Senior AWS DevOps Engineer

Remote • Posted 3 hours ago • Updated 3 hours ago
Contract Independent
Contract Corp To Corp
Contract W2
4 Months
No Travel Required
Remote
Depends on Experience
Fitment

Dice Job Match Score™

👾 Reticulating splines...

Job Details

Skills

  • AWS Control Tower
  • AWS Organizations
  • Terraform
  • CloudFormation
  • Account Factory

Summary

We are seeking a Senior AWS DevOps / Platform Engineer to design, automate, and operate secure self-service AWS platform capabilities for development teams. This role will own the foundation for governed multi-account provisioning, federated access, reusable Infrastructure as Code templates, and Git-based promotion workflows that move validated workloads across controlled environments. The ideal candidate has hands-on experience with AWS Control Tower, AWS Organizations, deep Terraform and CloudFormation-based IaC implementation, identity federation, service control policies, CI/CD automation, centralized logging, and cost governance in large-scale engineering environments. 

Role Summary

This role is responsible for building governed AWS platform capabilities that allow application and engineering teams to request, receive, use, and retire secure cloud accounts and environments with minimal manual cloud-engineering involvement. The engineer will combine AWS Control Tower, AWS Organizations, Account Factory for Terraform or an equivalent account-vending workflow, federated identity, SCP-based guardrails, reusable IaC modules, and automated delivery pipelines to create a scalable platform service.

  • The role requires a platform-engineering mindset focused on automation, standardization, developer enablement, security, cost control, and operational governance.

Key Responsibilities

  • Design, build, and operate organizational units and account-vending automation so standard cloud environment requests can be fulfilled without manual cloud-engineering work.
  • Implement organization-level guardrails, including SCPs that block unacceptable actions, enforce region restrictions, and enable required logging and security services by default during account creation.
  • Build and enforce per-account cost controls, including budgets, actual and forecasted spend alerts, and automated remediation paths such as notification, access restriction, quarantine, and cleanup.
  • Ensure each account or environment is isolated by account, organizational unit, and network boundary from controlled environments and corporate networks, with no default transitive trust.
  • Partner with the identity team to design federated access patterns and short-lived role assumption models that eliminate the need for long-lived IAM users.
  • Own and maintain the Terraform, CloudFormation, and CDK module/template library that developers use for EKS, databases, queues, serverless services, and other common application patterns.

Required Qualifications

  • Hands-on experience with AWS Control Tower, AWS Organizations, and multi-account landing zone design.
  • Deep hands-on experience implementing Infrastructure as Code using Terraform and AWS CloudFormation, including reusable modules/templates, parameterization, versioning, validation, state management, and promotion through CI/CD pipelines.
  • Experience with federated identity using SSO, SAML, or OIDC, and short-lived credential models such as IAM Identity Center and STS role assumption.
  • Working knowledge of SCPs and AWS guardrail design, with the ability to restrict high-risk actions while preserving developer velocity.
  • Experience with EKS, RDS or Aurora, Redshift, SQS, SNS, serverless services, or similar managed AWS services at a level needed to build safe self-service templates.
  • CI/CD pipeline experience supporting Git-based review and promotion workflows across development, staging, production, and other controlled environments.
  • Familiarity with AWS cost management tooling such as Budgets and Cost Explorer, including spend-based alerting and automated remediation patterns.
  • Familiarity with CloudTrail, AWS Config, Security Hub, or equivalent centralized logging, security, and audit tooling.

 

 

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10191472
  • Position Id: 9033022
  • Posted 3 hours ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Remote

13d ago

Easy Apply

Contract, Third Party

Depends on Experience

Remote

13d ago

Easy Apply

Contract

50

Remote or Rockville, Maryland

Today

Full-time

USD 98,000.00 - 163,000.00 per year

Remote

Today

Easy Apply

Contract

Depends on Experience

Search all similar jobs