Principal, Cloud Engineering, AWS

2 days ago

, Canada General Dynamics Corporation Full-time
At General Dynamics Mission SystemsCanada, were not just engineering technology were shaping the future of defence and security. Our teams design and deliver advanced, mission-critical solutions that enhance national security, strengthen communities, and protect the people we serve. Full-time At General Dynamics Mission SystemsCanada, were not just engineering technology were shaping the future of defence and security. Our teams design and deliver advanced, mission-critical solutions that enhance national security, strengthen communities, and protect the people we serve.

Job Description
General Dynamics Mission SystemsCanada is seeking a Principal, Cloud Engineering AWS Manager to own the design, build, and operation of our sovereign AWS Canada estate. Reporting into the Chief Digital & Information Officer(CDIO) this is a senior, the successful candidate will set the standards and guardrails for the platform, deliver them in code, and run the environment to the security and compliance bar that a regulated, sovereign defence environment demands. The role is deliberately positioned as the anchor of the organization's AWS capability. The successful candidate will lead the transition of landing-zone operations from the current managed-service provider into a sustainable in-house model and will act as the definitive AWS technical authority across the CDIO organization. Own the architecture, build, and lifecycle of the sovereign AWS Canada landing zone, including multi-account structure, account vending, and organizational guardrails using AWS Organizations and Control Tower. Design and implement core platform networking, including VPC design, Transit Gateway, and Direct Connect connectivity into on-premises and enclave environments. Design and enforce identity, encryption, logging, and monitoring controls, using services such as IAM, KMS, CloudTrail, GuardDuty, and Security Hub. Ensure the platform satisfies CMMC 2.0, ITAR and EAR handling obligations, and Controlled Goods Program requirements, and that data residency and sovereignty are preserved by design. Integrate the platform with the organization's security tooling and partner closely with the Cybersecurity function on threat detection and response. Deliver the environment as code using Terraform or equivalent, and implement policy-as-code, automated provisioning, and drift detection. Oversee the build and maintain CI/CD pipelines for platform and workload deployment, reducing manual effort and configuration risk. Lead the transition of landing-zone operations from the managed-service provider to an in-house model in line with the defined insourcing trigger. Manage the technical relationship with AWS and platform vendors, and hold them to standards and value. Platform Enablement and Technical Leadership Enable data, AI, and application workloads to land on the platform securely and efficiently, partnering with the data, networking, and application teams. Act as the AWS technical authority in design authority and governance forums, and set the standards that others build to. Anchor and mentor the AWS capability as it grows, providing the technical foundation for a future in-house cloud team. A minimum of 10 years of experience in cloud or infrastructure architecture,with deep, demonstrable expertise designing, building, and operating production AWS environments at scale. Expert command of AWS landing-zone design, including AWS Organizations, Control Tower, multi-account architecture, core networking, and security services. Strong Infrastructure as Code and automation capability, ideally with Terraform, together with hands-on experience of CI/CD and policy-as-code. A senior AWS certification, such as Solutions Architect Professional or DevOps Engineer Professional, or equivalent demonstrable expertise. Dual-cloud depth across both AWS and Microsoft Azure is highly desirable, given a multi-cloud estate in which AWS serves as the sovereign landing zone and Azure as the predominant enterprise platform. Experience in a defence, government, or critical-infrastructure environment subject to controlled-goods or equivalent handling requirements. Experience standing up sovereign or otherwise constrained cloud environments, and transitioning operations from a managed-service provider to an in-house model. Familiarity with CMMC 2.0, ITAR and EAR, and the Canadian Controlled Goods Program. Experience working with or familiarity with AI/ML models is preferred. It is a requirement that General Dynamics Mission Systems-Canada be registered with the Canadian Controlled Goods program and that all of its workforce be security assessed. Successful applicants must meet all applicable security requirements, including but not limited to the ability to obtain and maintain a Canadian government security clearance. Applicants may be required to meet additional security requirements in order to gain access to technical data, classi