Cloud Engineer - AWS Control Tower, Account Factory for Terraform (AFT) - Remote - W2 Contract - Only 5-6 years of experience candidate
Quick Overview
Job Description
Cloud Engineer AWS & Automation
Remote
Contract W2
we are looking for a hands-on AWS Cloud Engineer with strong experience in AWS Control Tower, Account Factory for Terraform (AFT), Terraform, IAM, Service Catalog, and AWS automation. The ideal candidate should have experience managing multi-account AWS environments, provisioning accounts through Control Tower/AFT, developing Lambda automation (Python/Boto3), and implementing IAM, SCPs, and CI/CD. Experience with AWS Organizations, Identity Center (SSO), CloudFormation, and AWS networking is required.
Must Have
- AWS Control Tower
- Account Factory for Terraform (AFT)
- Terraform (2+ years)
- AWS Organizations & SCPs
- IAM / Identity Center / SSO
- Lambda (Python/Boto3)
- AWS Service Catalog
- CloudFormation
- CI/CD (GitHub Actions, CodePipeline, GitLab)
- AWS Networking (VPC, TGW, Route53)
Nice to Have
- EKS/Kubernetes
- GovCloud
- CIS Benchmarks
- AWS Well-Architected Framework
- FinOps
Technical Requirements
AWS Networking
- General understanding of VPC architecture, subnets, route tables, and internet/NAT gateways
- Familiarity with Transit Gateway connectivity and multi-account networking patterns
- Understanding of NACLs and Security Groups and how they interact at different layers
- Experience with DNS resolution (Route 53) in multi-account environments
IAM & Identity Management
- IAM policy authoring (JSON), permission boundaries, and cross-account role assumption
- Understanding of how IAM policies, SCPs, and permission boundaries interact and evaluate
- Experience with federated access patterns and temporary credentials (STS)
SSO Technologies
- Prior experience with SSO technologies (SAML, OIDC)
- Familiarity with AWS IAM Identity Center configuration and assignment
- Understanding of external IdP integration patterns
Service Control Policies (SCPs)
- Author and manage SCPs across AWS Organizations (deny-list/allow-list strategies)
- Implement region restrictions, service restrictions, root lockdown, and encryption enforcement
- Understand SCP inheritance, limitations, and testing without production disruption
Account Factory for Terraform (AFT)
- Work within existing AFT setup for automated account provisioning
- Write and maintain Terraform modules for account baselining and customizations
- Manage AFT repositories (account-request, global-customizations, account-customizations)
- Integrate AFT with CI/CD pipelines and troubleshoot Step Functions/CodeBuild failures
AWS Service Catalog
- Manage and maintain Service Catalog portfolios and products (CloudFormation/Terraform-based)
- Implement self-service provisioning with launch constraints and TagOptions
- Share portfolios across accounts/OUs and integrate with ITSM tools (ServiceNow)
- Maintain standardized products (EC2, RDS, VPC, S3 templates)
Lambda Automation
- Develop Lambda functions (Python/Boto3) for event-driven infrastructure automation
- Build auto-remediation workflows (public S3, unused IAM keys, unencrypted resources, tagging)
- Integrate Lambda with EventBridge, Config Rules, and SecurityHub
- Implement Step Functions for multi-step orchestration workflows
- Follow best practices: error handling, DLQ, idempotency, structured logging
General Automation & IaC
- Terraform Proficient (modules, state management, workspaces) 2+ years
- CloudFormation StackSets, nested stacks, custom resources
- CI/CD CodePipeline, GitHub Actions, or GitLab CI
- Testing Checkov, tfsec, OPA/Rego
Key Responsibilities
- Execute backlog items for infrastructure and IAM work per existing standards
- Maintain and extend Service Catalog portfolios for self-service provisioning
- Develop Lambda-based automation for security remediation and compliance enforcement
- Provision and baseline new accounts via existing AFT/Terraform patterns
- Contribute to documentation and runbooks for implemented solutions
Preferred / Nice-to-Have
- EKS/Kubernetes familiarity (IRSA/Pod Identity)
- AWS GovCloud or regulated industry experience (SOC2, PCI-DSS, HIPAA)
- CIS Benchmarks, AWS Well-Architected Framework knowledge
- FinOps practices and cost optimization awareness
Skills
Similar jobs
AWS Cloud Automation and Administration Engineer
Stellent IT LLC · Reston, United States
7 minutes agoAzure Cloud Engineer
PY DATA, INC. · Warren, United States
27 minutes agoGoogle Cloud Platform Python Terraform Engineer
Millennium Software, Inc. · San Francisco, United States
28 minutes agoStaff Cloud Engineer
Tandym Tech · Tempe, United States
46 minutes agoOnsite interview - Senior Developer - Cloud Architectures & Public Cloud
Zealogics · New York, United States
48 minutes agoData Security / Cloud Engineer
SAI Systems Intl., Inc. · United States
1 hour ago