Building a security-first digital foundation on AWS for a major telecommunications company

10 min read
Published: 30 September 2026
Last updated: 30 September 2026
Share

Overview

A leading US telecommunications company is one of the largest wireless carriers in the United States, serving over 142 million customers across Consumer, Business and Indirect Dealer channels. A critical business function underpinning the customer’s sales operations is its commission and compensation management system, which calculates and disburses over $2.81 billion annually in payouts to retail representatives, indirect dealers (Walmart, Costco, Target, Best Buy), the customer's prepaid wireless brand partners and Customer Care agents.

Historically, the customer relied on a legacy commission calculation system, a third-party COTS (Commercial Off-The-Shelf) application, to perform commission calculations. The legacy commission calculation system operated on an unsupported on-premises infrastructure, creating significant operational risk. The system processed approximately 224 million transactions per year across three major commission domains: Employee Commission System (ECS), Dealer Commission System (DCS) and Global Commission System (GCS). Data flowed from upstream systems through SCMS (Sales Commission Management Solution) adapters into the legacy commission calculation system for calculation, then downstream into the Commissions Data Warehouse (CDW) for payroll processing and reporting.

The scale of the financial data spanning $1.7 billion in Consumer/CARE payouts, $110 million in Dealer payouts and $1 billion in rebates administration demanded enterprise-grade security, auditability and compliance with SOX (Sarbanes-Oxley) and internal InfoSec governance standards. Any data breach, unauthorized access, or calculation integrity failure could have severe financial and regulatory consequences for the organization. the customer needed a cloud-native architecture that could handle this scale while providing a fundamentally stronger security posture than the legacy on-premises model.

The Challenge

The customer faced several critical security and operational challenges with the legacy commission calculation system environment that necessitated a complete architectural transformation:

  • Unsupported on-premises security risk: The legacy commission calculation system was running on an unsupported on-premises version, meaning no vendor security patches, vulnerability fixes, or compliance certifications were available. This created an expanding attack surface with each passing month and put the customer at risk of non-compliance with SOX audit requirements and internal security mandates
  • Static credential exposure: The legacy system relied on hardcoded credentials and long-lived secrets embedded in configuration files for database connections, API integrations and batch job orchestration. This violated the principle of least privilege and created a persistent risk of credential theft, lateral movement and unauthorized data access across the commission processing pipeline
  • Lack of granular auditability: The on-premises architecture provided limited logging and tracing capabilities. It lacked a centralized, immutable audit trail of who accessed sensitive compensation data, when calculations ran and what data transformations occurred. This made SOX audit compliance labor-intensive and forensic investigation of anomalies extremely difficult
  • Flat network topology and no environment isolation: Production compensation calculation workloads, development environments and testing labs shared network boundaries with insufficient segmentation. A security incident in a non-production environment could potentially propagate to production systems processing billions of dollars in financial payouts
  • Manual vulnerability management: Patching, vulnerability scanning and compliance assessments were manual, infrequent processes with no automated enforcement. Security configuration drift was common and the customer had no real-time visibility into the security posture of its computational infrastructure
  • Third-party vendor dependency: Reliance on the legacy commission calculation system’s proprietary platform meant the customer had limited visibility into the vendor’s own security practices, limited ability to enforce encryption standards and no control over the security architecture of the compensation engine itself

Common Delivery Platform (CDP) challenges:

The customer runs its software delivery on the Common Delivery Platform (CDP), a shared GitLab-based CI/CD platform. Thousands of pipeline jobs a day, application builds, security scans, container packaging and infrastructure deployments — execute on CDP-provided runners. Those runners see the most sensitive material a delivery organisation has: proprietary source code, build-time secrets, registry credentials, cloud deployment credentials and the artifacts that ultimately reach production. The security posture of the runner fleet therefore sets a ceiling on the security posture of everything the customer ships.

The fleet is hosted entirely on in us-west-2, inside the customer's private, non-internet-facing VPC landing zone and is built on top of the enterprise-approved RHEL 9 and Windows Server 2022 base images.

