Design and build secure AWS Landing Zones, develop Infrastructure as Code using Terraform, and implement governance and security controls across multi-account AWS environments.
Key Highlights
Key Responsibilities
Technical Skills Required
Benefits & Perks
Nice to Have
Job Description
Contract Senior AWS Platform Engineer
Fully Remote (UK) - Outside IR35
Start Date: 17th August 2026
The Opportunity
We're supporting a highly respected UK cloud consultancy that has secured a major AWS transformation programme for a leading online education provider.
This is a business-critical cloud separation (carve-out) project, establishing a brand-new AWS platform following the client's separation from its parent organisation. The programme is operating to demanding timescales, making this an excellent opportunity for an experienced AWS Platform Engineer who enjoys building cloud environments from the ground up.
This is not a BAU support role. You'll be joining a project team responsible for designing, building and delivering a production-ready AWS platform that will underpin the client's future operations.
There is also a strong likelihood that this contract will extend into a wider cloud modernisation programme following completion of the initial separation project.
The Role
Working as part of an experienced cloud engineering team, you'll design and build a secure, enterprise-grade AWS Landing Zone and provide the cloud platform that enables the client's existing workloads to be deployed into their new environment.
The client already owns its application codebase. Your focus will be on building the infrastructure, governance, automation and deployment capabilities required to support those applications—not migrating SaaS platforms or rewriting applications.
Key Responsibilities
- Design and build a secure AWS Landing Zone.
- Build and configure multi-account AWS environments using AWS Organizations.
- Develop and manage Infrastructure as Code using Terraform.
- Refactor and migrate existing Terraform repositories.
- Implement governance, security guardrails and Service Control Policies (SCPs).
- Design AWS networking including VPCs, routing and security groups.
- Configure IAM Identity Center (AWS SSO), Permission Sets and role-based access controls.
- Configure AWS CloudTrail, AWS Config and security monitoring.
- Build and maintain GitHub repositories, permissions and CI/CD pipelines.
- Integrate GitHub authentication with AWS deployments.
- Support integration with Microsoft 365, Salesforce and other SaaS platforms from an AWS platform perspective.
- Configure Cloudflare services including DNS and WARP connectivity where required.
- Produce technical documentation, knowledge transfer and support production cutover.
Essential Skills & Experience
We're looking for an experienced AWS Platform Engineer with a proven track record of building secure cloud foundations rather than simply deploying workloads.
You'll ideally have experience with:
AWS Platform
- AWS Landing Zones
- AWS Organizations
- Organizational Units (OUs)
- AWS Control Tower
- AWS IAM Identity Center (AWS SSO)
- Service Control Policies (SCPs)
- AWS CloudTrail
- AWS Config
- Amazon VPC
- Amazon EC2
- Amazon S3
- AWS security services
- Multi-account AWS environments
- AWS governance and platform design
- Enterprise cloud migration and lift-and-shift programmes
Interested in remote work opportunities in Devops? Discover Devops Remote Jobs featuring exclusive positions from top companies that offer flexible work arrangements.
Infrastructure as Code
- Strong Terraform experience (essential)
- Terraform modules
- Terraform state management using S3
- Multi-account Terraform deployments
- Infrastructure automation
- Refactoring existing Terraform repositories
DevOps & Source Control
- GitHub administration
- Repository migration
- GitHub Teams & Permissions
- Branch protection
- CI/CD pipeline development
- GitHub authentication with AWS
- Pull Request workflows
Identity & Access Management
- Azure Entra ID (Azure AD)
- AWS IAM
- IAM Permission Sets
- Identity federation
- External Identity Providers (IdPs)
- Role-based access control
Browse our curated collection of remote jobs across all categories and industries, featuring positions from top companies worldwide.
Networking & Integrations
- Cloudflare
- Cloudflare WARP
- Cloudflare Access
- DNS delegation
- Public DNS
- SaaS integrations
- API authentication
- Cloud networking
Highly Desirable
- Enterprise carve-out or separation programmes.
- Cloud modernisation projects.
- AWS Well-Architected Framework.
- Security architecture and Zero Trust principles.
- Experience working alongside Managed Service Providers.
- Multi-vendor programme delivery.
What You'll Be Working Towards
By the end of the engagement you'll have:
- Delivered a secure, production-ready AWS Landing Zone.
- Established governance and security controls across a multi-account AWS environment.
- Enabled the client's workloads to deploy successfully into their new AWS platform.
- Supported a successful production cutover within demanding delivery timescales.
- Left behind a well-documented platform ready for ongoing cloud modernisation.
If you're an AWS Platform Engineer who enjoys building cloud platforms from scratch, working with Terraform, AWS Organizations, GitHub and modern cloud governance, we'd love to hear from you.
Similar Jobs
Explore other opportunities that match your interests