The AWS Landing Zone project aims to provide a scalable and standardized cloud environment to support cloud migration efforts. As part of the Cloud Center of Excellence, the focus is on establishing a secure, compliant, and extensible architecture that serves as a foundation for future cloud workloads. Particular attention is given to the challenges of scalability and security to ensure a flexible, high-performance, and policy-compliant environment.
A key milestone is the implementation of a Security Credential Management system that ensures secure access and authorization while complying with corporate policies and regulatory requirements. Additionally, automation and testing are used to guarantee efficiency and quality in the deployment and management of the cloud environment. Another critical aspect is the provision of a secure internet connection that meets stringent security requirements and enables reliable communication for cloud workloads. The architecture must be designed to support future expansion and adapt flexibly to new demands.
Scope of Work:
Optimization of the AWS Landing Zone using AWS, Terraform, Terragrunt, and Python; automation of processes with AWS Lambda, Go, and Bash; code development with CodeCommit and GitLab; development and administration using CoPilot and Visual Studio Code.
Expansion and improvement of CI/CD pipelines through the use of GitLab for source code management, AWS CodeBuild for automated builds, State Machines and AWS Lambda for deployment orchestration, and Python for process automation.
Reinforcement of security controls and compliance validation by leveraging AWS IAM for identity and access management, AWS Config for configuration monitoring, AWS EventBridge for security-relevant events, and automation via AWS Lambda and Python; continuous alignment with security standards in consultation with the security team.
Enhancement of the monitoring system using Amazon CloudWatch and DevOps Guru for log and metric monitoring, log forwarding and custom metrics for detailed analysis, active network tests for performance validation, and automation with AWS Lambda and Python.
Optimization of network services using AWS Route 53 Resolver, Route 53, VPC, VPN, Transit Gateway (TGW), and Direct Connect (DX); increased availability with Network Load Balancer (NLB) and Application Load Balancer (ALB); secure application integration using API Gateway; and strengthened security mechanisms through firewalls in collaboration with the Firewall & Security team.
Must have:
Should have: