This is a remote position.
Join one of the Philippines' fastest-growing tech companies! Open to Philippine-based candidates only.
Company Overview
Full Scale is a tech services company that helps businesses build dedicated teams of skilled software engineers. We make finding and retaining experienced software talent easy and affordable.
Position Summary
We are looking for an AWS Cloud Architect to join our growing team and serve as the technical authority on a multi-account AWS platform built for scale. You will own the cloud architecture, the Terraform/OpenTofu module ecosystem, and the ETL and data pipeline layer that feeds a lakehouse and ML services for a US-based client in the automotive retail space. This is a hands-on architecture role — not a slide-deck role. You will write Terraform, build Glue jobs, debug VPC route tables, and own the standards that make the platform scale across multiple business units. You will
partner with a DevOps Engineer (who operates what you design) and a Data Scientist (whose models depend on the data you make available and trustworthy).
Key Responsibilities
Own the multi-account AWS Organization design: OU structure, account vending, Service Control Policies, Control Tower guardrails, and IAM Identity Center for SSO.
Own network architecture — Transit Gateway hub-and-spoke, VPC design and segmentation, PrivateLink, DNS, and cross-account connectivity — designed for multi-region and multi-tenant growth.
Design the security architecture and keep it coherent as services multiply: IAM boundaries and least privilege, KMS key strategy, org-wide CloudTrail, GuardDuty/Security Hub/Inspector/Macie, and WAF/Shield at the edge.
Define reference architectures and standards for new services so the tenth service built looks like the first. Author and maintain architecture documentation.
Lead the EKS adoption path: Fargate vs. managed node groups, IRSA, cluster networking, and which workloads belong in containers vs. staying serverless.
Own AWS Well-Architected reviews and drive remediation. Own cloud cost architecture — tagging strategy, chargeback by workload, and commitment planning.
Own the Terraform/OpenTofu codebase end to end: module design, versioning, registry strategy, state management, and Terragrunt configuration across environments and accounts.
Enforce IaC quality through policy-as-code (OPA/Sentinel or equivalent), automated plan review, drift detection, and remediation.
Eliminate console-created resources — everything that exists should exist in code.
Mentor engineers on IaC patterns and review infrastructure changes.
Own the lakehouse architecture: S3 Bronze/Silver/Gold zones, partitioning and file-format strategy, Glue Data Catalog, Lake Formation governance, and Databricks integration.
Design, build, and maintain ETL and ELT pipelines ingesting from CRM/DMS systems, call data, payment systems, inventory feeds, and OEM sources — using AWS Glue, Lambda, Step Functions, EventBridge, and Databricks as appropriate.
Own data quality: validation at ingestion, schema evolution, reconciliation, late and duplicate record handling, and alerting when a feed goes quiet or goes wrong.
Design change-data-capture and incremental-load patterns; move off full reloads where they still exist.
Own the Aurora footprint (MySQL and PostgreSQL/pgvector), including schema design, performance tuning, and serverless scaling configuration.
Build the data lineage and cataloging practice so analysts and scientists can answer "where did this number come from" without asking a person.
Design pipelines with downstream ML consumption in mind — reproducible features, stable definitions, and backfill capability.
Define and enforce data retention, PII classification, and access control policy across the lake, with particular care around call recordings, payment data, and customer records.
Support PCI-relevant scoping and segmentation decisions on the payment path.