AWS Lead with Control Tower and Landing Zone and Cloud Formation(Remote)

LTM

$150K — $180K *
US-AnywhereRemote in New York, NY
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience with AWS Control Tower and Landing Zone concepts
  • Strong understanding of AWS Identity and Access Management (IAM) and Microsoft Entra ID integration
  • Experience in Infrastructure as Code (IaC) using Terraform and GitOps practices
  • Familiarity with configuring AWS services like S3, EC2, and networking components
  • Knowledge of security best practices in cloud environments, including SCP guardrails

Responsibilities

  • Provision multi-account AWS landing zone using AWS Control Tower
  • Apply SCP guardrails and configure AWS Config conformance packs
  • Establish secure node baseline with Bottlerocket and admission control
  • Build and operate Terraform modules and GitLab CI/CD pipelines
  • Activate AWS Outposts and validate configurations post-delivery
  • Configure networking components like Transit Gateway and Route 53
  • Produce detailed runbooks for handover and support operational knowledge transfer

Benefits

  • Remote work flexibility
  • Opportunities for skill development in advanced AWS technologies
  • Collaboration with a team of cloud experts
  • Engagement in innovative cloud infrastructure projects
  • Potential for career advancement in cloud engineering roles
Full Job Description
Role description

AWS Lead with Control Tower and Landing Zone and Cloud Formation

Remote

Landing zone build Provision the multi account AWS landing zone Non Production and Production via AWS Control Tower and Account Factory AFT with clean separation of the customers IT and network domains.

Guardrails identity Apply SCP guardrails and AWS Config conformance packs configure centralized logging and federate IAM Identity Center to the customer IdP Microsoft Entra ID with no local human IAM users.

Secure node baseline Establish immutable Bottlerocket node OS with signedimage admission control and pertenant virtualcluster isolation boundaries.

IaC pipeline Build Terraform Enterprise modules Region Local Zone persite with Sentinel policyascode gates and operate GitLab CI/CD Argo CD Flux GitOps with Cosign signing and SBOM gating.

Edge Outpost activation Perform Outpost postconnection activation after AWS Service Team install and capacity confirmation validate delivered capacity carve GPU CPU instance pools configure S3 on Outposts and EB Son Outposts storage classes and ACErack aggregation per site.

Network build Configure the Transit Gateway hub dual Direct Connect Route 53 ACM VPCsubnet design with pertenant isolation security groups NACLs RAM Local Gateway routing to the customer 5G RANCore and dualstack IPv4IPv6 with CNI CalicoCilium microsegmentation.

Fleet automation testing Implement repeatable persite provisioning and fleetrollout automation then support network cutover system integration and GPUinference performance testing per site.

Asbuilt handover Produce asbuilt landing zone network and Outpost activation runbooks plus persite activation records and support knowledge transfer to the operating team.

Similar Jobs

More Jobs at LTM

More Information Technology Jobs

Find similar AWS Lead with Control Tower and Landing Zone and Cloud Formation(Remote) jobs: