Skill 29 · Knowledge Base For Startups
Subchapter 29.238
references/learn/general/what-does-it-mean-to-be-an-aws-admin-at-a-startup.mdMarkdown10 KBView on GitHub
Guest Post by Faisal Farooq, Startup Solutions Architect and Abhi Singh, Sr. Security Solutions Architect
Most startups work at a high velocities, which can mean that release timelines often overshadow the security foundation. A frequent byproduct of this fast-paced culture can mean that the responsibilities of an Account Admin are not as defined or the role is distributed among several team members. As the team size grows and the company gains momentum, a startup’s customers often require the company to enforce least privilege and clearly define who and what an Admin should do, leaving founders to backtrack architecture-level decisions that were made early on, creating friction and disrupting the business. In this blog post, we will define what an Account Admin’s responsibilities should look like, the training that person, referred to hereafter as an Admin, should have to be effective in their role, and the continuous impact they make on the company.
An Account Admin is the second most powerful user in the company after the root account. As a result, it’s important to define what that person or entity can do to assign appropriate privileges to the person. Some of the key responsibilities include:
As mentioned above, the Admin is a trusted advisor for the development teams and founders. Some of the key tenets for a solid Account Admin are:
An Account Admin should be the internal trusted advisor and a subject matter expert on AWS. He or she needs to stay up-to-date on recent service announcements and help management realize the most efficient and effective usage of their AWS investment. Day-to-day activities for an Admin include:
An AWS Admin strives to keep the startup’s environment closely aligned to AWS best practices relative to the Services consumed and Well-Architected Framework (opens in a new tab), paying close attention to the following:
Security is a top priority for the Account Admin. As a result, they are responsible for performing the following key activities to maintain the startup’s environment to the required security standard:
The AWS Security Pillar (opens in a new tab) provides detailed guidance on how to configure an Account. Consider testing your configuration using the Well-Architected labs in a sandbox environment for more hands-on training.
External regulations and standards may apply to the startup, along with internal ones. The Admin is responsible for identifying appropriate mechanisms, such as AWS Audit Manager (opens in a new tab), AWS Config (opens in a new tab), or AWS Security Hub (opens in a new tab) to enforce the security and compliance reporting requirements such as NIST 800-83, HIPAA, FedRamp, PCI etc. to enable continuous compliance. They may also automate the compliance reporting to appropriate parties. AWS provides several services and solutions that can enable the Admin achieve the compliance and assurance goals (opens in a new tab). Based on the needs of the startup, the Admin can leverage these turn-key solutions and guides that align with AWS’s guidance.
Depending on the level of understanding of AWS and the startup’s business, the Admin continuously reviews the existing environment and identifies improvement opportunities. They should review the performance metrics against the target and suggest improvements, identify the bottlenecks and recommend alternate strategies. They may also test the automated deployment and rollback strategies, and leverage and promote infrastructure as code and CI/CD pipeline-based deployment. The Admin will regularly review security related issues and develop automated mitigation mechanisms such as alternate architectures for repetitive items, and lastly, maintain Runbooks and Playbooks for common tasks highlighted above. The AWS Well-Architected Framework has an Operational Excellence pillar (opens in a new tab) that can help Admin’s with continuous improvement.
AWS routinely provides guidance and architecture patterns, based on trends across the industry. This guidance along with the items listed below will help Admins invent and simplify on behalf of your customers:
Startup management often grapple with defining and outlining an AWS Admin’s responsibilities. With these resources, founders and stakeholders can hire and develop the best, while maintaining an appropriate level of separation of duties that often plague a startup’s growth and scalability. By following the practices defined above, AWS Admins can balance performing day-to-day activities effectively, help their startups adopt good security hygiene practices often required as part of third-party assurance, and optimize infrastructure costs.
The AWS Startups Content Marketing Team collaborates with startups of all sizes and across all sectors to deliver exceptional content that educates, entertains, and inspires.
Faisal Farooq is Solutions Architect at AWS on the Startups team. He routinely hosts customer open forums to help Startups to discuss the industry wide challenges. In his prior role, he worked with Fortune 100 companies as a cybersecurity consultant. He is passionate about helping startups use AWS more efficiently and securely.
Abhi Singh is a Senior Solution Architect who specializes in security and compliance within AWS. He has over 20 years of experience in information technology consulting and leadership experience.