Job Description
This is a remote position.
Job Title : AWS Cloud Infrastructure Architect
Location : Remote
Duration : Full-Time
Clearance : IRS MBI Required
We are seeking an experienced AWS Cloud Architect to design, implement, and manage our organization's cloud infrastructure on Amazon Web Services. This role will be responsible for establishing and maintaining our AWS environment, including account structure, networking, security, and governance frameworks.
Key Responsibilities
AWS Account & Organization Management
- Design and implement AWS account structure using AWS Organizations
- Create and manage Organizational Units (OUs) based on business requirements and best practices
- Establish account governance policies and standards
- Implement consolidated billing and cost allocation strategies
- Deploy and manage AWS Control Tower for automated account provisioning and governance
- Implement Landing Zone Architecture (LZA) for scalable, secure multi-account environments
Network Architecture & Connectivity
Design and deploy Virtual Private Clouds (VPCs) across multiple regionsConfigure and manage VPN connections (Site-to-Site VPN and Client VPN)Implement AWS Direct Connect for hybrid cloud connectivityDesign network segmentation strategies using subnets, route tables, and network ACLsConfigure Transit Gateway for multi-VPC connectivityManage DNS using Route 53Architect network solutions for AWS GovCloud environmentsIdentity & Access Management (IAM)
Design and implement IAM policies, roles, and permission boundariesEstablish identity federation with corporate identity providersImplement least privilege access principlesCreate and manage service control policies (SCPs) at the organization levelConfigure multi-factor authentication (MFA) requirementsDevelop IAM governance and compliance frameworksSecurity & Compliance
Design and implement security policies across the organizationConfigure AWS Security Hub, GuardDuty, and AWS ConfigImplement encryption strategies for data at rest and in transitEstablish security monitoring and incident response proceduresEnsure compliance with industry standards (SOC 2, ISO 27001, HIPAA, etc.)Maintain FedRAMP compliance requirements and controlsDesign and implement security architectures for AWS GovCloud (US) regionsConduct security assessments and vulnerability managementImplement AWS WAF and Shield for application protectionAdditional Responsibilities
Create infrastructure as code using AWS CloudFormation or TerraformDevelop and maintain architectural documentation and diagramsProvide technical guidance and mentorship to engineering teamsParticipate in disaster recovery planning and testingOptimize cloud costs and resource utilizationTechnical Skills
5+ years of experience in cloud architecture, with 3+ years specifically on AWSDeep understanding of AWS Organizations and multi-account strategiesHands-on experience with AWS Control Tower for account orchestration and governanceProficiency in Landing Zone Architecture (LZA) design and implementationExperience working with AWS GovCloud (US) environmentsKnowledge of FedRAMP compliance requirements, controls, and authorization processesExpert knowledge of AWS networking services (VPC, VPN, Direct Connect, Transit Gateway)Strong expertise in IAM, including policy design and identity federationProven experience implementing security best practices and compliance frameworksProficiency with infrastructure as code tools (CloudFormation, Terraform, CDK)Experience with AWS security services (Security Hub, GuardDuty, Config, CloudTrail)Certifications (Preferred)
AWS Certified Solutions Architect – ProfessionalAWS Certified Security – SpecialtyAWS Certified Advanced Networking - SpecialtyAdditional AWS certifications are a plusRequirements
AWS and govcloud and fedramp and formation and terraform and Control and Tower and IRS