ability to work with application engineering teams
Strongly Preferred
  • Account Factory for Terraform, also known as AFT
  • AWS Config, Security Hub, and GuardDuty
  • FinOps or AWS cost-optimization experience
  • ECS exposure
  • Experience creating reusable AWS reference architectures
  • Experience operating a shared enterprise cloud platform used by multiple development teams

In-person Interview. No Relocation, only locals within commutable distance

Similar jobs