Live opening · Posted 3 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
About Accion Labs
Accion Labs is a global technology services company specializing in digital transformation, cloud modernization, data engineering, AI, and product development. We partner with leading enterprises to deliver innovative solutions that accelerate business outcomes through cutting-edge technology and engineering excellence.
Role Overview
We are seeking a highly experienced AWS Cloud Platform Engineer to lead the implementation and rollout of an AWS Innovation Sandbox capability within an enterprise-scale AWS environment.
The successful candidate will work within an existing AWS Control Tower ecosystem and collaborate closely with Cloud Infrastructure, Cloud Operations, Security, and IAM teams to design, deploy, and operationalize a secure self-service sandbox platform. This role requires deep expertise in AWS multi-account environments, governance, identity management, and cloud platform engineering.
Key Responsibilities
AWS Organization & Account Structure
Configure Organizational Units (OUs) and account structures aligned with the existing AWS Control Tower architecture.
Establish account vending and lifecycle management processes for short-lived sandbox environments.
Ensure adherence to enterprise governance and security policies.
Sandbox Provisioning & Automation
Implement account provisioning templates and blueprints.
Configure account lease periods, budgets, approval workflows, and concurrency controls.
Automate account creation, recycling, and cleanup processes.
Identity & Access Management
Integrate the sandbox platform with AWS IAM Identity Center.
Configure permission sets, group assignments, and federated authentication via Okta or Microsoft Entra ID.
Ensure secure and compliant access management practices.
Solution Deployment & Validation
Deploy and configure Innovation Sandbox on AWS components within the enterprise landing zone.
Integrate with centralized logging and monitoring solutions.
Validate end-to-end user onboarding, provisioning, usage, and decommissioning processes.
Ensure sandbox environments remain isolated from protected organization-level resources.
Stakeholder Coordination
Collaborate with Cloud Infrastructure, Operations, Security, and IAM teams.
Coordinate dependencies and required access requests.
Drive implementation activities and ensure successful rollout execution.
Produce documentation, runbooks, and operational procedures.
Required Skills & Experience
7-10 years of experience in AWS Infrastructure, Cloud Engineering, Platform Engineering, or DevOps.
Minimum 4 years working in large-scale AWS multi-account environments.
Strong hands-on experience with:
AWS Organizations
AWS Control Tower
AWS IAM Identity Center
AWS Account Factory
Service Control Policies (SCPs)
AWS Budgets and Cost Management
CloudTrail, CloudWatch, CloudWatch Logs Insights
S3 lifecycle management
Experience with:
Innovation Sandbox on AWS
AWS Nuke / Cloud-Nuke
Account vending and account lifecycle automation
Knowledge of identity federation technologies including Okta and Microsoft Entra ID.
Strong understanding of cloud governance, security, and operational best practices.
Excellent written and verbal communication skills.
Nice to Have
Splunk experience and basic SPL knowledge.
Experience integrating AWS platforms with centralized logging solutions.
AWS Certifications:
AWS Certified Solutions Architect Professional
AWS Certified DevOps Engineer Professional
Preferred Industry Experience
Experience in regulated environments is considered an advantage, including:
GDPR
HIPAA
GxP
ISO 27001
SOC 2
Work arrangement
Yes
More openings worth a look
Recently tracked roles with full details and direct application links.