Contra - A professional network for the jobs and skills of the futureSecure AWS Landing Zones Architect for Enterprise Migrations
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started
Project Title
AWS Cloud Security Architect: Landing Zones
Project Description
Designed and deployed secure cloud landing zones for enterprise migrations. Built multi-tier VPC topologies and isolated private subnets via Terraform to enforce rigid security boundaries.
Technical Breakdown (The Details)
Edge Protection: Configured entry pathways using Amazon Route 53 routing and AWS WAF (Web Application Firewall) layers to block unauthorized external traffic.
Central Governance: Implemented an isolated AWS Management Account hosting core compliance engines including S3 Log Archives, CloudTrail trails, Security Hub, GuardDuty threat detection, and AWS Config.
Environment Isolation: Engineered independent network perimeters across isolated VPC accounts (VPC-DEV, VPC-QA, and VPC-PROD) to prevent cross-environment vulnerabilities.
Multi-Tier Subnets: Segregated workloads internally using internet-facing Public Subnets (ALBs & NAT Gateways), completely hidden Private Subnets (Application Servers), and locked-down Data Subnets (Amazon RDS & S3).
Hybrid Connectivity: Connected the distributed multi-account architecture back to local corporate infrastructure securely using a centralized AWS Transit Gateway attached to the On-Premises Data Center.

Post image
Back to feed
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started