Haystack
← Back to Jobs
Remote
Technology

Cloud Engineer - AWS Control Tower, Account Factory for Terraform (AFT) - Remote - W2 Contract - Only 5-6 years of experience candidate

Intellisoft TechnologiesUnited States🇺🇸United StatesPosted 21 Jul 2026

Quick Overview

Work Type
Remote
Level
Mid Senior

Job Description

Cloud Engineer AWS & Automation

Remote

Contract W2

we are looking for a hands-on AWS Cloud Engineer with strong experience in AWS Control Tower, Account Factory for Terraform (AFT), Terraform, IAM, Service Catalog, and AWS automation. The ideal candidate should have experience managing multi-account AWS environments, provisioning accounts through Control Tower/AFT, developing Lambda automation (Python/Boto3), and implementing IAM, SCPs, and CI/CD. Experience with AWS Organizations, Identity Center (SSO), CloudFormation, and AWS networking is required.

Must Have

  • AWS Control Tower
  • Account Factory for Terraform (AFT)
  • Terraform (2+ years)
  • AWS Organizations & SCPs
  • IAM / Identity Center / SSO
  • Lambda (Python/Boto3)
  • AWS Service Catalog
  • CloudFormation
  • CI/CD (GitHub Actions, CodePipeline, GitLab)
  • AWS Networking (VPC, TGW, Route53)

Nice to Have

  • EKS/Kubernetes
  • GovCloud
  • CIS Benchmarks
  • AWS Well-Architected Framework
  • FinOps

Technical Requirements

AWS Networking

  • General understanding of VPC architecture, subnets, route tables, and internet/NAT gateways
  • Familiarity with Transit Gateway connectivity and multi-account networking patterns
  • Understanding of NACLs and Security Groups and how they interact at different layers
  • Experience with DNS resolution (Route 53) in multi-account environments

IAM & Identity Management

  • IAM policy authoring (JSON), permission boundaries, and cross-account role assumption
  • Understanding of how IAM policies, SCPs, and permission boundaries interact and evaluate
  • Experience with federated access patterns and temporary credentials (STS)

SSO Technologies

  • Prior experience with SSO technologies (SAML, OIDC)
  • Familiarity with AWS IAM Identity Center configuration and assignment
  • Understanding of external IdP integration patterns

Service Control Policies (SCPs)

  • Author and manage SCPs across AWS Organizations (deny-list/allow-list strategies)
  • Implement region restrictions, service restrictions, root lockdown, and encryption enforcement
  • Understand SCP inheritance, limitations, and testing without production disruption

Account Factory for Terraform (AFT)

  • Work within existing AFT setup for automated account provisioning
  • Write and maintain Terraform modules for account baselining and customizations
  • Manage AFT repositories (account-request, global-customizations, account-customizations)
  • Integrate AFT with CI/CD pipelines and troubleshoot Step Functions/CodeBuild failures

AWS Service Catalog

  • Manage and maintain Service Catalog portfolios and products (CloudFormation/Terraform-based)
  • Implement self-service provisioning with launch constraints and TagOptions
  • Share portfolios across accounts/OUs and integrate with ITSM tools (ServiceNow)
  • Maintain standardized products (EC2, RDS, VPC, S3 templates)

Lambda Automation

  • Develop Lambda functions (Python/Boto3) for event-driven infrastructure automation
  • Build auto-remediation workflows (public S3, unused IAM keys, unencrypted resources, tagging)
  • Integrate Lambda with EventBridge, Config Rules, and SecurityHub
  • Implement Step Functions for multi-step orchestration workflows
  • Follow best practices: error handling, DLQ, idempotency, structured logging

General Automation & IaC

  • Terraform Proficient (modules, state management, workspaces) 2+ years
  • CloudFormation StackSets, nested stacks, custom resources
  • CI/CD CodePipeline, GitHub Actions, or GitLab CI
  • Testing Checkov, tfsec, OPA/Rego

Key Responsibilities

  • Execute backlog items for infrastructure and IAM work per existing standards
  • Maintain and extend Service Catalog portfolios for self-service provisioning
  • Develop Lambda-based automation for security remediation and compliance enforcement
  • Provision and baseline new accounts via existing AFT/Terraform patterns
  • Contribute to documentation and runbooks for implemented solutions

Preferred / Nice-to-Have

  • EKS/Kubernetes familiarity (IRSA/Pod Identity)
  • AWS GovCloud or regulated industry experience (SOC2, PCI-DSS, HIPAA)
  • CIS Benchmarks, AWS Well-Architected Framework knowledge
  • FinOps practices and cost optimization awareness

Skills

AWS
Encryption
SAML
SSO
CloudFormation
DNS
GitHub Actions
GitLab CI
HIPAA
Kubernetes
Python
Terraform

Similar jobs