
AWS Cloud Architect – ETL, Terraform
Posted Jul 29

Posted Jul 29
This is a fully remote position, open to applicants in Philippines.
• Take ownership of the multi-account AWS Organization design: Organizational Unit structure, account provisioning, Service Control Policies, Control Tower guardrails, and IAM Identity Center for Single Sign-On.
• Manage network architecture — including Transit Gateway hub-and-spoke, VPC design and segmentation, PrivateLink, DNS, and cross-account connectivity — tailored for multi-region and multi-tenant expansion.
• Architect the security framework and ensure coherence as services increase: IAM boundaries and least privilege, KMS key strategy, organization-wide CloudTrail, GuardDuty/Security Hub/Inspector/Macie, and WAF/Shield at the perimeter.
• Establish reference architectures and standards for new services to ensure consistency across deployments.
• Create and maintain comprehensive architecture documentation.
• Drive the EKS adoption strategy: Fargate versus managed node groups, IRSA, cluster networking, and determining which workloads should utilize containers versus remaining serverless.
• Oversee AWS Well-Architected reviews and facilitate remediation efforts.
• Manage cloud cost architecture — including tagging strategy, workload chargeback, and commitment planning.
• Oversee the Terraform/OpenTofu codebase throughout its lifecycle: module design, version control, registry strategy, state management, and Terragrunt configuration across different environments and accounts.
• Enforce Infrastructure as Code (IaC) quality through policy-as-code (OPA/Sentinel or equivalent), automated plan reviews, drift detection, and remediation strategies.
• Eliminate resources created through the console — all infrastructure must be represented in code.
• Mentor engineers on IaC best practices and evaluate infrastructure changes.
• Manage the lakehouse architecture: S3 Bronze/Silver/Gold zones, partitioning and file format strategy, Glue Data Catalog, Lake Formation governance, and Databricks integration.
• Design, develop, and maintain ETL and ELT pipelines that ingest data from CRM/DMS systems, call data, payment systems, inventory feeds, and OEM sources — utilizing AWS Glue, Lambda, Step Functions, EventBridge, and Databricks as necessary.
• Ensure data quality through validation at ingestion, schema evolution, reconciliation, and handling of late and duplicate records, while also setting up alerts for any issues with data feeds.
• Develop change-data-capture and incremental-load patterns; phase out full reloads where still in use.
• Manage the Aurora footprint (MySQL and PostgreSQL/pgvector), focusing on schema design, performance optimization, and serverless scaling configuration.
• Build a data lineage and cataloging practice to enable analysts and scientists to trace the origin of numbers without needing to consult others.
• Design pipelines with downstream machine learning consumption as a priority — ensuring reproducible features, stable definitions, and backfill capabilities.
• Establish and enforce data retention, PII classification, and access control policies across the lake, paying close attention to call recordings, payment data, and customer records.
• Assist in PCI-relevant scoping and segmentation decisions regarding the payment process.
• A minimum of 5 years in cloud engineering, with at least 4 years dedicated to AWS architecture.
• Expert proficiency in Terraform or OpenTofu (module development, state management, and multi-account strategies).
• Proven experience in multi-account AWS design (Organizations, Control Tower, SCPs, Transit Gateway, IAM Identity Center).
• Strong hands-on experience in ETL/data engineering using AWS Glue, Spark, Step Functions, and Python.
• Experience in designing data lakes or lakehouses, including Bronze/Silver/Gold architecture and governance using Lake Formation or similar tools.
• Extensive serverless experience with Lambda, API Gateway, EventBridge, SQS/SNS, and Aurora Serverless.
• Robust SQL and relational data modeling capabilities, including performance tuning on Aurora or comparable managed databases.
• In-depth knowledge of security architecture, covering IAM, KMS, network segmentation, and AWS security services.
• Ability to produce clear technical design documents that engineers can implement without the need for further clarification.
• Fully remote – work from anywhere in the Philippines.
• Senior architecture role with authentic decision-making authority over a production AWS platform.
• Engaging with a mature, robust cloud foundation — not a "build it from scratch" greenfield project.
• Opportunity to influence data platform standards that will scale across various business units.
• Small, senior, high-autonomy team that promotes a documentation-first culture.
• Collaborative engineering environment with strong Full Scale account support.
• A team culture that emphasizes ownership, technical depth, and commitment.
SPD Technology
Totara
Vesta Software Group
Elfonze Technologies
Get handpicked remote jobs straight to your inbox weekly.