UK remote
AWS Cloud Infrastructure Architect with IRS MBI Clearance
About this role
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an AWS Cloud Infrastructure Architect with IRS MBI Clearance based in United Kingdom. This role is responsible for designing and managing secure, scalable AWS cloud infrastructure across complex multi-account environments. You will shape cloud architecture spanning account governance, networking, identity and access management, security, and compliance.
The position requires hands-on expertise with AWS Organizations, Control Tower, Landing Zone Architecture, and GovCloud environments. You will help establish resilient cloud foundations while supporting stringent regulatory and security requirements, including FedRAMP. Working closely with engineering and security teams, you will provide architectural guidance and help drive infrastructure best practices. The role also includes infrastructure automation, cost optimization, disaster recovery, and technical documentation.
This is an opportunity to make a direct impact on the reliability, security, and scalability of a mission-critical cloud environment. Accountabilities: Design and implement AWS account structures using AWS Organizations, including Organizational Units aligned with business and technical requirements. Establish account governance policies, standards, consolidated billing, and cost allocation strategies. Deploy and manage AWS Control Tower for automated account provisioning, governance, and organizational controls.
Design and implement Landing Zone Architecture for secure, scalable, multi-account AWS environments. Architect and deploy multi-region VPC environments, including subnets, route tables, network ACLs, and network segmentation strategies. Configure and manage Site-to-Site VPN, Client VPN, AWS Direct Connect, and Transit Gateway connectivity. Design hybrid and multi-VPC networking solutions and manage DNS through Amazon Route 53.
Architect network solutions for AWS GovCloud environments. Design and implement IAM policies, roles, permission boundaries, identity federation, and organization-level Service Control Policies. Establish least-privilege access models and MFA requirements while maintaining IAM governance and compliance frameworks. Develop and implement organization-wide security policies, monitoring, and incident response procedures. Configure and manage AWS Security Hub, GuardDuty, AWS Config, CloudTrail, WAF, and Shield.