Services Expertise Projects Credentials Blog Get in touch
Available for new projects

Platform Architecture & AWS Landing Zones.| for Secure Enterprise Platforms

I design landing zones, governance frameworks and secure cloud foundations for enterprises — across AWS and European cloud platforms.

  • AWS Landing Zones, Control Tower & AFT
  • Governance, Security & Compliance by Design
  • Sovereign, Hybrid & European Cloud Platforms
main.tf variables.tf
AWS Landing Zones & Control Tower
Public sector & regulated environments
IONOS · OVHcloud · STACKIT
Sovereign & hybrid cloud architecture
AWS Certified Solutions Architect Pro
6+ years enterprise cloud engineering
ISO 27001 · BSI C5 · NIS2
100% Infrastructure as Code
AWS Landing Zones & Control Tower
Public sector & regulated environments
IONOS · OVHcloud · STACKIT
Sovereign & hybrid cloud architecture
AWS Certified Solutions Architect Pro
6+ years enterprise cloud engineering
ISO 27001 · BSI C5 · NIS2
100% Infrastructure as Code
Services

What I help clients build

Concrete platform architecture work for enterprises that need structure, security and governance — AWS-led, with capability across European and sovereign cloud environments.

AWS Landing Zones & Multi-Account Platforms

Design and implementation of secure AWS foundations for multi-account environments using Control Tower, AFT and Infrastructure as Code.

  • Organizations & OU design
  • Automated account vending
  • SCP guardrails & logging baselines
  • Identity Center & access models
Control TowerAFTTerraformAWS OrganizationsLanding Zone AcceleratorCDK

Governance & Security by Design

Governance frameworks and security models for regulated workloads — built around AWS-native controls and applicable across multi-cloud and sovereign cloud environments.

  • IAM, SCPs & permission boundaries
  • Security Hub, GuardDuty, Config
  • Compliance automation & evidence
  • Policy-as-code & cost governance
SCPsIAMSecurity HubBSI C5Data Perimeters

Hybrid & Sovereign Cloud Architecture

Enterprise cloud architecture for hybrid environments and sovereignty-driven requirements — across AWS, IONOS, OVHcloud, STACKIT and private infrastructure.

  • Hybrid cloud & direct connectivity
  • European & sovereign CSP platforms
  • AWS China and global networking
  • Migration architecture & planning
IONOSOVHcloudSTACKITCross-ConnectAWS European Sovereign Cloud
Results

Measured outcomes

Delivered across AWS and European cloud platforms — landing zones, security programs, hybrid SAP integration, sovereign cloud architecture and container platforms for regulated production environments.

0 Accounts governed across multi-account environments
0 Faster deployments via IaC vs. manual provisioning
0 Lower operating cost through governance & rightsizing
Service Deep-Dive

Multi-Account Landing Zones done right

I design and deploy enterprise-grade AWS Landing Zones using Control Tower and AFT — delivering automated account vending, centralized logging, and governance guardrails from day one. Your cloud foundation, built right the first time.

Discuss your project →
aft-deploy — prod
$ aft-deploy --env prod --account acme-prod-001
+ aws_organizations_account "acme-prod-001"
email = "aws+prod@acme.de"
ou_id = "ou-prod-eu-central-1"
+ aws_controltower_control "no-public-s3"
control = "AWS-GR_RESTRICT_ROOT_USER"
+ aws_cloudtrail "org-trail"
is_multi_region_trail = true
Apply complete! 47 resources added.
Account vending complete
SCPs applied — 12 guardrails active
Centralized logging pipeline active
security-hub — eu-central-1
Security Score87 / 100
GuardDutyACTIVE
Config Rules147 passed
IAM AnalyzerACTIVE
Security Hub87% controls
$ cat guardrail-no-public-s3.json
{
"Effect": "Deny",
"Action": "s3:PutBucketPublicAccessBlock",
"Condition": {
"aws:RequestedRegion": ["eu-central-1"]
}
}
Security & Compliance

Security & Governance by design

Security is not an afterthought. I implement SCPs, permission boundaries, and zero-trust architectures that enforce compliance automatically — aligned with BSI C5, ISO 27001 and NIS2.

Discuss your security needs →
Expertise

Technical depth across cloud platform architecture

AWS-led expertise across the full platform stack — with hands-on experience across European CSPs where sovereign, regulatory or strategic requirements demand it.

Platform Architecture

Multi-account foundations built to scale from day one

  • Account vending in under 10 minutes via AFT
  • Guardrails enforced across all OUs from day one
  • Centralized logging, audit trail & cost allocation
Control Tower AFT AWS Organizations Multi-account design EKS

Security & IAM

Zero-trust guardrails enforced through policy-as-code

  • SCPs blocking non-compliant actions automatically
  • Identity Center SSO rolled out across all accounts
  • Security posture auditable and reportable at any time
IAM & Identity Center SCPs Permission Boundaries Security Hub GuardDuty

IaC & Automation

Infrastructure deployed reproducibly across every environment

  • Full environments provisioned from a single command
  • GitOps pipelines with policy enforcement via OPA
  • No manual changes — everything version-controlled
Terraform Terragrunt OpenTofu GitLab CI/CD OPA

Networking

Hybrid & cross-border connectivity for enterprise workloads

  • Multi-VPC architectures with centralized egress
  • Private Direct Connect to on-prem & data centers
  • AWS China reachable via compliant transit paths
Transit Gateway Direct Connect BGP / GRE S2S VPN AWS China

Compliance & Governance

Regulatory frameworks embedded into the platform layer

  • BSI C5 & ISO 27001 evidence generated automatically
  • Policy-as-code prevents configuration drift before it happens
  • Audit-ready documentation at every infrastructure layer
BSI C5 ISO 27001 NIS2 GDPR Policy-as-code

European & Sovereign Cloud

Data residency and sovereignty requirements, by design

  • Data residency enforced at the infrastructure level
  • IONOS, OVHcloud & STACKIT alongside AWS
  • SAP workloads migrated to sovereign environments
IONOS Cloud OVHcloud STACKIT Sovereign cloud design SAP integration
Selected Projects

Recent work that signals enterprise depth

Selected engagements from recent years. Some details are anonymized under NDA.

