Senior AWS Platform Engineer (Control Tower Specialist)

1 Month ago • 5 Years + • Devops • $270,400 PA - $312,000 PA

Job Summary

Job Description

Tech Holding is seeking a Sr. AWS Platform Engineer with a specialization in Control Tower. The role involves leading the implementation and modernization of multi-account governance within AWS. Responsibilities include designing and implementing the AWS Control Tower Landing Zone for over 40 accounts, evaluating strategies for retrofitting or creating new organizations with risk/cost analysis, and configuring Account Factory for Terraform (AFT) and Customizations for Control Tower (CfCT) pipelines for automated account provisioning. The engineer will also establish shared accounts with baseline configurations, develop reusable infrastructure components using Infrastructure as Code (IaC) with Terraform, implement automated tagging, budget alerts, and security baseline enforcement, and create version-controlled IaC repositories with CI/CD integration. Governance responsibilities include designing and implementing Service Control Policies (SCPs) and guardrails, configuring AWS Config, CloudTrail, and centralized logging, establishing drift detection and remediation processes, and creating a guardrail exception registry. The role also entails leading account enrollment and migration into Control Tower governance, reconciling existing IAM roles and policies, optimizing the organizational unit structure, and developing account onboarding automation and documentation.
Must have:
  • 5+ years of AWS cloud architecture experience
  • Expertise in AWS Control Tower, Organizations, and Landing Zones
  • Proficiency in Infrastructure as Code (Terraform)
  • Experience with AFT and CfCT pipelines
  • Understanding of AWS security services (IAM, Config, CloudTrail, SCPs)
  • Experience with multi-account governance best practices
  • Strong scripting skills (Python, Bash, PowerShell)
  • Experience with CI/CD pipelines and GitOps
Good to have:
  • AWS Solutions Architect Professional or Security Specialty certifications
  • Experience with enterprise compliance frameworks
  • Knowledge of OpenTofu
  • Experience with AWS StackSets
  • Experience with enterprise identity federation and SSO

Job Details

About us:

Working at Tech Holding isn't just a job, it's an opportunity to be a part of something bigger. We are a full-service consulting firm that was founded on the premise of delivering predictable outcomes and high-quality solutions to our clients.  Our founders and team members have industry experience and have held senior positions in a wide variety of companies – from emerging startups to large Fortune 50 firms – and we have taken our combined experiences and developed a unique approach that is supported by the principles of deep expertise, integrity, transparency, and dependability.

About the Role:

Lead the AWS Control Tower implementation and multi-account governance modernization initiative. This role requires deep expertise in AWS Organizations, Control Tower, and enterprise-scale account management.

Key Responsibilities:

AWS Control Tower Implementation

  • Design and implement AWS Control Tower Landing Zone architecture for 40+ accounts
  • Evaluate retrofit vs. new organization strategies with comprehensive risk/cost analysis
  • Configure Account Factory for Terraform (AFT) pipeline for automated account provisioning
  • Deploy and customize Customizations for Control Tower (CfCT) pipelines
  • Establish shared accounts (Audit, Security, Log Archive, Networking) with proper baseline configurations

Infrastructure as Code & Automation

  • Develop and maintain modules for reusable infrastructure components
  • Implement automated tagging, budget alerts, and security baseline enforcement
  • Create version-controlled IaC repositories with proper CI/CD integration

Governance & Compliance

  • Design and implement Service Control Policies (SCPs) and guardrails strategy
  • Configure AWS Config, CloudTrail, and centralized logging across all accounts
  • Establish drift detection and remediation processes
  • Create guardrail exception registry and management workflows

Account Management

  • Lead 40+ account enrollment/migration into Control Tower governance
  • Reconcile existing IAM roles, policies, and automation with new baseline standards
  • Implement organizational unit (OU) structure optimization
  • Develop account onboarding automation and documentation

Required Skills & Experience:

  • 5+ years of AWS cloud architecture and enterprise-scale implementations
  • Expert-level experience with AWS Control Tower, Organizations, and Landing Zones
  • Strong proficiency in Infrastructure as Code (Terraform preferred)
  • Experience with Account Factory for Terraform (AFT) and Customizations for Control Tower (CfCT)
  • Deep understanding of AWS security services (IAM, Config, CloudTrail, SCPs)
  • Experience with multi-account governance patterns and best practices
  • Strong scripting skills (Python, Bash, PowerShell)
  • Experience with CI/CD pipelines and GitOps workflows

Preferred Qualifications:

  • AWS Solutions Architect Professional or Security Specialty certifications
  • Experience with enterprise compliance frameworks (SOC2, PCI-DSS, HIPAA)
  • Knowledge of OpenTofu and migration from Terraform
  • Experience with AWS StackSets and cross-account resource management
  • Background in enterprise identity federation and SSO implementations

Salary Range:

  • $130-150/hour

Location:

  • Westlake Village, Ca
  • On-site, 4x per week

 


*Applicants must be authorized to work for ANY employer in the U.S. We are unable to sponsor or take over sponsorship of an employment Visa at this time

Tech Holding is proud to be an Equal Opportunity Employer and is committed to fostering a diverse and inclusive workplace. We welcome applicants from all backgrounds and experiences, and we consider qualified applicants without regard to race, color, religion, gender, sexual orientation, gender identity, national origin, disability, veteran status, or any other legally protected characteristic. If you require accommodation in the application process, please contact our HR 

