Posted on: 05/10/2026
AWS Cloud Platform Engineer
About the role
We are looking for a senior AWS platform engineer to lead the implementation and configuration of a self-service AWS sandbox capability (Innovation Sandbox on AWS) inside an established enterprise landing zone.
The environment is an existing AWS Control Tower organization with federated identity through Okta and IAM Identity Center, centralized logging into Splunk Cloud, and mandatory controls enforced by service control policy. The sandbox capability has to sit inside that organization rather than beside it, so every part of the build has to keep the existing baseline in force.
Scope of work
Organization and account structure
1. Configure the organizational unit and account structure that supports the sandbox lifecycle, aligned to the existing Control Tower design.
2. Set up the account pool and vending configuration so engineering teams can be issued short-lived, guardrailed accounts.
Account blueprints and provisioning
1. Implement the account blueprints and provisioning templates that shape each vended account.
2. Configure the lease and budget settings (maximum budget, duration, concurrency and approval) as part of standing the service up.
Identity integration and access
1. Configure the integration between the sandbox solution and IAM Identity Center.
Solution deployment and validation
1. Deploy and configure the Innovation Sandbox on AWS solution components inside the landing zone.
2. Wire the solution into centralized logging (Splunk Cloud) and the existing cost allocation model.
3. Validate end to end that a user can request an account, work in it, and have it recovered cleanly, with no protected organization-level resource touched.
Coordination and delivery
1. Raise and track the requests and access needed from the cloud infrastructure, cloud ops, cloud security and IAM teams.
2. Coordinate the sequence of work across those teams so the rollout is not blocked waiting on any one of them.
Must have
1. 7 to 10 years in AWS infrastructure, DevOps or cloud platform engineering, including at least 4 years in a multi-account environment.
2. Direct experience with Innovation Sandbox on AWS, AWS Nuke, cloud-nuke, or other account-vending or account-recycling automation.
3. Hands-on AWS Organizations: designing organizational units, authoring service control policies, account movement and delegated administration.
4. AWS Control Tower in production: landing zone, controls, Account Factory and drift detection.
5. IAM Identity Center: permission sets, groups, and SAML or SCIM federation from Okta or Entra ID.
6. Enough CloudWatch, CloudTrail, CloudWatch Logs Insights and S3 lifecycle configuration to stand up and prove centralized logging.
7. Cost Explorer, AWS Budgets and cost allocation tags, enough to configure sandbox spend into the existing allocation model.
8. Clear written English. Writing a runbook or change record that someone else can follow is a real part of this job.
Strongly preferred
1. Splunk with basic SPL in a centralized logging pattern.
2. AWS Certified Solutions Architect Professional, or DevOps Engineer Professional.
Did you find something suspicious?
Posted by
Posted in
Platform Engineering / SAP/Oracle
Functional Area
DevOps / Cloud
Job Code
1676593