Hire AWS Engineers Who Own the Bill as Well as the Architecture
Northell places AWS engineers who own infrastructure as code, least-privilege IAM, and the monthly bill — not engineers whose experience is clicking through the console. Every engineer is screened on a live exercise involving a real Terraform or CDK change and an IAM policy they have to justify.
Scope the role
Tell us the product, the stage, and the specific gap — a one-off build, an ongoing engineer, or a whole squad.
Meet 2-3 matched engineers
Shortlisted from our own vetted bench, not a marketplace of unverified profiles.
Start the engagement
Full-time embedded, part-time, or contract-to-hire — begin with a paid trial week before any longer commitment.
Got it — thanks!
A senior engineer will review this and reply within one business day.
Northell places AWS engineers on teams that have outgrown treating infrastructure as something someone sets up once. The bench behind this page has shipped 155+ product builds and holds a Clutch Top 20 ranking for Product Designers and Developers. AWS candidates are screened on infrastructure as code, IAM policy design, and cost attribution — because an engineer who can stand up a working environment but cannot reproduce it, secure it, or explain its cost leaves you with something that becomes a liability the moment they leave. Engagements run full-time embedded, part-time, or contract-to-hire, and every one opens with a paid trial week.
- Terraform or CDK as a requirement, so environments are reproducible and reviewable.
- Least-privilege IAM designed deliberately, not a wildcard policy that unblocked a deploy.
- Cost treated as an engineering metric with an owner and an attribution trail.
- Every engagement opens with a paid trial week before any longer commitment.
AWS Profiles Available Now
Senior Cloud Engineer — AWS Cost Optimization
Works on accounts where the bill has grown faster than the product and nobody can explain which service is responsible.
What you'll build
Tagging and cost allocation so spend maps to teams and services, right-sizing and scheduling for non-production environments, storage lifecycle and retention policies, and a data-transfer audit — followed by the guardrails that stop it recurring.
Works with engineering leadership and whoever owns the budget.
Why clients choose this profile
Starts with attribution rather than cuts, so reductions do not quietly break a service nobody claimed.
Apply to get matched →AWS Engineer — Serverless & Event-Driven Systems
Builds Lambda, EventBridge, and queue-based architectures for teams without a dedicated platform group.
What you'll build
Event-driven services with dead-letter queues and replay, API Gateway and Lambda deployed through CDK, and the observability needed to trace a request across several asynchronous hops.
Embeds with the product engineers consuming the infrastructure.
Why clients choose this profile
Designs for failure and replay from the start, which is what makes event-driven systems debuggable later.
Apply to get matched →Senior Platform Engineer — EKS & Deployment Pipelines
Owns the container platform and deploy pipeline several product teams ship through.
What you'll build
EKS cluster configuration and upgrade path, CI/CD pipelines with safe rollback, secret management, and autoscaling tuned to real traffic rather than defaults.
Serves multiple product teams as internal platform support.
Why clients choose this profile
Has run Kubernetes in production, including upgrades, which is where most self-managed clusters get painful.
Apply to get matched →Cloud Engineer — Migration & Landing Zone
Moves workloads from on-premise or another cloud onto AWS without a big-bang cutover.
What you'll build
A multi-account landing zone with sane guardrails, workload-by-workload migration with rollback paths intact, network and connectivity setup, and the runbooks your team needs to operate it afterwards.
Works with an internal team that knows the workloads but has not run them on AWS.
Why clients choose this profile
Sequences migrations so each step is reversible, rather than betting the business on one weekend.
Apply to get matched →What It Costs
We don't publish a blended average rate — a single number hides more than it reveals across seniority, specialization, and region. The ranges above are placeholders until we've tracked enough engagements to publish real medians; ask for current numbers on a scoping call rather than trusting a guess here.
We Turn Most Applicants Away
What we screen for
- A live technical exercise on a real, timeboxed problem — not a take-home someone else could have finished.
- At least one shipped production system they can walk through and explain their own decisions on.
- A code-review / architecture-critique session — how they handle pushback, not just how they present.
- Depth in one stack we place for over shallow 'full-stack everything' claims across a dozen technologies.
- Direct, unassisted communication in a live call — no relay through an account manager during screening.
What we don't do
- We don't forward a resume because it has the right keywords.
- We don't run a single unstructured chat and call it vetted.
- We don't place an engineer we haven't personally worked with or verified.
- We don't quote a rate before we understand the actual scope.
We turn away most applicants before they ever reach a client introduction — we're not publishing an exact rejection rate here until we're tracking it well enough to stand behind the number.
How We Screen Every AWS Engineer
Shipped-work + code review
We check for finished, production systems they've actually shipped — not just tutorial repos or slide decks.
Live technical exercise
A real, timeboxed problem drawn from a past Northell engagement, reviewed by one of our senior engineers.
Culture + communication check
A working session with the actual team they'd join, not only with Northell staff.
Who we're looking for
- Mid-to-staff level, with a track record of shipping production software (exact minimum years: TODO)
- Can walk through at least one system they took from scratch to production
- Comfortable presenting and defending technical decisions live
- Fluent in the core stack for the role, plus its testing and tooling ecosystem
- Experience owning code through code review, deploy, and on-call — not just writing it
- Written and spoken English fluency for client-facing work
- Available for a paid trial week before a longer engagement
- Comfortable working inside an existing codebase, not only greenfield builds
- Reads and writes tests as a default, not as an afterthought
- No conflicting concurrent full-time engagement, for embedded roles
- References from at least one prior client or employer we can verify directly
How it works
- You describe the role — Northell doesn't ask you to write a job post.