The Solution

Built SPACE (Sales Performance Analytics and Computational Engine), a fully cloud-native commission calculation platform on AWS, implementing a defense-in-depth security architecture across six critical layers:

  • End-to-end encryption with AWS KMS: All data at rest is encrypted using AES-256 via AWS Key Management Service (KMS) across Amazon S3 data lake buckets, Amazon RDS metadata databases and temporary Amazon EMR EBS volumes. All data in transit is protected with TLS 1.2+ using custom EMR Security Configurations with dedicated certificates for Hadoop/Hive inter-node communication
  • Zero-trust identity and access management: SPACE eliminated 100% of static credentials by adopting IAM instance profiles and ephemeral token delegation (sts: AssumeRole) for all compute workloads—AWS Step Functions, Lambda functions and EMR clusters. Enterprise Single Sign-On via Entra ID/SAML federation ensures that only authenticated, authorized operators can access production systems
  • Multi-account isolation and network segmentation: Production workloads operate in dedicated Sensitive Data (SD) AWS accounts, fully isolated from Non-Production (NPE) development and testing environments, with a separate SEC-PRD account for centralized security governance. All EMR clusters and RDS instances are deployed in private VPC subnets with Security Groups and NACLs enforcing strict ingress/egress policies. Zero compute nodes have direct public internet exposure
  • Automated compliance and vulnerability management: Continuous policy enforcement via Security360/PacBot evaluates all infrastructure against security baselines. Automated monthly vulnerability scans cover 100% of persistent EC2/RDS infrastructure with automated patching cycles. S3 bucket policies enforce mandatory tagging, lifecycle rules and access logging
  • Comprehensive observability and SIEM integration: AWS CloudTrail captures every API call and administrative action. Amazon CloudWatch provides real-time metrics, log aggregation and threshold-based alerting. VPC Flow Logs and Lambda-based pipelines forward security telemetry into centralized Splunk SIEM for event correlation, anomaly detection and 7-year audit retention
  • Secure ephemeral compute: EMR clusters are provisioned on-demand (~15 minutes), execute commission calculations using pre-configured security profiles and terminate upon completion—minimizing the persistent attack surface

Common Delivery Platform (CDP) Solution:

CDP replaced the static runner estate with an immutable, ephemeral, autoscaling fleet on AWS and driven entirely from GitLab CI. Two tiers: a small set of hardened runner-manager EC2 instances that hold no workload and disposable worker instances launched from EC2 Auto Scaling groups that run the jobs and are then destroyed.

Challenge FacedSolution
Static cloud credentials in CI/CDGitLab OIDC identity tokens exchanged with Vault for short-lived AWS credentials, per environment.
Container escape to instance credentialsIMDSv2 enforced with metadata hop limit 1, plus a least-privilege worker instance profile with no runtime AWS credentials.
Configuration drift on build hostsImmutable Packer-baked AMIs with a 7-day deregistration lifecycle; hosts are replaced, never patched.
Public-registry dependency and rate limitsVetted images pre-baked into the AMI from the internal registry, with authenticated pulls and a pre-flight availability check.
Upgrading the fleet without breaking buildsTwo-batch blue/green rollout across AZs, pause-and-drain of the outgoing generation, smoke test before tag promotion.
Shadow changes outside GitMerge-request-gated pipelines, branch-scoped environment access, GitLab environments per batch/size, no console path.
Bursty demand vs. idle costTime-of-day and weekday/weekend warm-pool schedules per runner size, on a zero-baseline Auto Scaling group.
Shared-account AWS API throttlingReplaced per-boot EC2 Describe* calls with instance-metadata lookups and lengthened the autoscaler poll interval, removing the fleet's contribution to the account-wide rate limit.

The Impact

Qualitative results

SPACE’s AWS security architecture delivered transformational qualitative outcomes for the customer: the complete elimination of third-party vendor security dependency by replacing the legacy commission calculation system with a fully the customer-controlled, ; enterprise-wide adoption of zero-trust principles with no static credentials anywhere in the commission processing pipeline; seamless SOX audit compliance through immutable, centralized audit trails with 7-year retention; real-time security posture visibility replacing manual, periodic assessments; and a zero-recorded data breach track record across all production compensation payout cycles processing $2.81B+ annually.

