Role: AWS Modernization Consultant
Location: Remote role
Duration: Long Term
Job description:
This Senior Consultant role modernizes legacy workloads into cloud-native, resilient and observable AWS platforms. The consultant is expected to operate as an embedded AWS SME, provide hands-on implementation support, and create audit-ready technical documentation aligned to regulated Financial Services delivery expectations.
Role Scope & Key Responsibilities (from Column W)
Multi-Account Governance (WS-2): Design AWS Organizations landing zone with OU structure, Service Control Policies (SCPs), centralized logging (CloudTrail, VPC Flow Logs, AWS Config), and automated account vending for Security Lab foundation
Isolated Recovery Environment (WS-3): Architect IRE account with WORM vault locking (S3 Object Lock/Backup Vault Lock), cross-account/cross-region backup (3-2-1 strategy), AWS KMS CMKs, CyberArk break-glass integration, Amazon Macie data classification, AWS Network Firewall, Transit Gateway route isolation, and recovery orchestration
Clean Room Forensics: Design forensic investigation environment with network isolation, immutable evidence storage, and controlled access patterns
Security Lab Infrastructure: Establish Amazon EKS baseline and lab environment for testing security capabilities, threat simulation, and vulnerability assessments
Compliance & Audit: Design AWS Backup Audit Manager compliance framework, Route 53 DNS isolation, and hardened compute baselines (AMI/container hardening)
Documentation & Implementation: Author IRE & Clean Room Architecture & Design Document, Security Lab Architecture Document, lab operations guide, and account vending admin procedures
Security Agent Infrastructure (WS-1): Design and support AWS Security Agent cloud infrastructure implementation
Secrets Management: Implement AWS Secrets Manager/Parameter Store integration with CyberArk for break-glass scenarios
Key Deliverables:
Multi-Account Landing Zone Architecture with OU/SCP design
IRE & Clean Room Architecture & Design Document
Security Lab Architecture Document
Backup Audit Manager compliance framework
Hardened compute baselines (AMIs, EKS node configurations)
Account vending automation and admin procedures
Recovery orchestration runbooks
AWS Skills & Services (added)
Governance & Multi-Account Architecture:
AWS Organizations: OU structure design, SCP policies, consolidated billing, cross-account IAM strategies
AWS Control Tower: Landing zone automation, guardrails, Account Factory customization
AWS Service Catalog: Automated account vending, standardized resource provisioning
AWS Resource Access Manager (RAM): Cross-account resource sharing for Transit Gateway, Route 53 Resolver
Security & Compliance:
AWS IAM: Advanced policies, permission boundaries, IRSA (IAM Roles for Service Accounts), cross-account roles, break-glass access patterns
AWS KMS: Customer Managed Keys (CMKs), key policies, cross-account/cross-region key grants, envelope encryption
AWS Secrets Manager: Secret rotation, CyberArk integration, cross-account secret access
Amazon Macie: Sensitive data discovery, S3 bucket classification, compliance reporting
AWS Security Hub: Centralized security findings, compliance standards (CIS, PCI-DSS)
AWS GuardDuty: Threat detection, malware protection, runtime monitoring
AWS Network Firewall: Stateful/stateless rules, intrusion prevention, domain filtering
AWS WAF: Web application protection, managed rule groups
Backup & Disaster Recovery:
AWS Backup: Centralized backup management, WORM vault locking (Vault Lock), cross-account/cross-region backup, 3-2-1 backup strategy
AWS Backup Audit Manager: Compliance framework design, backup policy enforcement, audit reporting
Amazon S3: Object Lock (WORM compliance), versioning, cross-region replication, Glacier Vault Lock
AWS Elastic Disaster Recovery (DRS): Continuous replication, recovery orchestration, failover testing
Logging & Monitoring:
AWS CloudTrail: Multi-account trail design, log file validation, S3/CloudWatch Logs integration, event history analysis
Amazon CloudWatch: Centralized logging, log aggregation, metric filters, alarms, dashboards
VPC Flow Logs: Network traffic analysis, security group validation, threat detection
AWS Config: Configuration compliance, resource inventory, change tracking, conformance packs
Networking & Isolation:
Amazon VPC: Advanced networking, security groups, NACLs, VPC peering, PrivateLink
AWS Transit Gateway: Hub-and-spoke architecture, route table isolation, network segmentation
Amazon Route 53: DNS isolation, private hosted zones, DNSSEC, resolver rules
AWS PrivateLink: Service endpoint isolation, cross-account connectivity without internet exposure
Container & Compute Security:
Amazon EKS: Cluster hardening, pod security policies/standards, IRSA, network policies, secrets encryption, runtime security
Amazon ECR: Image scanning, vulnerability assessment, immutable tags, lifecycle policies
AWS Systems Manager: Patch Manager, Session Manager (bastion replacement), Parameter Store, hardened AMI automation
Amazon EC2: Hardened AMI creation, IMDSv2 enforcement, instance metadata security, EBS encryption
Forensics & Incident Response:
Amazon Detective: Security investigation, graph-based analysis, threat hunting
AWS Step Functions: Recovery orchestration workflows, automated incident response
Amazon EventBridge: Event-driven security automation, cross-account event routing
AWS Lambda: Automated remediation, forensic data collection, snapshot automation
Infrastructure as Code & Automation:
AWS CloudFormation: StackSets for multi-account deployments, nested stacks, drift detection
AWS CDK: Programmatic infrastructure definition, construct libraries for security patterns
AWS Service Catalog: Self-service account vending, compliance-approved resource templates
Cost Optimization & Governance:
AWS Cost Explorer: Cost allocation tags, backup storage optimization
AWS Budgets: Cost alerts, anomaly detection
AWS Trusted Advisor: Security and cost optimization recommendations
Financial Services & Industry Skills (added)
Large regulated financial-services delivery with formal change-control, audit and risk governance
Operational resilience expectations including RTO/RPO, multi-region DR and evidence for audit review
Awareness of applicable controls and regulations such as DORA, NIST CSF 2.0, PCI DSS, SEC cyber rules, RegSCI and SIFMU/FMI expectations where relevant
Ability to create Tech Risk-ready documentation including ADRs, runbooks, design docs, threat models and validation evidence
Clear communication with client engineering, security, SRE, data and platform stakeholders as an embedded SME
Certifications / Qualifications
AWS Certified Solutions Architect - Associate / Professional
AWS Certified Developer - Associate
AWS Certified DevOps Engineer - Professional preferred
General Requirements
8+ years of relevant hands-on delivery experience at L6 scope
Prior delivery in a large regulated enterprise environment, preferably financial services
Ability to write architecture decision records, design documents, runbooks and test evidence for client Tech Risk review
Strong stakeholder communication across engineering, security, operations, SRE and delivery teams
Compliance with AWS ProServe and client onboarding, security, vetting and time-zone overlap requirements