AWS engineer job description template (2026)
A complete AWS engineer job description you can copy, plus seniority levels and writing tips for hiring someone who designs, secures and runs your AWS accounts.
By the Ryz Labs team · Updated October 2026
An AWS engineer job description should say which part of AWS the person will own. Some teams need someone to design a multi-account landing zone, some need a cost and reliability owner for an existing estate, and some really want a backend developer who can deploy to Lambda. Spell out the accounts, the services in production, the compliance pressure and who owns application code. The template below is written for a senior AWS engineer who owns account structure, IAM, networking, cost and reliability for a product team running on AWS. Copy it, replace the bracketed details and remove anything that does not match your environment.
AWS engineer job description template
Job title
Senior AWS Engineer (Cloud Infrastructure, Security and Cost)
Employment type: full-time or contract. Location: remote, with at least four hours of overlap with US Eastern time.
About the role
We are looking for a senior AWS engineer to own the cloud foundation behind [product name]. Today we run [number] AWS accounts under AWS Organizations, with workloads on [ECS / EKS / Lambda] and data in [RDS Postgres / Aurora / DynamoDB]. You will shape how accounts, identities and networks are structured, keep our bill predictable, and make sure we can recover from a regional problem without heroics. You will work with backend engineers, security and finance, and report to [title].
Responsibilities
- Design and maintain our multi-account structure with AWS Organizations, Control Tower or a custom landing zone, including service control policies and guardrails.
- Own IAM: least-privilege roles, permission boundaries, IAM Identity Center access for engineers, and cross-account access patterns that people can actually understand.
- Design VPC networking: subnets, routing, NAT strategy, Transit Gateway or VPC peering, PrivateLink endpoints and DNS with Route 53.
- Write and review infrastructure as code in Terraform or AWS CDK, with plans reviewed in pull requests and no click-ops in production.
- Run cost reviews with Cost Explorer and the Cost and Usage Report, tag resources consistently, and right-size compute, storage and data transfer.
- Plan Savings Plans and Reserved Instance coverage with finance, based on real usage rather than guesses.
- Set up backup, disaster recovery and multi-AZ designs with documented RPO and RTO, and test restores on a schedule.
- Configure security services such as GuardDuty, Security Hub, AWS Config and CloudTrail, and turn their findings into fixed issues.
- Run architecture reviews against the AWS Well-Architected Framework for new services before they reach production.
- Manage secrets and keys with Secrets Manager, Parameter Store and KMS, including key policies and rotation.
- Help application teams debug production problems across load balancers, security groups, quotas and service limits.
Requirements
- 5+ years in infrastructure or backend engineering, with at least 3 years running production workloads on AWS.
- Deep knowledge of IAM policy evaluation: identity policies, resource policies, SCPs, permission boundaries and how they combine.
- Strong VPC networking skills, including CIDR planning, routing, NAT gateways, security groups versus NACLs and private connectivity.
- Production experience with Terraform or AWS CDK, including state management, modules and safe refactoring.
- Hands-on experience with core compute and data services: EC2, ECS or EKS, Lambda, S3, RDS or Aurora, and DynamoDB.
- A track record of reducing AWS cost without hurting reliability, and the ability to explain where the money goes.
- Experience with CloudWatch metrics, logs and alarms, or a third-party tool such as Datadog, for debugging production issues.
- Working knowledge of encryption at rest and in transit with KMS and ACM.
- Clear written English for design docs, runbooks and change proposals.
Nice to have
- AWS Certified Solutions Architect Professional or Security Specialty.
- Experience with compliance frameworks such as SOC 2, HIPAA or PCI DSS on AWS.
- Multi-region active-passive or active-active designs with Aurora Global Database or DynamoDB global tables.
- Event-driven architectures with EventBridge, SQS, SNS and Step Functions.
- Experience migrating workloads from on-premises or another cloud with AWS Migration Hub or DMS.
- Policy as code with OPA, Checkov or tfsec in CI.
Tech stack
AWS Organizations and IAM Identity Center, Terraform, ECS on Fargate, Lambda, Aurora Postgres, DynamoDB, S3, CloudFront, Route 53, Transit Gateway, KMS, Secrets Manager, GuardDuty, Security Hub, CloudWatch, GitHub Actions with OIDC to AWS. Replace this list with your real services; candidates use it to judge the job.
