Required Skills: EC2, S3, RDS, Lambda, VPC, IAM, VPC, subnets, CloudWatch, CloudTrail, ELK stack, Docker, Kubernetes, EKS, ECS
Job Description
AWS Cloud Engineer to own, secure, and modernize our AWS infrastructure across numerous tenant accounts. You will lead the transition to an AWS Security Reference Architecture (SRA)-aligned, multi-account environment, harden our cloud security posture, and support enterprise security and compliance initiatives such as ISO 27001:2022. This is a hands-on, individual-contributor ownership role: you will be the technical authority for our AWS estate – designing, building, automating, and operating cloud infrastructure – while partnering with Systems Engineering, InfoSec, and IT to keep our environments secure, resilient, well-documented, and cost-effective.
Client is a global leader in digital asset compute that develops and deploys innovative technologies to build a more sustainable and inclusive future. Clients secures the world’s preeminent blockchain ledger and supports the energy transformation by converting clean, stranded, or otherwise underutilized energy into economic value.
ESSENTIAL DUTIES AND RESPONSIBILITIES :
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform essential functions. Other duties may be assigned.
AWS Infrastructure Ownership & Architecture
Own the design, deployment, and day-to-day operation of Client's AWS infrastructure across multiple tenant accounts.
Lead the transition to an AWS Security Reference Architecture (SRA)-aligned, multi-account environment using AWS Organizations, Control Tower, and a well-architected landing zone.
Define and enforce account, networking, and guardrail standards (organizational units, service control policies, and baseline configurations) across all tenants.
Serve as the technical authority and senior escalation point for AWS architecture, performance, and reliability issues.
Evaluate and modernize existing workloads, recommending improvements in scalability, resilience, automation, and cost efficiency.
Security & Compliance Harden the AWS security posture in line with the AWS SRA and industry best practices, including least-privilege IAM, encryption, centralized logging, and network segmentation.
Support enterprise security and compliance initiatives such as ISO 27001:2022 by implementing, operating, and evidencing the required controls within AWS.
Configure and manage AWS security services such as IAM Identity Center, GuardDuty, Security Hub, Config, CloudTrail, KMS, and WAF.
Partner with InfoSec on threat detection, vulnerability remediation, audit readiness, and incident response within the cloud environment.
Implement and monitor guardrails, detective controls, and automated remediation to maintain continuous compliance across tenants.
Automation & Modernization Build and maintain infrastructure as code (e.g., Terraform, CloudFormation, or AWS CDK) to provision and manage environments consistently and repeatably.
Develop and improve CI/CD pipelines and automation for infrastructure and deployments.
Automate operational tasks, patching, backups, and configuration management to reduce manual effort and risk.
Drive modernization efforts such as containerization (ECS/EKS), serverless adoption, and migration of legacy or unmanaged workloads where appropriate. Operations, Reliability & Cost Monitor, troubleshoot, and optimize the performance, availability, and reliability of AWS workloads.
Manage backup, disaster recovery, and business continuity for cloud-hosted systems.
Track and optimize AWS spend, providing cost visibility and recommendations to leadership.
Maintain thorough documentation of architecture, standards, runbooks, and operational procedures.
Collaborate with other IT Teams on hybrid connectivity, identity, and integration between cloud and on-premises environments.
QUALIFICATIONS:
5+ years of hands-on experience designing, building, and operating production AWS environments.
Current AWS Certified Security – Specialty certification (strongly preferred); Solutions Architect – Professional and/or SysOps Administrator certifications preferred.
Proven track record owning AWS infrastructure at scale, ideally across a multi-account or multi-tenant organization.
Hands-on experience with AWS Organizations, Control Tower, and building or operating an SRA-aligned or well-architected landing zone.
Strong experience with AWS security services (IAM Identity Center, GuardDuty, Security Hub, Config, CloudTrail, KMS, WAF) and least-privilege design.
Experience supporting compliance frameworks such as ISO 27001:2022, SOC 2, or similar, including implementing and evidencing controls.
Proficiency with infrastructure as code (Terraform, CloudFormation, or CDK) and CI/CD automation.
Strong scripting skills (e.g., Python, Bash, or PowerShell).
Solid understanding of cloud networking, encryption, and identity and access management.
Strong documentation and communication skills, with the ability to work effectively with both technical and non-technical stakeholders.
Critical Qualities:
Strong sense of ownership — accountable for the security, reliability, and quality of the AWS estate end to end.
Security-first mindset and sound judgment around risk, least privilege, and compliance.
Ability to balance modernization and automation with operational stability.
Clear thinking and composure during incidents and outages.
Proactive approach to hardening, monitoring, and continuous improvement.
Excellent documentation habits.
Strong organizational skills and attention to detail.
Effective collaboration across Systems Engineering, InfoSec, and IT.