Cloud Foundations Engineer - Account & Landing Zone (Mensch)

Neura Robotics GmbH
Metzingen, Germany
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Languages
English, German
Job source

Tech stack

Microsoft Access Amazon Web Services Cloud Computing Cloud Computing Security Identity and Access Management Cloud Platform System Amazon Virtual Private Cloud (VPC)

Job description

  • Du verantwortest NEURAs AWS-Account-Management, das Control-Tower-Setup und die Landing-Zone-Architektur. Dabei arbeitest du eng mit Engineering, Security und dem Leadership zusammen, damit die Cloud-Basis mit dem Unternehmen skaliert - ohne zum Flaschenhals zu werden.
  • Du baust Guardrails, aber so, dass sie ermĂśglichen, nicht einschränken.
  • Design, Implementierung und Weiterentwicklung der AWS Landing Zone - inkl. Control Tower, Account Factory, OUs und Account-Vending-Pipelines.
  • Ownership der IAM- und SSO-Architektur: Permission Sets, Rollen-Hierarchien und ein klar strukturierter, Self-Service-orientierter Access-Workflow, der Teams nicht blockiert.
  • Enge Zusammenarbeit mit schnell wachsenden Engineering-Teams, um neue Accounts, Umgebungen und Use Cases schnell zu onboarden - deine Standardantwort ist: “So machen wir das”, nicht “geht noch nicht”.
  • Aufbau und Durchsetzung von Tagging-Policies, Budget-Alerts und Kosten-Transparenz Ăźber alle Accounts hinweg, damit Teams echte Ownership fĂźr ihre Cloud-Kosten haben.
  • Implementierung von Cloud-Security-Controls (SCPs, Config Rules, GuardDuty, Security Hub usw.), die schĂźtzen ohne zu lähmen - nach dem Motto: Security ermĂśglicht Geschwindigkeit.
  • Schnittstelle zwischen Cloud Platform und Security: du Ăźbersetzt Policies in konkrete, automatisierte Cloud-Kontrollen.
  • Alles als Infrastructure as Code - keine manuellen Änderungen in Produktion.

Requirements

  • 5+ Jahre Erfahrung in Cloud-Infrastruktur oder Platform Engineering, idealerweise mit viel Hands-on-AWS in einem schnell skalierenden Umfeld.
  • Tiefe praktische Erfahrung mit AWS Control Tower, Organizations, Account Factory und Multi-Account-Landing-Zones - du hast das schon gebaut, nicht nur darĂźber gelesen.
  • Sehr starke IaC-Skills - Infrastructure as Code ist fĂźr dich Standard, nicht Beiwerk.
  • Fundiertes Know-how in AWS IAM, SSO / Identity Center und Permission-Boundary-Design auf Organisationsebene.
  • Erfahrung mit Cloud-Security-Controls (SCPs, Config Rules, GuardDuty, Security Hub, VPC-Security) - mit dem Mindset: Security soll Teams befähigen, nicht blockieren.
  • Ein klar lĂśsungsorientierter, pragmatischer Ansatz.
  • Du fĂźhlst dich wohl in einer schnell wachsenden Organisation, kannst mit Unklarheiten umgehen und lieferst trotzdem Qualität.
  • Sehr gute Englischkenntnisse; Fähigkeit, komplexe Themen verständlich zu erklären. Deutsch ist ein Plus.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:49 min

Container hosting options available on Amazon Web Services

Federico Fregosi ¡ WWC 2022

3:24 min

Testing applications with Microsoft accessibility insights tool

Dennie Declercq ¡ LIVE

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo ¡ WWC 2024

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder ¡ LIVE

4:42 min

Triggering local execution with environment variables

Markus MÜller ¡ WWC 2021

1:44 min

Career transition into cloud native and data management

Michael Cade ¡ LIVE

Videos

See all

Related articles

See all