Principal AWS Enterprise Architect
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+2 more
Job description
Join a high-impact, remote-first team as a Principal AWS Enterprise Architect. You will architect and implement foundational AWS platforms that empower multiple application teams to build and scale securely. This hands-on role offers you the chance to lead the design and delivery of enterprise-scale AWS environments, directly shaping infrastructure, security, identity, networking, and compliance for a regulated, data-driven organization.
Responsibilities
- Design, implement, and document AWS foundation and landing zones, including account structures, organization units, and enforced guardrails
- Establish and automate identity management, integrating IAM Identity Center with corporate IdP (Okta) and enforcing least privilege access patterns
- Architect robust multi-account network topology using Transit Gateway, Direct Connect, Shared VPCs, and perimeter security (WAF, Network Firewall)
- Build security and compliance controls mapped to frameworks such as NIST CSF 2.0, ensuring PII protection, encryption, and centralized logging
- Deploy and govern AWS-hosted VDI solutions and regulated Databricks environments, including data platform governance and secure service integrations
- Implement cost governance strategies (budgets, tagging, FinOps cadence) and multi-region disaster recovery aligned with business objectives
- Lead architecture reviews, design workshops, and enable knowledge transfer to in-house teams for long-term platform ownership
- Create clear diagrams, reference architectures, Infrastructure-as-Code (Terraform preferred), and actionable documentation
Requirements
15+ years in enterprise infrastructure/cloud architecture; 7+ years hands-on with AWS at scale
- Proven experience designing and launching at least two AWS landing zones in production
- Deep expertise in AWS Organizations, Control Tower, IAM Identity Center, Transit Gateway, Direct Connect, KMS, WAF, GuardDuty, Security Hub, Config, CloudTrail, Macie, and Network Firewall
- Track record running Databricks on AWS in regulated/secure environments
- Experience architecting enterprise VDI solutions on AWS
- Strong knowledge of handling PII and implementing compliance controls (NIST CSF, SOC 2, HIPAA, or PCI)
- Expert-level Terraform skills; familiarity with CDK and CloudFormation
- Demonstrated ability to create high-quality reference architectures, ADRs, and technical documentation
- Excellent communication skills with both technical and executive audiences
Preferred Skills
- AWS Solutions Architect - Professional and AWS Security - Specialty certifications
- Experience supporting large-scale on-prem to AWS migrations
- Familiarity with API Gateway, EKS, ECS, and integrations (Okta, ServiceNow, Splunk, CrowdStrike)
- Background in Telecommunications or Service Provider industries
Benefits & conditions
100% remote work flexibility
- Lead mission-critical, high-visibility projects impacting enterprise cloud strategy
- Collaborate with top-tier engineers, security, and application teams
- Opportunity to build, document, and transfer ownership of a modern AWS platform
- Work with cutting-edge AWS and data technologies in a supportive, growth-oriented environment
About the company
on the table pick what makes sense* SCPs permission boundaries and a tagging policy that actually gets enforced* Baseline guardrails wired in from day one: CloudTrail Config GuardDuty security hub IAM Access Analyzer centralized log aggregation* Reference IaC - Terraform preferred CDK acceptable - that workload teams inherit when they get a new accountIdentity and access* Federation through IAM Identity Center integrated with our corporate IdP (Okta) A clear story for break-glass JIT elevation and what humans get vs what workloads get* Role and policy patterns workload teams can reuse without inventing their own Least privilege ABAC where it actually pays off permission boundaries* Secrets and KMS Key hierarchy rotation cross-account access - the boring stuff that has to be rightNetwork* Multi-account topology with Transit Gateway Shared VPCs through AWS RAM segmentation by environment and sensitivity and DNS (Route 53 Resolver private zones hybrid resolution)* Hybrid connectivity to the data center Direct Connect with a resilience model that matches our risk tolerance Direct Connect Gateway VPN as backup
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
What Are The Top Skills Required For Azure Developers?
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
From Prototype to Production: Build AI Agents with This Free 4-Course Learning Path
Top Must-Visit Developer Conferences in the US in 2026