Senior Cloud Platform Engineer (AWS) - Landing Zone
Nordea · Helsinki
Hybridsenior💰 5,950–7,250 EURTech · FinancePublicerad 25.09.2026 klo 03.00
Kompetenser
AWSterraformansiblePythonbashCI/CDinfrastructure as codenetworkingsecurityiamzero trustobservabilityincident response
Jobbeskrivning
Job ID: 5900
Group Technology sits at the centre of how Nordea runs and evolves as a bank. Our job is to give the organisation a clear, structured picture of its technology and the environment around it, so that the business strategy and the customer vision have a solid foundation to build on.
We're looking for a Senior Cloud Platform Engineer with deep AWS experience to join us and take real ownership of our AWS Landing Zone. This is a hands-on role. You'll be building new capabilities into the platform as well as keeping what we already run healthy, secure, and reliable.
Nordea has a long history across the Nordics, but the way we work today looks a lot more like a tech company than a traditional bank. What we build touches millions of people every day, so it has to be dependable and it has to keep their money and data safe. That responsibility is a big part of what makes the work interesting About Our Team We're the Cloud Platform Team, a group of cloud specialists who own and evolve Nordea's enterprise cloud platforms. We work alongside application teams through their whole cloud journey, from first onboarding into day-to-day operations and optimisation. Because we operate in banking, our AWS environment has to hold up to serious scrutiny on security, compliance, and operational stability, and we take that seriously without making it a bottleneck for the teams we support.
What You'll Be Doing
The heart of this role is our AWS Landing Zone. You'll be developing new features for it and maintaining the existing platform. In practice that means:
Building and maintaining Landing Zone infrastructure as code with Terraform, handling configuration management with Ansible, and writing automation in Python and Bash for provisioning and ongoing operations.
Building central, reusable solutions at the Landing Zone level so that application teams can adopt them with minimal effort, instead of every team solving the same problems on their own.
Designing and running the CI/CD pipelines that ship Landing Zone changes, keeping those pipelines healthy, and setting up automated testing for platform components, while helping the wider team work in a genuine DevOps way rather than just talking about it.
Staying active in day-to-day engineering: raising and reviewing pull requests as a normal part of how the team works, and contributing to architecture documentation so the reasoning behind the platform is written down and easy to follow.
Keeping an eye out for gaps in our automation and closing them, so we're not repeating manual work that could be scripted.
Designing the networking foundation across our multi-account setup: VPCs, subnets, security groups, route tables, Transit Gateway, and the multi-account structure that keeps workloads properly separated.
Building and operating hybrid connectivity between AWS and our on-premises data centres using Direct Connect and Site-to-Site VPN, and making sure it's reliable and performant.
Applying zero trust principles to how workloads and users get access, so that connectivity is never implicitly trusted just because it's inside the network. This includes sensible use of IAM, service control policies, and network segmentation.
Setting the governance guardrails and best practices (think Control Tower, Landing Zone Accelerator, and organisation-level policy) that keep the platform compliant with banking security standards, without turning every request into a ticket queue.
Building the platform's observability, including the dashboards we use to monitor and control it, so that both our team and the application teams can see what's running and react quickly when something looks off.
Leading P1/P2 incident response when things go wrong: driving the response, running root cause analysis, coordinating across teams, and improving our procedures afterwards so we don't hit the same wall twice.
Who You Are
Your background and skills include:
5+ years of hands-on cloud engineering, with strong, current AWS experience at enterprise scale.
Practical experience designing and running an AWS Landing Zone, ideally using Control Tower, Landing Zone Accelerator, or an equivalent multi-account foundation.
Strong command of Terraform for infrastructure as code, and solid Ansible skills for configuration and automation.
Good programming ability in Python and Bash.
Experience building CI/CD pipelines.
A genuine understanding of AWS networking: VPC design, Transit Gateway, Direct Connect, and how you'd connect AWS back to on-prem, along with how zero trust changes the way you design access.
Nice to have
None of these are dealbreakers, but they'd be a plus:
A degree in Computer Science, Information Technology, or something related.
AWS Solutions Architect Professional or DevOps Engineer Professional certification.
Experience with Docker and Kubernetes (EKS in particular).
Familiarity with security frameworks and compliance standards.
Experience with monitoring and observability tooling (CloudWatch, Prometh