AWS Platform Engineer / Cloud IAM Engineer
Ensar Solutions IncUnited States
ContractOn-siteJuniorLimited info disclosed
42 views0 applications
Description
Job Summary: Design, automate, and manage enterprise-scale AWS identity, access management, and multi-account governance solutions. The role focuses on AWS IAM, IAM Identity Center, AWS Organizations, Control Tower, and Python-based serverless automation to deliver secure, scalable access management while supporting governance, compliance, and operational excellence. Experience : 6
- years AWS platform / cloud / security engineering Automation : Python, Lambda, Step Functions, EventBridge, Boto3 Key Responsibilities: ● Design, implement, and manage AWS IAM and IAM Identity Center solutions across enterprise multi-account AWS environments. ● Build event-driven automation using Python, Lambda, Step Functions, EventBridge, Boto3, APIs, and reusable operational components. ● Support governance-as-code and IAM automation using Git, CI/CD pipelines, CloudFormation, CDK, or Terraform with automated validation. ● Maintain secure and scalable identity and access controls across multi-account AWS environments. ● Automate IAM, governance, validation, and account management processes using reusable cloud components. ● Develop IAM policies, permission boundaries, trust relationships, RBAC models, permission sets, and least-privilege access controls. ● Manage AWS Organizations governance, including SCPs, RCPs, tag policies, backup policies, guardrails, and account lifecycle controls. ● Configure and support AWS Control Tower, AWS Config, GuardDuty, CloudTrail, and Security Hub for governance and security posture monitoring. Required Skills: ● Hands-on experience with AWS Config, GuardDuty, CloudTrail, Security Hub, compliance monitoring, and automated remediation. ● Strong understanding of least-privilege access, multi-account governance, identity controls, and secure cross-account permissions. ● Ability to automate IAM, compliance validation, governance controls, and remediation workflows using Python and AWS serverless services. ● Deep expertise in AWS IAM, IAM Identity Center, AWS Organizations, Control Tower, IAM policy language, policy evaluation logic, cross-account access, and permission boundaries. ● Strong Python development skills with AWS Lambda, Step Functions, EventBridge, Boto3, APIs, and event-driven automation frameworks. ● Experience with Git-based source control, CI/CD pipelines, and version-controlled IAM policies, permission sets, and governance configurations. Preferred Qualifications / Certifications: ● Experience implementing enterprise AWS Landing Zones, account vending, account onboarding, and governance automation across AWS Organizations. ● Ability to implement version-controlled IAM, governance, and infrastructure configurations using CI/CD and Infrastructure as Code tools. ● Preferred certifications include AWS Certified Solutions Architect – Associate or Professional, AWS Certified Security – Specialty, and AWS Certified DevOps Engineer – Professional. ● Hands-on experience managing IAM Identity Center permission sets and automating account assignments through CI/CD pipelines. ● Familiarity with Terraform, CloudFormation, AWS CDK, GitOps practices, compliance frameworks, and identity governance patterns. ● Strong experience supporting multi-account AWS governance, identity management, and automated account provisioning. Soft Skills: Strong problem-solving skills, independent ownership, and the ability to manage responsibilities with minimal supervision. Effective stakeholder communication and collaboration across security, governance, engineering, and business teams. Ability to translate security and governance requirements into secure, scalable, and practical AWS solutions.