Multi-Account AWS Landing Zone
Problem: Single-account AWS environments share blast radius across all teams and provide no policy enforcement boundary between environments.
Solution: Designed a four-OU organization with 8 SCPs, GuardDuty org-wide threat detection, centralized CloudTrail, and IAM Identity Center for federated access across all accounts.