AWS Lead with Control Tower and Landing Zone and Cloud Formation(Remote)

LTM

$150K — $180K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in AWS cloud architecture and management.
  • Proficient in AWS Control Tower and Account Factory integration.
  • Experience with Infrastructure as Code (IaC) using Terraform and GitOps practices.
  • Strong understanding of security best practices for cloud environments.
  • Familiarity with networking concepts, including Transit Gateway and dual-stack IP addressing.

Responsibilities

  • Lead the provisioning of AWS multi-account landing zones using Control Tower.
  • Apply and manage AWS service control policies (SCPs) and compliance configurations.
  • Establish secure baseline environments using Bottlerocket OS and admission control.
  • Develop and manage Infrastructure as Code (IaC) pipelines in Terraform and GitLab.
  • Activate and configure AWS Outposts, ensuring proper resource allocation and setup.
  • Design and implement network solutions with proper security and routing configurations.
  • Document and provide training on as-built network and Outpost activation processes.

Benefits

  • Flexible remote working arrangement.
  • Opportunities for continuous learning and professional development.
  • Access to advanced cloud technologies and tools.
  • Collaborative work environment with a focus on innovation.
  • Support for knowledge transfer and team integration.
Full Job Description
Role description

AWS Lead with Control Tower and Landing Zone and Cloud Formation

Remote

Landing zone build Provision the multi account AWS landing zone Non Production and Production via AWS Control Tower and Account Factory AFT with clean separation of the customers IT and network domains.

Guardrails identity Apply SCP guardrails and AWS Config conformance packs configure centralized logging and federate IAM Identity Center to the customer IdP Microsoft Entra ID with no local human IAM users.

Secure node baseline Establish immutable Bottlerocket node OS with signedimage admission control and pertenant virtualcluster isolation boundaries.

IaC pipeline Build Terraform Enterprise modules Region Local Zone persite with Sentinel policyascode gates and operate GitLab CI/CD Argo CD Flux GitOps with Cosign signing and SBOM gating.

Edge Outpost activation Perform Outpost postconnection activation after AWS Service Team install and capacity confirmation validate delivered capacity carve GPU CPU instance pools configure S3 on Outposts and EB Son Outposts storage classes and ACErack aggregation per site.

Network build Configure the Transit Gateway hub dual Direct Connect Route 53 ACM VPCsubnet design with pertenant isolation security groups NACLs RAM Local Gateway routing to the customer 5G RANCore and dualstack IPv4IPv6 with CNI CalicoCilium microsegmentation.

Fleet automation testing Implement repeatable persite provisioning and fleetrollout automation then support network cutover system integration and GPUinference performance testing per site.

Asbuilt handover Produce asbuilt landing zone network and Outpost activation runbooks plus persite activation records and support knowledge transfer to the operating team.

Similar Jobs

More Jobs at LTM

More Information Technology Jobs

Find similar AWS Lead with Control Tower and Landing Zone and Cloud Formation(Remote) jobs: