Hands-on AWS Architect
Summary
A part-time, 2-3 month contract for an experienced AWS Architect to set up governance and security guardrails on a new main AWS account: service control policies, tagging enforcement, IAM and account provisioning baselines, aligned to ISO 27001. Prefers on-site work in Copenhagen; core stack is AWS with Terraform.
Introduction & Summary
We are seeking an experienced AWS Architect to lead the design and implementation of organizational guardrails on a newly created main AWS account. This role focuses on establishing appropriate governance for sub-accounts while ensuring compliance with security standards, including ISO 27001. The ideal candidate will possess substantial expertise in developing service control policies, IAM management, and cloud security best practices.
Main Responsibilities
The AWS Architect will be responsible for:
Developing service control policies, including region restrictions.
Implementing a tagging policy with enforcement.
Establishing an account provisioning baseline for new accounts.
Setting up an IAM baseline at the organization level.
Conducting a report-only run of guardrails against the existing main account.
Key Requirements
Proven experience in architecting AWS solutions.
Strong understanding of service control policies and IAM management.
Experience with Terraform for infrastructure as code.
Knowledge of compliance standards such as ISO 27001.
Ability to collaborate effectively in an on-site team environment.
Nice to Have
Experience in the life sciences or pharmaceutical industry.
Familiarity with GuardDuty and detection/logging tools.
Other Details
This engagement is expected to last two to three months at part-time intensity, with a preference for on-site collaboration in Copenhagen.