We are seeking a Senior IT Platform Specialist to act as the AWS Platform Owner within DIGITALcore responsible for the vision, roadmap, and hands-on delivery of the AWS Secure Landing Zone and associated AWS-native platform capabilities. You will operate the AWS environment as an internal product, enabling GDMS programs and internal services to onboard quickly, build securely, and meet compliance requirements.
You will manage feature development and platform evolution, while also managing our sub-contractor providing day-to-day operational support. The ideal candidate combines deep AWS platform and infrastructure expertise with strong service ownership instincts customer obsession, user experience awareness, and the ability to translate stakeholder needs into secure, scalable platform features.
Key Responsibilities
AWS Platform Ownership
- Own the AWS platform roadmap inside DIGITALcore: define priorities, epics, and release plans for the Landing Zone and AWS platform services.
- Establish AWS platform “product” outcomes: onboarding velocity, reliability, security posture, and customer satisfaction.
- Align AWS platform priorities with DIGITALcore system governance, enterprise architecture, and security/compliance stakeholders.
Secure Landing Zone Engineering (Hands-On)
- Design, build, and evolve AWS Landing Zone capabilities using IaC and automation (e.g., Terraform/CDK/CloudFormation + CI/CD).
- Implement and maintain multi-account patterns, baseline configurations, and secure-by-default guardrails (SCPs, IAM standards, encryption/KMS, centralized logging, config rules, detective controls).
- Publish and maintain reference architectures and reusable patterns for common workloads (networking, segmentation, endpoints, logging, monitoring, shared services).
Compliance Enablement & Evidence
- Ensure AWS platform capabilities support required control objectives (e.g., NIST 800-171-aligned requirements and other program-driven frameworks).
- Build audit-ready evidence through automated checks, standard configurations, and repeatable artifacts (control mappings, test results, runbooks).
Operational Excellence & SOC/SIEM Integration
- Own AWS operational health: SLOs, incident processes, change controls, patching/upgrades, and service reliability.
- Enable enterprise security monitoring: standardized logs, alerting, and integrations that support corporate SOC and SIEM workflows.
Sub-Contractor Management
- Direct and manage sub-contractor daily work: backlog assignment, priorities, acceptance criteria, QA, documentation, and knowledge transfer.
- Establish SLAs, escalation pathways, and a continuous improvement cycle for support quality and platform stability.
Customer Obsession & UX for Engineers
- Treat GDMS programs/internal teams as customers: capture pain points, remove friction, improve “time-to-first-workload.”
- Improve platform usability: clear docs, onboarding checklists, templates, paved roads, and developer-friendly guardrails.