Cloud Architect - AWS

Cloud Architect - AWS

Location:

Geelong 

Work Type:

Contract

Industry:

Cloud & DevOps

Contact Name:

Nick Reddy

Contact Phone:

03 8080 7260

Date Published:

01-Sep-2026

  • Cloud Architect - AWS
  • Location: Geelong
  • Hybrid, 3 days per week in office
  • 6 months Contract with view to extend
  • VIC Government organisation
  • Attractive daily rate
 
About the Role
Client is strengthening its enterprise cloud foundations as part of a broader hybrid and multi-cloud strategy. The Principal AWS Landing Zone Architect will own the target architecture and provide hands-on technical leadership through implementation, assurance and transition into operations.
The role requires someone who has previously built enterprise AWS landing zones at scale and can translate security, compliance, networking, identity, delivery and operational requirements into a practical platform that product teams can consume safely.

What success looks like in the role
  • A clear, approved target architecture covering account structure, organisational units, identity, connectivity, security, logging, observability, resilience, cost governance and service operations.
  • A governed multi-account foundation using AWS Organizations and AWS Control Tower, with repeatable account vending and workload onboarding.
  • Automated platform deployment and configuration using infrastructure as code, version control, peer review and CI/CD controls.
  • Security controls that are embedded by default, with central visibility, evidence collection and integration into enterprise security operations.
  • A pragmatic operating model with clear ownership, support boundaries, lifecycle management, exception handling and measurable service outcomes.
  • Reusable patterns and documentation that enable delivery teams to adopt AWS without recreating foundational controls for every workload.
 
Key accountabilities
Architecture ownership
  • Lead discovery across architecture, cyber security, identity, network, platform, operations, risk, procurement and delivery stakeholders.
  • Define the end-state AWS landing zone architecture, architecture principles, decision records, standards and implementation roadmap.
  • Design the multi-account and organisational unit model, management account boundaries, delegated administration model, service control policies and control inheritance.
  • Make and document practical trade-offs between AWS-native capabilities, enterprise tooling and third-party controls.
  • Ensure the platform can evolve without redesign as workload demand, regulatory obligations and operating arrangements change.
 
Technical design and delivery leadership
  • Provide detailed architecture and engineering direction for AWS Control Tower, AWS Organizations, IAM Identity Center, Account Factory and Account Factory for Terraform where appropriate.
  • Define infrastructure-as-code modules, repositories, branching, testing, release and deployment patterns using Terraform and enterprise CI/CD tooling.
  • Design enterprise connectivity including Direct Connect, Transit Gateway, VPC architecture, IP address management, DNS, routing, ingress, egress, inspection, Private Link and private service access.
  • Design identity federation, privileged access, workload identities, role models, break glass access, secrets management and least-privilege controls.
  • Define central security, logging and monitoring capabilities using services such as AWS CloudTrail, AWS Config, GuardDuty, Security Hub, KMS, CloudWatch and central log archive patterns.
  • Establish patterns for backup, disaster recovery, encryption, key management, vulnerability management, patching and incident response integration.
  • Lead technical assurance of the build, resolve design issues and ensure implementation remains aligned with the approved architectur
Required experience
  • Significant experience in senior infrastructure, platform or cloud engineering and architecture roles, including substantial recent AWS architecture experience, typically seven years or more.
  • Personal leadership of at least two enterprise AWS multi-account landing zone implementations from discovery and detailed design through build, workload onboarding and operational handover.
  • At least one landing zone delivered in a regulated, government, financial services, health, insurance or similarly complex environment.
  • Deep hands-on knowledge of AWS Organizations, AWS Control Tower, account vending, organisational unit design, service control policies and delegated administration.
  • Strong Terraform and automation capability, including reusable modules, testing, Git-based delivery and CI/CD pipelines. The candidate must be able to review implementation quality, not only produce diagrams.
  • Strong enterprise networking knowledge spanning hybrid connectivity, routing, DNS, IP address management, network security and traffic inspection.
  • Strong cloud security architecture knowledge across identity, encryption, key management, central logging, threat detection, security monitoring, vulnerability management and audit evidence.
  • Demonstrated ability to define platform operating models, technical standards, support boundaries, workload onboarding and FinOps controls.
  • Excellent stakeholder leadership and communication skills, including the ability to explain complex architecture decisions and trade-offs to senior non-technical stakeholders.
Highly desirable
  • AWS Certified Solutions Architect - Professional. Certification is valued but is not a substitute for delivery evidence.
  • Experience integrating AWS with Microsoft Entra ID, enterprise SIEM platforms, service management tooling and on-premises security controls.
  • Experience with AWS Account Factory for Terraform, Control Tower customisation and automated policy deployment.
  • Experience aligning technical controls to Australian government or regulated-industry frameworks such as the ISM, Essential Eight, VPDSF, ISO 27001 or NIST CSF.
  • Experience establishing AWS foundations within a broader hybrid or multi-cloud environment.
Apply Now
Ready to take on a high-impact role within a nationally significant program, send through your CV to  nick.reddy@peoplebank.com.au
 
Referrals are welcome – please share with your network.

Keywords for Search - Principal AWS Architect, AWS Cloud Architect, AWS Solutions Architect, Principal Cloud Architect, Cloud Platform Architect, AWS Platform Architect, AWS Landing Zone Architect, AWS DevOps Architect



Peoplebank and Leaders IT are committed to creating a diverse and inclusive workplace where everyone belongs. We welcome applications from people of all backgrounds, identities, and experiences. If you need adjustments to the recruitment process due to your circumstances, please let us know—we’re here to support you.
APPLY NOW

Share this job

Interested in this job?
Save Job
Create As Alert

Similar Jobs

SCHEMA MARKUP ( This text will only show on the editor. )