Job Description
Our client is looking for a Principal AWS Enterprise Architect to design the AWS environment our application teams will build on top of. This is a foundation and platform role. Workload migration is owned by other teams. Your job is everything underneath the applications: how accounts are structured, how the network is laid out, how identity works, how we connect back to the data center, how we protect PII, how we host Databricks and VDI, and what guardrails and patterns the rest of the org consumes. This is a hands-on architect role. We expect diagrams, working IaC reference modules, written decisions, and time in the room with security, networking, data, and application leadership — not just recommendations. By the time you wrap, the in-house team should own and be able to extend what you leave behind. We need technical expertise combined with communication and leadership skills to be able to present data and information to the executive team. This role is fully remote.
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.
Required Skills & Experience
• 15+ years in enterprise infrastructure and cloud architecture, with at least seven of those spent on production AWS at enterprise scale.
• You've personally architected at least two AWS landing zones that are still in production. Be ready to talk through them.
• Hands-on with the AWS pieces we care about here: Organizations, Control Tower, IAM Identity Center, Transit Gateway, Direct Connect, Shared VPC / RAM, KMS, WAF, Shield Advanced, GuardDuty, Security Hub, Config, CloudTrail, Macie, Network Firewall.
• Real experience running Databricks on AWS in a regulated environment.
• You've designed VDI on AWS at least once for an enterprise — WorkSpaces, AppStream, or something equivalent.
• Worked with PII (and ideally PHI, PCI, or other regulated data) and know what “compliant” looks like in implementation, not just on a slide.
• You can translate NIST CSF, SOC 2, HIPAA, PCI, or FedRAMP controls into concrete AWS configuration.
•Strong Terraform.
Nice to Have Skills & Experience
•AWS Solutions Architect – Professional and AWS Security – Specialty.
•Prior experience supporting an enterprise on-prem to AWS migration at scale.
•Comfortable with API Gateway, EKS, and ECS. Your design has to support modern API workloads even if you aren't building them.
•Integrations you've worked through before: Okta or Entra ID, ServiceNow, Splunk or Sentinel, CrowdStrike, Wiz or Sweet Security, CyberArk.
•Industry background in Telco/Service Provider
Benefit packages for this role will start on the 1st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401k retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other paid time off as provided by applicable law.