Quantitative results

  • End-to-end encryption with AWS KMS: All data at rest is encrypted using AES-256 via AWS Key Management Service (KMS) across Amazon S3 data lake buckets, Amazon RDS metadata databases and temporary Amazon EMR EBS volumes. All data in transit is protected with TLS 1.2+ using custom EMR Security Configurations with dedicated certificates for Hadoop/Hive inter-node communication
  • Zero-trust identity and access management: SPACE eliminated 100% of static credentials by adopting IAM instance profiles and ephemeral token delegation (sts: AssumeRole) for all compute workloads—AWS Step Functions, Lambda functions and EMR clusters. Enterprise Single Sign-On via Entra ID/SAML federation ensures that only authenticated, authorized operators can access production systems
  • Multi-account isolation and network segmentation: Production workloads operate in dedicated Sensitive Data (SD) AWS accounts, fully isolated from Non-Production (NPE) development and testing environments, with a separate SEC-PRD account for centralized security governance. All EMR clusters and RDS instances are deployed in private VPC subnets with Security Groups and NACLs enforcing strict ingress/egress policies. Zero compute nodes have direct public internet exposure
  • Automated compliance and vulnerability management: Continuous policy enforcement via Security360/PacBot evaluates all infrastructure against security baselines. Automated monthly vulnerability scans cover 100% of persistent EC2/RDS infrastructure with automated patching cycles. S3 bucket policies enforce mandatory tagging, lifecycle rules and access logging
  • Comprehensive observability and SIEM integration: AWS CloudTrail captures every API call and administrative action. Amazon CloudWatch provides real-time metrics, log aggregation and threshold-based alerting. VPC Flow Logs and Lambda-based pipelines forward security telemetry into centralized Splunk SIEM for event correlation, anomaly detection and 7-year audit retention
  • Secure ephemeral compute: EMR clusters are provisioned on-demand (~15 minutes), execute commission calculations using pre-configured security profiles and terminate upon completion—minimizing the persistent attack surface

Common Delivery Platform (CDP) Solution:

CDP replaced the static runner estate with an immutable, ephemeral, autoscaling fleet on AWS and driven entirely from GitLab CI. Two tiers: a small set of hardened runner-manager EC2 instances that hold no workload and disposable worker instances launched from EC2 Auto Scaling groups that run the jobs and are then destroyed.

MetricBefore (Legacy System)After (SPACE on AWS)
Data encryption coveragePartial / vendor-dependent100% at rest (AES-256 KMS) and in transit (TLS 1.2+)
Static/hardcoded credentialsMultiple across config filesZero (0) — 100% IAM roles and ephemeral tokens
Environment isolationShared network boundaries100% multi-account isolation (SD, NPE, SEC-PRD)
Public internet exposureSome components exposedZero (0) direct public access to compute/DB
Audit trail coveragePartial, manual collection100% API traceability via CloudTrail + CloudWatch
Audit log retentionLimited7-year retention in centralized SIEM/Splunk
Vulnerability scan coverageManual, periodic100% automated monthly scans (Tenable)
Open critical (P1) security violationsPeriodic findingsZero (0) open P1 violations in production
Security incident response SLAHours< 15 minutes (P1), < 30 minutes (P2)
Data breach incidentsN/AZero (0) recorded breaches
Annual financial data protected$2.81B+ in payouts$2.81B+ with full encryption and access control
Transaction volume secured224M+ transactions/year224M+ with end-to-end security controls
Compute attack surfacePersistent on-prem serversEphemeral EMR clusters (~15 min lifecycle)
Vendor license fees eliminatedOngoing Legacy System contracts$0 — fully in-house AWS-native platform

Notes

SPACE represents a strategic shift from a vendor-dependent, on-premises compensation management model to a fully AWS-native, security-first architecture owned and operated by the customer’s engineering teams. The project was executed by 4 dedicated SCRUM teams running 2-week sprint cycles, with 12 domain teams coordinating weekly deployments.

