The challenge
Three sprawling AWS accounts with no guardrails, shared IAM users, and a billing report nobody could explain. Auditors were asking hard questions and every deploy felt risky.
How I approached it
- Control Tower landing zone with separate workload, logging, and security accounts
- Identity federation to the bank directory with short-lived roles only
- Wave-based migration of 60 workloads with dual-run validation
- Service control policies locking regions, encryption, and egress
The outcome
Every workload moved with zero customer-facing downtime, and the next audit passed with the landing zone itself cited as good practice.
Stack: AWS Control Tower · Terraform · IAM Identity Center · CloudTrail Lake