Public sector

Secure AWS landing zone for a regulated organization

Delivered an audit-ready AWS landing zone with automated account vending, centralized logging and BSI C5-aligned guardrails — reducing manual provisioning time by 80% and establishing a foundation that passed a regulatory audit on first review.

Control TowerAFT OrganizationsBSI C5
Enterprise platform

Landing zone governance for >500 AWS accounts

Enabled fully automated self-service account provisioning across 500+ AWS accounts with 100% IaC coverage and policy-as-code enforcement — eliminating manual governance overhead and making quarterly audits predictable and repeatable.

500+ AccountsTerraform GitLabOPA
Hybrid cloud

SAP migration to AWS with hybrid integration

Migrated SAP workloads to AWS with zero downtime and maintained stable hybrid connectivity to SAP RISE — enabling the client to retire on-premises infrastructure on schedule and reduce hosting costs by 35%.

SAPDirect Connect Hybrid CloudEC2
Networking

Global SD-WAN between AWS and AWS China

Achieved stable, low-latency global connectivity bridging AWS commercial and AWS China regions — enabling the client to operate a unified platform across regulatory boundaries that previously required separate manual operations.

AWS ChinaTGW Connect BGPCisco c8000v
Modernization

Container platform for faster and safer releases

Cut release cycles from several weeks to days and removed all manual deployment bottlenecks — giving engineering teams full deployment autonomy on a production-ready EKS platform with zero unplanned outages in the first six months.

EKSFargate HelmGitLab CI/CD
Security

Cloud security & audit readiness across production accounts

Raised the Security Hub compliance score from below 50% to over 90% across production accounts within eight weeks — delivering an audit-ready evidence package that passed a subsequent external penetration test without critical findings.

Security HubConfig KMSAudit
Credentials

Certifications

Architecture work is built on delivery first. The certifications provide formal validation for regulated environments and procurement processes where it is required.

Amazon Web Services
AWS

AWS Certified Solutions Architect – Professional (SAP-C02)

The most comprehensive AWS architecture certification — enterprise-grade design, resilience, security and cost optimization at scale.

AWS

AWS Certified Solutions Architect – Associate (SAA-C03)

Core AWS architecture certification covering design, resilience, security and networking.

AWS

AWS Certified Data Engineer – Associate (DEA-C01)

AWS certification covering data pipeline design, analytics services and data governance at enterprise scale.

AWS

AWS Certified Cloud Practitioner (CLF-C01)

AWS cloud fundamentals: core services, security, pricing and architectural best practices.

Kubernetes / CNCF
CNCF

Certified Kubernetes Security Specialist (CKS)

Advanced CNCF certification focused on securing container-based applications and Kubernetes infrastructure in production.

CNCF

Certified Kubernetes Administrator (CKA)

Hands-on CNCF certification validating the ability to design, install, configure and manage production-grade Kubernetes clusters.

CNCF

Certified Kubernetes Application Developer (CKAD)

CNCF certification covering containerized application design, deployment and configuration for Kubernetes environments.

Cloud Platforms
IONOS

IONOS Cloud – Professional Cloud Architect

Professional cloud architecture certification for EU-sovereign infrastructure on the IONOS Cloud platform.

STACKIT

Certified STACKIT Cloud Engineer

STACKIT cloud engineering certification covering the sovereign German cloud platform by Schwarz Group — infrastructure, services and compliance for regulated European environments.

Azure

Microsoft Azure Fundamentals (AZ-900)

Microsoft Azure core services, compliance, security, pricing and support fundamentals.

Clients

What clients say

"Mostapha came in, assessed our existing AWS setup in a week and had a Control Tower landing zone running across our 40 accounts within six weeks. The audit trail and guardrails we now have would have taken our internal team months to build — and probably would have had gaps."
CF
Head of Cloud Infrastructure Financial services company · AWS Landing Zone engagement, 2025
"The security posture work was exactly what we needed before our ISO 27001 audit. No fluff — just a clear gap analysis, a prioritized remediation backlog, and someone who could actually implement the fixes rather than just write a report and disappear."
MR
CISO Regulated manufacturing group · Cloud Security engagement, 2024
"What stood out was the combination of deep AWS knowledge and the ability to work within our procurement and compliance constraints. Not every architect understands what it means to deliver for public sector — the documentation, the approval processes, the audit requirements."
TH
IT Director Public sector organization · Platform Architecture engagement, 2025
Contact

Start the conversation

Share the challenge, the environment and the outcome you need. That is enough to start a useful conversation.

Available for new projects

Let's talk

Project requests, architecture reviews, landing zones, governance — tell me what you need.

I don't just write reports and disappear. I design, build and implement — and stay until it works.
1
Send your inquiry Describe the environment and what you are trying to solve — takes 5 minutes.
2
Free intro call (30 min) We discuss scope, fit and timeline — no strings attached.
3
Clear proposal You get a concrete offer and next steps — no obligation.
Germany · Remote & on-site in DACH

Project inquiry

The initial consultation is free and without obligation — just a conversation about whether I can actually help.