Key architectural decisions that strengthened the security posture include: (1) choosing AWS Step Functions for orchestration, which provides built-in execution logging and state machine traceability; (2) leveraging Amazon EMR’s native security configuration framework for certificate-based encryption rather than retrofitting third-party encryption layers; (3) designing the S3 data lake with bucket-level policies and VPC endpoints rather than relying on network-level controls alone; and (4) implementing a dedicated SEC-PRD account for centralized security policy management, decoupled from application workload accounts.

The architecture also supports the customer’s broader commission ecosystem, including SCMS (Sales Commission Management Solution) adapters, Metro Dealer Commissions and downstream integration with the Commissions Data Warehouse (CDW) and Payroll systems. Security controls are applied consistently across all integration points, ensuring no data leaves the encrypted, access-controlled boundary without proper authorization.

The migration from the legacy commission calculation system to SPACE also eliminated vendor contract and license fees for an unsupported on-premises COTS package, delivering both security and cost benefits. The operational support model maintains only 25–30 monthly tickets, demonstrating the security architecture's reliability and stability under production load.

Average Cost Savings (USD)

The migration from the legacy commission calculation system to SPACE on AWS eliminated ongoing vendor contract and license fees for the unsupported on-premises COTS (Commercial Off-The-Shelf) compensation management package. While exact dollar figures are proprietary, the cost savings span multiple dimensions:

  • Vendor license elimination: Complete removal of legacy system annual licensing, maintenance and support fees across ECS, DCS and GCS commission domains. Enterprise ICM platforms at this scale (processing $2.81B+ in annual payouts across 224M+ transactions) typically carry annual license costs in the range of $2M–$5M+
  • On-premises infrastructure retirement: Decommissioning of legacy on-premises servers, storage and associated data center costs (power, cooling, physical security, hardware refresh cycles). Migration to AWS pay-per-request (DynamoDB) and on-demand EMR compute models ensures the customer pays only for actual computation time
  • Security operations efficiency: Automated vulnerability scanning, compliance monitoring (Security360/PacBot) and centralized SIEM integration reduced manual security operations effort by an estimated 60–70%, freeing security engineering resources for higher-value work
  • Audit and compliance cost reduction: Automated, immutable audit trails with 7-year retention eliminated weeks of manual evidence collection previously required for each SOX audit cycle, reducing compliance preparation costs significantly
  • Incident response cost avoidance: Zero recorded data breaches across all production compensation cycles represents significant cost avoidance. Industry benchmarks estimate the average cost of a data breach at $4.45M, with financial services breaches averaging higher

AWS Services Deployed

  • Amazon EMR (Elastic MapReduce) with Spark
  • Amazon S3 (Data Lake)
  • Amazon RDS
  • AWS Step Functions
  • AWS Lambda
  • AWS KMS (Key Management Service)
  • Amazon VPC
  • AWS IAM
  • AWS CloudTrail
  • Amazon CloudWatch (Logs, Metrics, Alarms)
  • AWS WAF (Web Application Firewall)
  • Amazon CloudFront
  • VPC Flow Logs
  • AWS Security Groups
  • Network ACLs
  • Amazon DynamoDB
  • AWS STS (Security Token Service)

Services deployed for Common Delivery Platform :

  • Amazon EC2
  • Amazon EC2 Auto Scaling (Auto Scaling groups and launch templates)
  • Amazon EBS (encrypted gp3 volumes and snapshots)
  • Amazon Machine Images
  • Amazon VPC (private subnets, security groups, NAT egress)
  • AWS Identity and Access Management (instance profiles and roles)
  • Instance Metadata Service v2
  • AWS Key Management Service (EBS encryption)
  • AWS Systems Manager (SSM Agent for managed instance access)
  • Amazon EC2 key pairs. Region: us-west-2.
Cloud and Ecosystem AWS Case study Building a security-first digital foundation on AWS for a major telecommunications company