Principal, Cloud Engineering, AWS

General Dynamics Missions System InternationalOttawa, ON
CA$120,000 - CA$170,000

About The Position

General Dynamics Mission Systems–Canada is seeking a Principal, Cloud Engineering AWS Manager to own the design, build, and operation of our sovereign AWS Canada estate. Reporting into the Chief Digital & Information Officer(CDIO) this is a senior, the successful candidate will set the standards and guardrails for the platform, deliver them in code, and run the environment to the security and compliance bar that a regulated, sovereign defence environment demands. The role is deliberately positioned as the anchor of the organization's AWS capability. The successful candidate will lead the transition of landing-zone operations from the current managed-service provider into a sustainable in-house model and will act as the definitive AWS technical authority across the CDIO organization. This person will be a builder first; comfortable owning outcomes end to end and exercising a high degree of autonomy within the guardrails and priorities set by executive leadership.

Requirements

  • A minimum of 10 years of experience in cloud or infrastructure architecture, with deep, demonstrable expertise designing, building, and operating production AWS environments at scale.
  • Expert command of AWS landing-zone design, including AWS Organizations, Control Tower, multi-account architecture, core networking, and security services.
  • Strong Infrastructure as Code and automation capability, ideally with Terraform, together with hands-on experience of CI/CD and policy-as-code.
  • Proven experience securing and operating cloud within a regulated environment, with a working understanding of the compliance frameworks and change discipline it demands.
  • The ability to own outcomes end to end and operate autonomously, and to present platform direction and trade-offs to an executive audience.
  • A senior AWS certification, such as Solutions Architect – Professional or DevOps Engineer – Professional, or equivalent demonstrable expertise.
  • Demonstrated mentorship capabilities

Nice To Haves

  • Dual-cloud depth across both AWS and Microsoft Azure is highly desirable, given a multi-cloud estate in which AWS serves as the sovereign landing zone and Azure as the predominant enterprise platform.
  • Experience in a defence, government, or critical-infrastructure environment subject to controlled-goods or equivalent handling requirements.
  • Experience standing up sovereign or otherwise constrained cloud environments, and transitioning operations from a managed-service provider to an in-house model.
  • Familiarity with CMMC 2.0, ITAR and EAR, and the Canadian Controlled Goods Program.
  • Experience working with or familiarity with AI/ML models is preferred.

Responsibilities

  • Own the architecture, build, and lifecycle of the sovereign AWS Canada landing zone, including multi-account structure, account vending, and organizational guardrails using AWS Organizations and Control Tower.
  • Design and implement core platform networking, including VPC design, Transit Gateway, and Direct Connect connectivity into on-premises and enclave environments.
  • Establish platform standards, reference patterns, and the roadmap that balance quality against the constraints of a controlled environment.
  • Design and enforce identity, encryption, logging, and monitoring controls, using services such as IAM, KMS, CloudTrail, GuardDuty, and Security Hub.
  • Ensure the platform satisfies CMMC 2.0, ITAR and EAR handling obligations, and Controlled Goods Program requirements, and that data residency and sovereignty are preserved by design.
  • Integrate the platform with the organization's security tooling and partner closely with the Cybersecurity function on threat detection and response.
  • Deliver the environment as code using Terraform or equivalent, and implement policy-as-code, automated provisioning, and drift detection.
  • Oversee the build and maintain CI/CD pipelines for platform and workload deployment, reducing manual effort and configuration risk.
  • Champion automation as the default operating model for the estate.
  • Lead the transition of landing-zone operations from the managed-service provider to an in-house model in line with the defined insourcing trigger.
  • Define the operating model, runbooks, and standards required to run the platform sustainably, and manage knowledge transfer from the incumbent provider.
  • Manage the technical relationship with AWS and platform vendors, and hold them to standards and value.
  • Enable data, AI, and application workloads to land on the platform securely and efficiently, partnering with the data, networking, and application teams.
  • Act as the AWS technical authority in design authority and governance forums, and set the standards that others build to.
  • Anchor and mentor the AWS capability as it grows, providing the technical foundation for a future in-house cloud team.

Benefits

  • Comprehensive medical, dental, and vision coverage for you and eligible dependents from day one (no cost), including flexible benefits options (HCSA) emergency travel insurance, and 24/7 virtual care services.
  • Employee & Family Assistance Program (EFAP), onsite fitness facilities, and employee resource groups.
  • Defined Contribution Pension Plan with employer contributions after 3 months, RRSP access from day one, and financial planning support.
  • Flexible time off including vacation, holidays, parental leaves with top-up options, sick leave, and disability programs.
  • Career development through learning platforms, educational assistance, mentoring, and reimbursement of professional memberships.
  • Additional perks such as employee discounts, free onsite parking, social clubs, and an annual scholarship program for employees’ children.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service