Cloud Foundations Engineer - Account & Landing Zone (human)

Neura Robotics GmbH
Metzingen, Germany
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Languages
German
Job source

Tech stack

Amazon Web Services Cloud Computing Cloud Computing Security Identity and Access Management Cloud Platform System Amazon Virtual Private Cloud (VPC) Opsworks

Job description

  • You are responsible for NEURA’s AWS account management, Control Tower setup, and landing zone architecture.
  • You work closely with engineering teams, security, and leadership to ensure that the cloud foundation scales with the business - without becoming a bottleneck.
  • You design the guardrails, but you design them to enable, not to restrict.
  • Designing, implementing, and evolving NEURA’s AWS landing zone - including Control Tower, Account Factory, organizational units, and account vending pipelines.
  • Owning the IAM and SSO architecture: permission sets, role hierarchies, and a structured, self-service-oriented access request workflow that keeps teams unblocked.
  • Partnering with fast-growing engineering teams to onboard new accounts, new environments, and new use cases quickly - your default answer is “here’s how we do it”, not “that’s not possible yet.”
  • Establishing and enforcing tagging policies, budget alerts, and cost visibility across all accounts, giving teams clear ownership of their cloud spend.
  • Implementing cloud security controls that protect without paralyzing: SCPs, AWS Config Rules, GuardDuty, Security Hub, etc. - designed with the principle that security enables velocity, not the other way around.
  • Acting as interface between Cloud Platform and the Security team, translating policy requirements into concrete, automated cloud controls.
  • Everything as Infrastructure as Code. No manual changes in production ever.

Requirements

Do you have experience in Identity & access management?, * 5+ years of experience in cloud infrastructure or platform engineering, with significant hands-on AWS experience in a fast-growing company environment.

  • Deep practical experience with AWS Control Tower, Organizations, Account Factory, and multi-account landing zone design - you have built this before, not just read about it.
  • Strong Infrastructure as Code skills, IaC is your default tool, not an afterthought.
  • Solid understanding of AWS IAM, SSO/Identity Center, and permission boundary design at organizational scale.
  • Experience designing and implementing cloud security controls (SCPs, Config Rules, GuardDuty, Security Hub, VPC security) with a clear philosophy: security that enables teams, not security that blocks them.
  • A proven solution-oriented mindset: you find creative, pragmatic paths forward.
  • Comfort working at pace in a scaling organization - you can handle ambiguity, incomplete requirements, and shifting priorities without losing quality.
  • Strong English communication skills; ability to explain complex access and governance topics clearly to non-specialists. German is a plus.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:49 min

Container hosting options available on Amazon Web Services

Federico Fregosi · WWC 2022

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo · WWC 2024

2:14 min

Solving complex platform architecture challenges at an enterprise scale

Maria Apazoglou · Coffee With Developers

2:51 min

Alibaba Cloud developer resources and cloud computing training

Cheng Zhang · LIVE

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

2:57 min

Scaling distributed processing through measurement-based quantum computing

Alexander Pirker · WWC 2023

Videos

See all

Related articles

See all