




Job Summary: We are seeking a legal entity service provider with AWS experience to define the cloud foundation for a bank, ensuring governance, security, and regulatory compliance. Key Highlights: 1. Results-oriented performance in a critical banking environment. 2. Technical and operational autonomy in AWS cloud projects. 3. Definition of the AWS cloud foundation, ensuring governance and security. ### **Be yourself, be your best!** E\-Core develops digital solutions and strategic initiatives through specific projects, connecting specialized expertise to the requirements of each delivery. For a defined project, we seek a **legal entity service provider**, with technical experience aligned with the scope described below, to deliver results-oriented work and pre-agreed deliverables. ### **Project Context** Project for a banking-sector client focused on three key areas: Landing Zone/Infrastructure, Database, and Observability/Monitoring. Requirements involve critical, high-availability environments. We seek a service provider with solid experience in the financial/banking sector, responsible for defining the bank’s AWS cloud foundation—ensuring governance, security, financial control, and regulatory compliance—with a resilient architecture prepared for future expansion. ### **Scope of Services** The services provided will include, but are not limited to: ### **AWS Landing Zone Structuring** * Implementation of AWS Organizations and definition of OUs. * Configuration of Control Tower (where applicable). * Definition of a multi\-account model with segregation by environment and domain. * Implementation of SCPs (Service Control Policies). * Standardization of corporate naming and tagging. ### **Network Architecture** * Structuring of segmented VPCs and subnets. * Configuration of Transit Gateway and hybrid connectivity (VPN / Direct Connect). * Planning of a secure architecture across multiple Availability Zones. * Implementation of DMZ and segmentation of critical workloads. ### **Security and Compliance** * Implementation of centralized IAM and role-based access control. * Configuration of CloudTrail, Config, GuardDuty, and Security Hub. * Key and encryption management using AWS KMS. * Alignment with banking-sector regulatory requirements. ### **Governance and Costs (FinOps Integration)** * Structuring of tagging and cost allocation models. * Configuration of Budgets and Cost Explorer. * Support for financial governance of the Landing Zone. ### **Resilience and Continuity** * Multi\-AZ and multi\-region architecture. * Backup and disaster recovery strategies. * Definition of standards for critical workloads (EKS, EC2, RDS). Activities will be carried out with technical and operational autonomy, respecting the agreed scope, deadlines, and acceptance criteria. ### **Professional Profile Aligned with the Project** This project aligns with professionals possessing the following technical competencies: * AWS Organizations \& Control Tower * IAM, SCPs * VPC, Transit Gateway * Direct Connect / VPN * GuardDuty, Security Hub, CloudTrail * AWS KMS * EKS, EC2, RDS * Terraform / CloudFormation ### **Work Model** * Modality: Hybrid work: 3 days onsite at the bank in the Itaim Bibi region and 2 days remote. * Occasional alignment sessions as required by the project, without working-hour tracking. ### **Contract Model** * Employment Type: Legal Entity (PJ) * Engagement Type: Service Provision * Estimated Commitment: Phase-/Delivery-Based Engagement * Project Duration: 10 months The provision of services does not establish an employment relationship, subordination, habitual engagement, or exclusivity, and is governed by a specific agreement between the parties. **Privacy** By submitting an application, I acknowledge that I have read and understood e\-Core’s Privacy Policy. Privacy Policy (EN) / Privacy Policy (PT\-BR) The purpose of everything we do is to connect people and technology to build a better future—together!


