We are seeking an exceptional Senior Cloud Engineer with deep expertise in AWS Control Tower to join our CloudOps team. This role is critical to designing, implementing, and managing our multi-account AWS environment using Control Tower and related AWS governance services. As a Control Tower specialist, you will architect and maintain our AWS Landing Zone, ensure compliance and security across all accounts, and build automation frameworks that enable teams to leverage our cloud infrastructure effectively. You will continuously improve our systems, adopt the latest AWS technologies, and work in full collaboration with DevOps, Platform, DevSecOps, FinOps, and SRE teams to deliver cutting-edge infrastructure and platform solutions. Join us if you seek an opportunity to work with enterprise-scale AWS architectures, cutting-edge cloud governance technologies, and want to be part of a strong team.
About:
Our client is developing electro-mechanical devices for dairy farms, pulsators and automatic detachers. The solution is leading in the industry with advanced cow monitoring solutions based on activity and rumination sensors.
Responsibilities:
- Design, implement, and manage AWS Control Tower multi-account environments with AWS Organizations, OUs, and account structures;
- Deploy and maintain Account Factory for Terraform (AFT) for automated account provisioning and IaC-based organizational customizations;
- Implement Customizations for Control Tower (CfCT) for Config Rules and Service Control Policy (SCP) management;
- Manage AWS IAM Identity Center (SSO), PermissionSets, and role-based access control across accounts;
- Manage Innovation Sandbox environments with API-driven automation for temporary account provisioning and lifecycle management;
- Collaborate with DevSecOps to implement AWS Config, Security Hub, GuardDuty, and Inspector;
- Design detective and preventive security guardrails;
- Develop and enforce SCPs across the organization;
- Automate compliance reporting and remediation workflows;
- Advanced AWS Networking (Critical Requirement):
- Design and implement network architectures within the Control Tower ecosystem using Transit Gateway, VPC Endpoints, and VPC Links;
- Configure Route53 for DNS management (private hosted zones) and Route53 Resolver Rules for hybrid DNS resolution;
- Implement ALB, NLB, and Gateway Load Balancer (GWLB) for inline traffic inspection and third-party appliance integration;
- Manage SSL/TLS certificates using ACM and certificate distribution strategies;
- Design network routing, subnet strategies, and CIDR planning using AWS IPAM; manage IPAM pools and scopes across multi-account environments;
- Implement network security (Security Groups, NACLs, network firewall) and troubleshoot networking issues across multi-account environments;
- Develop and maintain infrastructure using Terraform (professional-level): reusable modules, state management, AFT integration for account baselines;
- Implement infrastructure CI/CD pipelines using GitOps principles;
- Leverage AI-assisted development tools (Claude, GPT, Copilot) within IDEs to enhance productivity and code quality;
- Write Python/Bash for AWS automation, custom Lambda functions for Control Tower lifecycle events, and automated remediation solutions;
- Work in full collaboration with DevOps, Platform, DevSecOps, FinOps, and SRE teams to deliver integrated cloud solutions;
- Partner with cross-functional teams (security, application teams, architects) and support multiple projects simultaneously;
- Perform POCs, deliver technical presentations, and mentor team members on AWS best practices and Control Tower patterns;
- Document architectures, runbooks, and operational procedures Operations & Optimization;
- Monitor and maintain cloud infrastructure health, performance, and cost optimization across multi-account environments;
- Implement monitoring, alerting, and compliance solutions; perform routine maintenance, updates, and security patches;
- Conduct security assessments, manage incident response, and lead post-incident.
Requirements:
- Minimum 5+ years of experience in Cloud, DevOps Engineering, or related fields;
- AWS Control Tower: Hands-on experience designing and managing Control Tower environments;
- AWS Control Tower AFT (Account Factory for Terraform): Experience implementing and managing AFT workflows for account provisioning and IaCbased organizational customizations;
- AWS Organizations: Deep understanding of multi-account strategies, OUs, and organizational policies;
- AWS IAM Identity Center (SSO): Experience managing PermissionSets and multi-account access strategies;
- AWS Security Services: Professional experience with SCPs, AWS Config, Security Hub, GuardDuty, and Inspector;
- Terraform: Expert-level proficiency (MUST) — complex modules, state management, and best practices;
- AWS Networking: Comprehensive knowledge (MUST) — VPC design, Transit Gateway, VPC Endpoints/Links, Route53, Resolver Rules, ALB/NLB/GWLB, ACM/PKI, AWS IPAM, network routing and troubleshooting;
- Team Player: Excellent interpersonal skills, collaborative mindset, and ability to work across CloudOps, DevOps, Platform, DevSecOps, FinOps, and SRE teams;
- Strong understanding of AWS Landing Zone architectures;
- Experience with AWS CloudFormation and StackSets;
- Proficiency in Python, Bash, or other scripting languages;
- Ability to implement security and compliance requirements provided by DevSecOps (CIS, PCI-DSS, GDPR, etc.);
- Experience with version control (Git) and CI/CD practices Highly Desirable Skills (Big Advantages);
- AWS Control Tower CfCT (Customizations for Control Tower): Experience with CfCT deployment for Config Rules and SCP management;
- Innovation Sandbox Management: Experience with API-driven sandbox account automation, lifecycle management, and temporary environment provisioning;
- AWS Image Factory / EC2 Image Builder: Experience with automated AMI and Docker image creation, management, and distribution across Control Tower accounts;
- Experience with AWS Systems Manager for fleet management;
- Knowledge of AWS Backup and disaster recovery strategies;
- Experience with AWS CloudTrail log analysis and security forensics;
- Familiarity with AWS Audit Manager Additional;
- At least Upper-Intermediate English level.
Would be a plus:
- AI-Assisted Development: Demonstrates proficiency using LLM-based tools (Claude, GPT, GitHub Copilot) within IDEs (Cursor, VSCode, etc.) for infrastructure code, automation, and documentation;
- API Gateway: Experience with API Gateway architectures (REST, HTTP, WebSocket APIs) and Private API implementations;
- ZScaler: Experience with ZScaler Cloud Connector and App Connector, Zero Trust Network Access (ZTNA) management, integration with Route53, Route53 Resolver Rules, and Gateway Load Balancer for secure internet and application access;
- Experience with GitOps workflows using ArgoCD or Flux;
- Knowledge of Crossplane for Kubernetes-based infrastructure management;
- Experience with containerization and container image management (Docker, ECS, EKS);
- Container image automation.
We offer:
Professional Development: Free English courses, free access to the corporate Udemy account, corporate digital library subscription, possibility to participate and share your knowledge as a speaker in our internal meetups.
Benefits: 100% paid vacation and sick leaves, opportunity to accumulate part of the own salary in the company in dollar terms.