Design and deploy a new Amazon WorkSpaces environment, including directory services (AWS Managed Microsoft AD or AD Connector), networking, and security configuration
Build and maintain Terraform modules for all infrastructure components, following IaC best practices (state management, module reuse, environment separation)
Configure Workspace bundles, custom images, and user provisioning workflows
Implement networking (VPCs, subnets, route tables, security groups, VPN/Direct Connect as needed) to support secure Workspace access
Set up monitoring, logging, and alerting (CloudWatch, CloudTrail) for the Workspaces environment
Apply security best practices including IAM least-privilege, encryption at rest/in transit, and MFA enforcement
Document the architecture, runbooks, and IaC patterns to enable handoff at end of engagement
Collaborate with internal stakeholders to translate requirements into a working environment
Requirements
3+ years of hands-on AWS engineering experience
Production experience deploying and managing Amazon WorkSpaces
Strong Terraform skills, including module design, state management, and CI/CD integration