This is the section where round two of the screen actually happens, the closing gate before an
interview hits your inbox. A recruiter takes their time here, and even at that, the current
role still drives around 95% of the result.
That tracks: nothing proves what you can run in production today like the seat you sit in
right now. To earn a "yes", the section has to hit every entry on the
Cloud Engineer role profile, one bullet per domain you named in Domain
Expertise above. Every bullet has to come off something you genuinely held in production,
never a ticket that landed on your queue.
1
Cloud Architecture & Landing Zones
You lay the landing zone every team builds on. Hiring managers read real landing-zone design behind it,
not "has an AWS account", so this is where a cloud hire proves out. Talk about how you used a
hub-and-spoke topology and Well-Architected reviews, in AWS Control Tower, to onboard teams and cut
time-to-account.
Techniques
Multi-account topology
Hub-and-spoke
Well-Architected reviews
Tenant isolation
Tools
AWS Control Tower
AWS Organizations
GCP Resource Manager
Metrics
Accounts brought online
Teams onboarded
Time-to-account cut
2
Networking & Connectivity
You wire up the cloud network: VPCs, peering, private links. Cloud networking is where things break in
ways nobody can see, so hiring managers want proof you designed it, not that you "opened some
security groups". Show them how you used a transit-gateway design and private connectivity, with
Route 53 and Direct Connect, to hold the network SLA and cut egress cost.
Techniques
VPC / subnet design
Transit & peering
DNS & CDN
Direct Connect / VPN
Tools
AWS Transit Gateway, Route 53
CloudFront / Cloud CDN
AWS Direct Connect
Metrics
Network SLA
Latency cut
Egress cost down
3
Identity & Security
You control who can touch what, by policy not trust. Loose IAM is how a single leaked key becomes a
breach, so hiring managers want to see access you actually locked down. Point out how you used SSO with
SCIM and least-privilege permission sets, backed by KMS and GuardDuty, to reduce privileged access and
close findings.
Techniques
SSO & SCIM
Permission sets / least privilege
SCPs / Org policies
Secrets & KMS
Tools
IAM Identity Center, Okta
KMS, Secrets Manager, Vault
GuardDuty, Security Hub
Metrics
Findings closed
Privileged access reduced
Audits passed
4
Compute & Cloud-Native Services
You pick the right cloud service for each workload. The wrong compute choice shows up in the uptime and
latency numbers a hiring manager can read, so the pick has to be defensible. Mention how you used
serverless patterns and event-driven architecture, on Lambda with EventBridge, to onboard workloads
while holding service uptime.
Techniques
Compute selection
Serverless patterns
Event-driven architecture
Reference patterns
Tools
EC2, EKS, Lambda
RDS, Aurora, DynamoDB
SQS, EventBridge, Pub/Sub
Metrics
Workloads onboarded
Service uptime
Latency held
5
Storage, Data & Databases
You store cloud data safely without overpaying. A hiring manager weighs two things here: whether you can
restore inside RPO when something fails, and whether you're overpaying to store it the rest of the
time. Walk them through how you used S3 lifecycle tiering and cross-region backup, tested with AWS
Backup, to hold RPO and RTO while cutting storage cost.
Techniques
S3 lifecycle & tiering
Backup & PITR
Cross-region replication
Encryption at rest
Tools
S3, EBS, EFS
RDS, Aurora, Redshift
AWS Backup
Metrics
RPO / RTO
Storage cost cut
Backups restored under test
6
Cost Optimization & FinOps
You hold the cloud bill down before finance notices. Hiring managers look here to see whether you watch
spend like an engineer, or whether the cost quietly creeps up until finance flags it. Lay out how you
used tagging with chargeback and rightsizing, tracked in Cost Explorer and CloudHealth, to cut annual
spend and hold unit cost.
Techniques
Tagging & chargeback
Rightsizing
Savings Plans / RIs
Anomaly detection
Tools
Cost Explorer, CUR
CloudHealth, Vantage
AWS Budgets
Metrics
Annual spend cut
Tag coverage
Unit cost held
7
Reliability, DR & Compliance
You prove the cloud survives a region loss and an audit. The business bets on the cloud staying up and
staying compliant, so a real DR drill tells a hiring manager they can trust you with production. Spell
out how you used multi-region design and audit-evidence pipelines, with AWS Config and Vanta, to hold
RPO and RTO and pass the audit.
Techniques
Multi-AZ / multi-region
DR playbooks
Audit evidence pipelines
Compliance frameworks
Tools
AWS Config, CloudTrail
Drata, Vanta
AWS Audit Manager
Metrics
Audits passed
RPO / RTO held
Findings closed
8
Tooling & Workflow
You turn cloud work into something teams self-serve. A self-serve setup means teams stop waiting on you
for every change, and that leverage is exactly what a hiring manager wants. Tell them how you used
policy as code and reusable modules, in Terraform with OPA and Checkov, to cut ticket volume and speed
reviews.
Techniques
Reusable IaC modules
Plan-based PR review
Policy as code
Self-serve docs
Tools
Terraform, Atlantis
Git, GitHub
OPA / Conftest, Checkov
Metrics
Modules maintained
PR cycle time
Onboarding ramp cut