- We shortlist from engineers already vetted, not job-board applicants.
- You interview 2-3 matched profiles, not twenty.
- The engineer starts on a paid trial week before any longer commitment.
Common Hesitations, Answered Directly
What if the hire isn't a fit after we start?
That's what the paid trial week is for — flag it during the trial and we requalify or replace the person before any longer commitment is on the table.
What if we need someone full-time, not part-time?
Any engagement can convert from part-time or contract-to-hire into a full-time embedded model without restarting the vetting process — it's a scope conversation, not a new search.
What if our team is fully remote across time zones?
We match for meaningful working-hours overlap during scoping, not just calendar availability on paper.
What if we're not ready to commit long-term?
Start with the paid trial week. It exists specifically so neither side commits before actually working together.
Work This Bench Has Shipped
What Happens Next?
Even if none of the shortlisted candidates is a fit, you keep the scoping notes and a written recommendation on what to look for next.
Common Questions
Is this a DevOps engineer or a back-end developer who knows AWS?
It depends what you need, and it is worth separating on the scoping call. If your main gap is application code that happens to run on AWS, you likely want a back-end developer. If it is infrastructure, deployment, IAM, and cost, you want the profile on this page. We will tell you which one your description actually points to rather than staffing whichever you asked for.
Do they write infrastructure as code, or click through the console?
Infrastructure as code — Terraform or CDK — is a screening requirement, not a preference. Console-only work is unreviewable and unreproducible, and it is the single most common reason environments drift apart until nobody can recreate production.
Can they reduce our AWS bill?
Usually, and the first step is attribution rather than cuts: tagging and cost allocation so spend maps to services and teams. Most savings then come from a small number of specific causes — idle or oversized instances, storage class and retention, data transfer, and forgotten environments. We do not promise a percentage before seeing your account, because any number offered at that stage is guesswork.
Can they handle a migration from on-premise or another cloud?
Yes, and the useful skill is sequencing rather than architecture diagrams — moving one workload at a time, keeping a rollback path, and cutting over without a big-bang weekend. We screen for migration experience separately from general AWS competence, because they are genuinely different jobs.
How fast can an AWS engineer start?
Typically 1-2 weeks from the scoping call, and every engagement opens with a paid trial week. Exact turnaround depends on how specialized the requirement is (precise day-count: TODO, not yet tracked).
Also Hiring
The State of AWS Hiring in 2026
Console Experience Is Not Cloud Engineering
Plenty of candidates can stand up a working environment through the AWS console. Far fewer can reproduce it, review it, or hand it over. Infrastructure defined only through clicks has no history, no review, and no reliable path to a second environment that matches the first — which is why our screening requires a real Terraform or CDK change rather than a description of one. This single filter removes a large share of applicants who look strong on a resume.
IAM Is Where Most Cloud Security Actually Fails
Breaches in cloud environments far more often trace back to over-permissive roles than to exotic exploits. The wildcard policy that unblocked a deploy on a deadline tends to survive into production indefinitely, because nobody wants to be the person who tightens it and breaks something. We screen by asking candidates to justify a policy they wrote and to narrow it under questioning — an engineer who reaches for least privilege by default is worth substantially more than one who reaches for it after an audit.
Cost Is an Engineering Metric Without an Owner
AWS bills rarely grow because of a single bad decision. They grow because dozens of small ones accumulate with nobody accountable for the trend — an oversized instance here, a non-production environment left running, a storage class never revisited, cross-AZ data transfer nobody measured. The fix starts with attribution, not cuts: until spend maps to services and teams, every reduction is guesswork and some of it will break something. We screen for engineers who instinctively ask what is driving the number before proposing to lower it.
Serverless and Kubernetes Are Both Right Answers, to Different Questions
Serverless suits spiky, event-driven workloads and small teams without a platform group. Kubernetes suits organizations running many services with a team able to own upgrades and cluster operations. The failure mode is choosing on preference and then paying for the mismatch — a small team maintaining a cluster nobody has time to upgrade, or a complex system fragmented across hundreds of functions that no one can trace. We ask what your team can realistically operate, not just what the architecture diagram would prefer.
What Is Changing in AWS Hiring for 2026
Cost discipline has moved from a finance concern to an engineering requirement, and teams increasingly want an engineer who can attribute and defend spend rather than a specialist brought in after the bill spikes. Infrastructure as code is now assumed rather than differentiating. The other shift is trial-first engagements, with teams opening on a paid trial week rather than committing to a full-time platform headcount upfront — which is how every engagement here starts.
The company-wide numbers on this page come from Northell's own delivered work: 155+ product builds shipped, a Clutch Top 20 ranking for Product Designers & Developers, a Manifest Top 4 Product Design Team distinction, and named client engagements including MeetAlfred, Referrizer, NWCC, SmartJen, and Finixflo. We have not yet published a large-sample rate or engagement-tenure dataset — every field marked TODO on this page is a placeholder awaiting that tracking, not an estimate dressed up as fact.
AWS Engineer Screening Kit
The live-exercise prompts and review checklist we screen on — the infrastructure-as-code change, the least-privilege IAM scenario, and the cost-attribution questions we use to separate console operators from platform engineers.
Got it — thanks!
A senior engineer will review this and reply within one business day.