AWS Engineer
Summary
Designs and implements secure, scalable AWS cloud platforms for a large banking group, enforcing governance, security, and self-service provisioning for internal teams.
- Do you want to design and implement scalable, secure, and cost-effective solutions on AWS and influence the organization's cloud architecture and strategy?
- Are you interested in a role where you combine deep technical expertise with stakeholder engagement, lead architectural decisions, and mentor others?
- Are you interested in becoming part of a leading global provider of software and cloud solutions that helps organizations optimize technology and drive digital transformation?
Practical Information
Location: Prague, Czech Republic | Leader: Cloud Services Lead | Working Model: Hybrid | Job Type: Full time | Visa: Valid work permit for the Czech Republic | Language requirements: Fluent/professional Czech (written and spoken), communicative English
Join the Cloud Platform team responsible for building and governing a centralized AWS Landing Zone and multi-account platform for a large banking group. The role focuses on designing, implementing, and enforcing cloud governance, security guardrails, networking foundations, and self-service account provisioning capabilities used by internal application teams.
Key Responsibilities- Build and evolve AWS Landing Zone and AWS Organization structures across multiple business entities and Organizational Units (OUs).
- Design and implement multi-account AWS environments at enterprise scale.
- Develop and maintain Terraform modules and Infrastructure-as-Code automation.
- Build Account Vending and Account Factory capabilities for self-service account provisioning.
- Implement governance guardrails using SCPs, Control Tower controls and resource-based policies.
- Design IAM strategy including ABAC (Attribute-Based Assess Control), IAM Roles, Permission Sets, Permission Boundaries and IAM Identity Center.
- Create secure networking foundations, including Hub-Spoke architectures, Transit Gateway, VPC Endpoints, Direct Connect, and hybrid connectivity between on-premises datacenters and AWS.
- Build security baselines including CloudTrail, GuardDuty, logging, monitoring and service hardening.
- Define and enforce approved service catalog and cloud standards consumed by internal application teams.