What success looks like in 6 months
- Every production account is defined in code, and engineers reach AWS through Identity Center roles rather than long-lived access keys.
- Monthly spend is broken down by team and service through tags, and you have shipped at least two cost reductions finance can see on the bill.
- Restores and failover have been tested and documented, with an agreed RPO and RTO for each critical system.
- High-severity Security Hub and GuardDuty findings are triaged on a routine, not left to pile up.
How to apply and interview process
Send your resume or LinkedIn profile and a short note about an AWS environment you designed or cleaned up. Our process has four steps: a 30-minute intro call, a technical conversation about an environment you have run, a practical design exercise on a realistic infrastructure problem, and a final conversation with the team you would join. We aim to give feedback within a few days of each step.
Junior vs mid vs senior AWS engineer
AWS work ranges from following runbooks to deciding how a whole company's accounts and networks fit together. Match the level to the decisions the person will make on their own.
| Level | Scope | Typical experience | Key skills |
|---|
| Junior | Changes to existing Terraform modules and resources, with every plan reviewed by a senior engineer | 0-2 years | Core services (EC2, S3, IAM basics), reading Terraform plans, CloudWatch logs, Linux and shell |
| Mid-level | Owns infrastructure for one or two services, including networking, alarms and deployments | 2-5 years | VPC design, IAM roles for workloads, ECS or Lambda in production, cost tagging, incident debugging |
| Senior | Account strategy, security guardrails, cost governance and DR design across the company | 5+ years | Organizations and SCPs, cross-account networking, Well-Architected reviews, FinOps, threat modeling |
Tips for writing an AWS engineer job description that attracts senior talent
- Say how many accounts and regions you run. One account with everything in it and fifty accounts under Control Tower are different jobs. Senior candidates want to know which one they are walking into.
- Name your IaC tool and its state. "Terraform, mostly in modules, with some resources still created by hand" is honest and useful. Candidates know a cleanup job when they see one, and many enjoy it.
- Be clear about cost ownership. If the person is expected to answer to finance for the bill, say so. If cost is someone else's problem, say that too, because it changes the role.
- Separate platform work from application work. State whether this engineer writes application code or supports teams who do. Mixing the two without saying so is a common reason AWS hires leave early.
- List your compliance requirements. SOC 2, HIPAA or PCI scope shapes daily work. Engineers with audit experience will apply because of it, and others will filter themselves out.
- Do not over-weight certifications. A certification shows study; a story about recovering from a misconfigured route table shows judgment. Ask for certifications as a plus, not a gate.
- Describe on-call honestly. State the rotation, how often pages happen and who is the escalation point. Vague on-call language puts off experienced engineers more than a demanding but defined schedule.
Skip the job post: hire a vetted senior AWS engineer
A strong job description starts a hiring process that can take months, and cloud work rarely waits. If you need senior AWS capacity sooner, Ryz Labs can match you with senior AWS engineers from Latin America who work on your team, work in your accounts, repos and standups, and keep hours within ±1h of US time zones. Only the top 1% of the engineers we interview make it through our vetting, which covers IAM, networking, infrastructure as code and production debugging.
Our staff augmentation model lets you add one engineer or several without changing how your team works. Ryz engineers work on your team, reporting to your leads. Talk to us to scope your team. If you are running your own hiring loop, our AWS interview questions cover the areas we test and what strong answers sound like.
FAQ
What is the difference between an AWS engineer and a DevOps engineer?
An AWS engineer goes deep on one cloud: account structure, IAM, networking, managed services, security and cost. A DevOps engineer focuses on how software gets built, released and observed, and may work across clouds. Many people do both, but your job description should say which one is the main job.
Should an AWS engineer job description require certifications?
Usually not as a hard requirement. Certifications such as Solutions Architect Professional show breadth, but production experience with IAM, VPC design and incident response matters more. List certifications as a plus unless a customer contract requires them.
Which AWS services should I list in the job description?
List the services you run in production today and the ones you plan to adopt soon. A focused list such as ECS, Aurora, S3 and Transit Gateway tells candidates far more than a long list of every AWS service, and it attracts people who have used those services at real scale.
Questions we didn't answer? Email info@ryzlabs.com.