Delivery Tech Lead (DTL) – AWS Landing Zone & Cloud Governance
Sobre a oportunidade
We are seeking an experienced Delivery Tech Lead (DTL) to lead the design, governance, and implementation of enterprise-scale AWS Landing Zones. This is a senior customer-facing leadership role responsible for defining secure, scalable, compliant, and operationally ready AWS multi-account environments that enable cloud adoption and large-scale migration initiatives.
As the technical authority for AWS platform delivery, you will work closely with executive stakeholders, cloud platform teams, security organizations, networking teams, identity teams, and application owners to establish the foundational AWS architecture that supports enterprise workloads across multiple business units and environments.
This position is primarily focused on cloud platform architecture, governance, security, identity, networking, operational readiness, and automation, rather than application development.
Responsabilidades
AWS Landing Zone Architecture
AWS Landing Zone Architecture
- Own the end-to-end architecture and technical delivery of enterprise AWS Landing Zone engagements.
- Define AWS Organizations strategy, Organizational Unit (OU) structure, account hierarchy, delegated administration, and governance models.
- Design and govern AWS Control Tower environments, including customization, lifecycle management, upgrades, and drift remediation.
- Establish Service Control Policies (SCPs), organizational guardrails, and governance controls aligned with business and compliance requirements.
- Define account vending, account baselining, and lifecycle automation frameworks.
- Create scalable patterns for shared services, security, logging, networking, sandbox, development, testing, and production environments.
- Ensure landing zones are fully prepared to support workload onboarding and migration activities at scale.
Identity & Access Management
- Define enterprise identity federation and Single Sign-On (SSO) strategies.
- Design AWS IAM Identity Center permission models, role mappings, and least-privilege access patterns.
- Guide integrations with Active Directory, SAML, OIDC, AWS Directory Service, and other enterprise identity providers.
- Establish privileged access, break-glass access, and access governance models.
- Ensure identity and security controls are implemented as foundational platform capabilities.
Networking & Connectivity
- Lead AWS network foundation architecture, including:Amazon VPC
AWS Transit Gateway
AWS Direct Connect
VPN Connectivity
AWS Resource Access Manager (RAM) - Define enterprise IP addressing, CIDR allocation, segmentation, and routing strategies.
- Architect hybrid DNS solutions using Amazon Route 53 Resolver and private hosted zones.
- Partner with networking teams to establish secure connectivity between AWS and on-premises environments.
Security, Compliance & Governance
- Define enterprise cloud security baselines and governance frameworks.
- Establish centralized logging, monitoring, compliance, and threat detection capabilities.
- Lead implementation and adoption of:AWS CloudTrail
AWS Config
AWS Security Hub
Amazon GuardDuty
Amazon CloudWatch
Amazon Inspector
AWS Firewall Manager - Define KMS key management and encryption strategies.
- Map customer regulatory requirements to AWS controls and services.
- Support frameworks such as CIS, SOC 2, PCI-DSS, HIPAA, FedRAMP, NERC CIP, and similar compliance standards.
Infrastructure as Code & Automation
- Define Infrastructure as Code (IaC) standards and deployment strategies.
- Lead Landing Zone Accelerator (LZA) implementations.
- Drive automation using CloudFormation, AWS CDK, Terraform, and StackSets.
- Establish CI/CD, GitOps, change control, drift management, and deployment governance practices.
- Ensure platform changes are repeatable, auditable, secure, and well-governed.
Operational Excellence & FinOps
- Define backup, retention, disaster recovery, and cross-account protection strategies.
- Establish enterprise tagging standards and cost allocation models.
- Enable centralized monitoring, observability, and operational governance.
- Support FinOps foundations through budgeting, reporting, cost visibility, and accountability frameworks.
- Define operational ownership, support boundaries, and escalation processes.
Customer & Delivery Leadership
- Serve as the primary technical advisor for customer cloud platform engagements.
- Lead architecture discussions with CTOs, CISOs, Enterprise Architects, Security Leaders, and Cloud Platform stakeholders.
- Communicate security, compliance, operational, and architectural trade-offs to both technical and business audiences.
- Drive architecture governance and strategic technical decision-making.
- Manage cross-functional dependencies across security, networking, identity, compliance, migration, and application teams.
- Lead RAID management, risk mitigation, status reporting, and escalation activities.
- Contribute to Statements of Work (SOW), effort estimation, delivery planning, assumptions, and scope management.
Habilidades obrigatórias
- Extensive experience designing and delivering enterprise AWS Landing Zones.
- Deep expertise with:AWS Control Tower
AWS Organizations
Service Control Policies (SCPs)
AWS IAM Identity Center
Multi-Account AWS Governance - Strong experience with cloud security, compliance, hybrid networking, DNS, identity federation, logging, and monitoring.
- Proven background implementing platform solutions through Infrastructure as Code and automated deployment pipelines.
- Experience designing secure and scalable AWS foundations supporting enterprise migration programs.
- Strong consulting and executive stakeholder management experience.
- Experience leading multidisciplinary teams across security, networking, cloud infrastructure, identity, operations, and compliance.
- Excellent written and verbal communication skills in English.
- Working knowledge of the AWS Well-Architected Framework.
- AWS Certified Solutions Architect – Associate
Habilidades desejáveis
Technical Skills
- Landing Zone Accelerator on AWS (LZA)
- Terraform
- AWS CDK
- AWS CloudFormation
- AWS Config
- AWS Security Hub
- Amazon GuardDuty
- Amazon Inspector
- AWS Firewall Manager
- AWS Backup
- AWS Service Catalog
- AWS CodePipeline
- AWS CodeBuild
- Route 53 Resolver
- AWS Resource Access Manager (RAM)
- AWS KMS
- Amazon ECS
- Amazon EKS
- AWS Lambda
- Cross-account observability and monitoring
- Disaster Recovery and Business Continuity Planning
- FinOps and Cloud Cost Governance
Preferred Certifications
- AWS Certified Solutions Architect – Professional
- AWS Certified Security – Specialty
- AWS Certified Advanced Networking – Specialty
- AWS Certified DevOps Engineer – Professional
- AWS Certified SysOps Administrator – Associate
- HashiCorp Terraform Associate
- CISSP
- CCSP
- TOGAF
- PMP
- PRINCE2
- Agile Certifications
Ideal Candidate Profile
- Hands-on experience owning enterprise-scale AWS platform architecture decisions.
- Proven expertise in AWS Control Tower, AWS Organizations, SCP design, IAM Identity Center, and Landing Zone governance.
- Strong understanding of cloud security, compliance, networking, identity federation, and operational excellence.
- Ability to influence executive stakeholders and lead complex cloud transformation initiatives.
- Experience working within regulated and highly governed enterprise environments.