Similar Jobs

Mastercard - SVP, Account Management, Global Digital Platforms

Mastercard

San Francisco, California, United States (On-Site)
1 Month ago
AI Fund - Senior Recruiter

AI Fund

Antioquia, Colombia (Hybrid)
4 Months ago
Alpha Sense - Implementation Consultant

Alpha Sense

New York, New York, United States (On-Site)
3 Months ago
ISS Stoxx - Client Success Associate

ISS Stoxx

Norman, Oklahoma, United States (On-Site)
1 Month ago
Saviynt - Senior Solutions Engineer

Saviynt

Paris, Île-de-France, France (Hybrid)
8 Months ago
Capgemini - Devops Engineer

Capgemini

Bengaluru, Karnataka, India (On-Site)
2 Months ago
Zscaler - Senior DevOps Engineer

Zscaler

Ramat Gan, Tel Aviv District, Israel (Hybrid)
2 Months ago
Nice - Cloud Site Reliability Engineer

Nice

Pune, Maharashtra, India (On-Site)
1 Month ago
Match Group - Sr. Software Engineer, Machine Learning Infrastructure

Match Group

Palo Alto, California, United States (Hybrid)
9 Months ago
PwC - Senior Solution Architect – Modular & Scalable Systems

PwC

Buenos Aires, Buenos Aires, Argentina (On-Site)
3 Weeks ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

CME Group - Manager, Global Account Management

CME Group

Tokyo, Japan (On-Site)
1 Year ago
GHX - Asset Management Specialist

GHX

Hyderabad, Telangana, India (On-Site)
1 Month ago
skillz - VIP Account Manager

skillz

Las Vegas, Nevada, United States (On-Site)
3 Months ago
USE Insider - Customer Success Manager (Arabic Speaker)

USE Insider

Türkiye (Hybrid)
9 Months ago
klass - Chief Revenue Officer

klass

Toronto, Ontario, Canada (Hybrid)
3 Months ago
Plaid  - Account Manager - Fintech Named Accounts

Plaid

New York, United States (On-Site)
4 Months ago
Unity - Client Partner, User Acquisition

Unity

London, England, United Kingdom (On-Site)
3 Months ago
Keywords Studios - Senior Business Development Manager

Keywords Studios

Canada (Remote)
4 Months ago
hogarth - Freelance Producer Support

hogarth

Tokyo, Japan (On-Site)
2 Months ago
Adyen - Sales Manager Enterprise

Adyen

São Paulo, Brazil (On-Site)
1 Month ago

Get notifed when new similar jobs are uploaded

Jobs in Westlake Village, California, United States

Varonis  - Account Manager

Varonis

Minneapolis, Minnesota, United States (On-Site)
9 Months ago
GoMotive - Underwriting Manager, Risk Operations Management

GoMotive

United States (Remote)
3 Months ago
Apple - AIML - Machine Learning Educator

Apple

Seattle, Washington, United States (On-Site)
2 Months ago
Bright Edge - Sales Enablement Manager I

Bright Edge

Cleveland, Ohio, United States (On-Site)
1 Month ago
zoox - Strategic Sourcing Manager - Electrical Components

zoox

Foster City, California, United States (Hybrid)
9 Months ago
upwork - Director of Payments & Financial Services Partnerships

upwork

United States (Remote)
1 Month ago
Luma - AI Tooling Engineer

Luma

Palo Alto, California, United States (Hybrid)
3 Months ago
Fliff - Data Scientist

Fliff

Austin, Texas, United States (On-Site)
1 Year ago
Threat connect - Account Executive

Threat connect

California, United States (Remote)
4 Months ago
Perplexity - Customer Success Engineer - API and Enterprise

Perplexity

New York, United States (On-Site)
3 Weeks ago

Get notifed when new similar jobs are uploaded

Devops Jobs

Aristocrat - DevOps Lead

Aristocrat

Austin, Texas, United States (Hybrid)
2 Months ago
Amber - Bazel Senior Build Engineer (Project Based)

Amber

Bucharest, Bucharest, Romania (Remote)
5 Months ago
endava - Google Cloud Engineer - Infrastructure

endava

Guadalajara, Jalisco, Mexico (On-Site)
2 Months ago
Salesforce - Distributed Systems Software Engineer - Public Cloud (Senior/Lead/Principal)

Salesforce

San Francisco, California, United States (On-Site)
10 Months ago
CyberArk - Senior Software Engineer, Golang, Cloud Native

CyberArk

Santa Clara, California, United States (Hybrid)
3 Months ago
Applied materials  - Software Architect

Applied materials

Chennai, Tamil Nadu, India (On-Site)
1 Month ago
Illumina - Staff Automation Engineer

Illumina

Foster City, California, United States (On-Site)
1 Month ago
FitXR - Backend Engineer (DevOps / Cloud)

FitXR

United Kingdom (Remote)
1 Month ago
Interactive Brokers - Platform Operations Engineer - Linux

Interactive Brokers

Zug, Zug, Switzerland (On-Site)
2 Months ago
Vercel - Build Systems Engineer - Turborepo

Vercel

New York, United States (Hybrid)
2 Months ago

Get notifed when new similar jobs are uploaded

About The Company

London, England, United Kingdom (On-Site)

London, England, United Kingdom (Hybrid)

Gurugram, Haryana, India (On-Site)

Bengaluru, Karnataka, India (On-Site)

Santiago De Querétaro, Querétaro, Mexico (On-Site)

View All Jobs

Get notified when new jobs are added by techholding

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug