Senior Cloud Platform Engineer (AWS) - Landing Zone

Gdańsk, PL, 80-309 Warszawa, PL, 02-460 Gdynia, PL, 81-537 Helsinki, FI, 00500

Job ID: 5900

 

Group Technology sits at the centre of how Nordea runs and evolves as a bank. Our job is to give the organisation a clear, structured picture of its technology and the environment around it, so that the business strategy and the customer vision have a solid foundation to build on.

 

We're looking for a Senior Cloud Platform Engineer with deep AWS experience to join us and take real ownership of our AWS Landing Zone. This is a hands-on role. You'll be building new capabilities into the platform as well as keeping what we already run healthy, secure, and reliable.

 

Nordea has a long history across the Nordics, but the way we work today looks a lot more like a tech company than a traditional bank. What we build touches millions of people every day, so it has to be dependable and it has to keep their money and data safe. That responsibility is a big part of what makes the work interesting

 

About our team

 

We're the Cloud Platform Team, a group of cloud specialists who own and evolve Nordea's enterprise cloud platforms. We work alongside application teams through their whole cloud journey, from first onboarding into day-to-day operations and optimisation. Because we operate in banking, our AWS environment has to hold up to serious scrutiny on security, compliance, and operational stability, and we take that seriously without making it a bottleneck for the teams we support.

 

What you'll be doing

 

The heart of this role is our AWS Landing Zone. You'll be developing new features for it and maintaining the existing platform. In practice that means:

  • Building and maintaining Landing Zone infrastructure as code with Terraform, handling configuration management with Ansible, and writing automation in Python and Bash for provisioning and ongoing operations.
  • Building central, reusable solutions at the Landing Zone level so that application teams can adopt them with minimal effort, instead of every team solving the same problems on their own.
  • Designing and running the CI/CD pipelines that ship Landing Zone changes, keeping those pipelines healthy, and setting up automated testing for platform components, while helping the wider team work in a genuine DevOps way rather than just talking about it.
  • Staying active in day-to-day engineering: raising and reviewing pull requests as a normal part of how the team works, and contributing to architecture documentation so the reasoning behind the platform is written down and easy to follow.
  • Keeping an eye out for gaps in our automation and closing them, so we're not repeating manual work that could be scripted.
  • Designing the networking foundation across our multi-account setup: VPCs, subnets, security groups, route tables, Transit Gateway, and the multi-account structure that keeps workloads properly separated.
  • Building and operating hybrid connectivity between AWS and our on-premises data centres using Direct Connect and Site-to-Site VPN, and making sure it's reliable and performant.
  • Applying zero trust principles to how workloads and users get access, so that connectivity is never implicitly trusted just because it's inside the network. This includes sensible use of IAM, service control policies, and network segmentation.
  • Setting the governance guardrails and best practices (think Control Tower, Landing Zone Accelerator, and organisation-level policy) that keep the platform compliant with banking security standards, without turning every request into a ticket queue.
  • Building the platform's observability, including the dashboards we use to monitor and control it, so that both our team and the application teams can see what's running and react quickly when something looks off.
  • Leading P1/P2 incident response when things go wrong: driving the response, running root cause analysis, coordinating across teams, and improving our procedures afterwards so we don't hit the same wall twice.

 

Who you are

 

Your background and skills include: 

  • 5+ years of hands-on cloud engineering, with strong, current AWS experience at enterprise scale.
  • Practical experience designing and running an AWS Landing Zone, ideally using Control Tower, Landing Zone Accelerator, or an equivalent multi-account foundation.
  • Strong command of Terraform for infrastructure as code, and solid Ansible skills for configuration and automation.
  • Good programming ability in Python and Bash.
  • Experience building CI/CD pipelines.
  • A genuine understanding of AWS networking: VPC design, Transit Gateway, Direct Connect, and how you'd connect AWS back to on-prem, along with how zero trust changes the way you design access.

 

Nice to have

 

None of these are dealbreakers, but they'd be a plus:

  • A degree in Computer Science, Information Technology, or something related.
  • AWS Solutions Architect Professional or DevOps Engineer Professional certification.
  • Experience with Docker and Kubernetes (EKS in particular).
  • Familiarity with security frameworks and compliance standards.
  • Experience with monitoring and observability tooling (CloudWatch, Prometheus, Grafana, ELK).
  • ITIL or a similar service management background.
  • Comfort working in an agile setup.

 

What we offer

 

Collaboration. Ownership. Passion. Courage. These are the values that guide us in how we work and how we make decisions – and that we imagine you share with us.

 

People are driven by many different factors. For some, it’s to take their career to the next level. For others, it’s to break new ground within their area of expertise – in other words, with us, you will always move forward.

 

A culture that fosters performance and growth in one of the largest Nordic banks, offering various opportunities to evolve, develop and learn from brilliant colleagues with diverse backgrounds in a vibrant working environment.

 

Hybrid working model – we believe in the value of bringing people together and at the same time we embrace the freedom of flexibility.

 

Diversity and inclusion are a natural part of our daily work. We know that an inclusive workplace is a sustainable one. We genuinely believe that our diverse backgrounds, experiences, characteristics and traits make us stronger together. Every day we strive to find new ways to improve diversity and inclusion within our community e.g. we have signed the European Diversity Charters in the countries where we operate to show our commitment and engage with others to continue learning and improving.

 

If this sounds like you, get in touch!

 

Next steps

 

​Submit your application no later than 07/09/2026. Please notice that we'll start interviewing before the posting closes.

 

We enable dreams and aspirations for a greater good.

 

We build relationships. We add a personal touch to everything we do – when advising our customers, collaborating with colleagues, and meeting our potential candidates.

 

We learn and develop. We take pride in being experts and thinking ahead. We use our expertise to meet our customers’ needs, from the simplest to the most complex. We bring a growth mindset to our work that enables us to focus on a broader perspective in our daily challenges.

 

We lead change. We are responsible and aware of the impact of our decisions, both for our customers and for our local and global communities. Mindful of our responsibility towards current and future generations, we have made sustainability an integrated part of our business strategy.

 

We are Nordea. We have a 200-year history of supporting and growing the Nordic economies and our values are deeply rooted in these open, progressive and collaborative societies. As one of the biggest employers in the Nordics, Poland and Estonia, you have excellent opportunities to evolve, develop and move forward with us. Studies show that members of underrepresented communities don’t apply for jobs unless they tick all the qualification boxes. If this is part of why you hesitate to apply, we would like you to reconsider and give it a chance. Maybe your profile fits our needs much better than you think.

 

Only for candidates in Finland: A security clearance will be performed for the person selected for this position.

 

Only for candidates in Poland: Please include permit for processing personal data in CV as following:

 

In accordance with art. 6 (1) a and b. Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) hereinafter ‘GDPR’. I agree to have: my personal data, education and employment history proceeded for the purposes of current and future recruitment processes in Nordea Bank Abp.

 

The administrator of your personal data is: Nordea Bank Abp operating in Poland through its Branch, address: Aleja Edwarda Rydza Śmiglego 20, 93-281 Łodź. Your personal data will be processed for the recruitment processes in Nordea Bank Abp. You have a right to access your personal data, right to rectify and right to delete. Disclosing the personal data in the scope specified by the provisions of Polish Labour Code from 26 June 1974 and executive acts are mandatory. Providing personal data is necessary to conduct the recruitment processes. The request for the deletion of your personal data means resignation from further participation in recruitment processes and causes the immediate removal of your application. Detailed information concerning processing of your personal data can be found at: https://www.nordea.com/en/doc/nordea-privacy-policy-for-applicants.pdf

 

We reserve the right to reply only to selected applications.

Department:  IT/Technology

Learn more about us

Learn more about us

How we recruit

Who we are

Sustainability in Nordea

Our purpose and values