Two functions, one organisation: CCoE and Platform Team
Section titled “Two functions, one organisation: CCoE and Platform Team”Before the role model is discussed, a structural fundamental decision is needed — one that in practice is often conflated: a Cloud Team consists of two functionally separate areas that do different things and require different competencies.
The Cloud Centre of Excellence (CCoE) defines what applies. It is responsible for governance, policies, standards, the service catalogue, and supporting application teams through consulting and enablement. It answers the question: “What must and may cloud environments look like?” The CCoE is the guardian of the framework.
The Cloud Platform Team implements how. It builds and operates the technical platform: Landing Zone, network infrastructure, automation, self-service platforms, monitoring of platform components. It translates the CCoE’s requirements into technical reality.
Both functions can be performed by the same people in smaller organisations — but the separation of responsibilities must remain explicit. Without this separation, governance decisions get silently replaced by implementation decisions, or governance documents that nobody implements.
In the role model below, roles are assigned accordingly: CCoE Lead, Cloud Architect, Security Engineer, and Enablement Specialist belong primarily to the CCoE. Platform Engineer and Operations Engineer belong primarily to the Platform Team. FinOps Analyst works closely with both.
The 7-role model
Section titled “The 7-role model”A fully staffed CCoE covers seven core roles. In smaller organisations, roles can be combined — but the function must be covered, even if one person takes on several.
| Role | Core responsibility | FTE (mid-sized organisation) |
|---|---|---|
| CCoE Lead | Strategy, stakeholder management, roadmap | 1.0 |
| Cloud Architect | Reference architectures, design decisions, landing zone | 1.0–2.0 |
| Platform Engineer | IaC module library, CI/CD templates, landing zone operations | 1.0–2.0 |
| Cloud Security Engineer | IAM governance, policy-as-code, DevSecOps | 1.0 |
| FinOps Analyst | Cost optimisation, tagging, showback/chargeback | 0.5–1.0 |
| Cloud Enablement Specialist | Training programme, Communities of Practice, Cloud Champions | 0.5–1.0 |
| Operations Engineer (SRE) | Observability, incident response, runbooks | 0.5–1.0 |
Minimum staffing to start transformation: 4–5 FTE (CCoE Lead + Architect + Platform Engineer + Security + FinOps/Enablement combined). With fewer than 4 FTE, a structural bottleneck emerges immediately.
Role profile: CCoE Lead
Section titled “Role profile: CCoE Lead”Profile: Experienced IT leader with cloud understanding and strong stakeholder management capability. Must be able to conduct CIO-level strategic conversations and coordinate technical teams simultaneously.
Responsibilities:
- Programme ownership of the cloud transformation
- Reporting line: CIO (direct)
- Preparation and facilitation of the Cloud Strategy Board
- Escalation point for cross-team blocking issues
- KPI reporting and transformation progress
Common hiring mistakes:
- Purely technical profile without leadership experience: leads to absent stakeholder engagement
- Pure leadership profile without cloud understanding: loses credibility with the technical team
- Internal promotion without cloud background: risky when cloud knowledge must be built at the same time
Role profile: Cloud Architect
Section titled “Role profile: Cloud Architect”Profile: Senior engineer with deep platform understanding. Knows STACKIT architecture principles, networking, security architecture, and migration architecture patterns.
Responsibilities:
- Reference architectures for recurring workload types (web apps, databases, batch jobs, streaming)
- Technical consulting for workload teams during design
- Landing zone architecture and continued development
- Architecture Decision Records (ADRs) for platform-relevant decisions
Role profile: Platform Engineer
Section titled “Role profile: Platform Engineer”Profile: Hands-on IaC expert. Writes Terraform modules, builds CI/CD templates, operates the landing zone daily.
Responsibilities:
- IaC module library (paved roads for standard resources)
- CI/CD pipeline templates for workload teams
- Landing zone operations and updates
- Guardrail implementation and testing
Example output: A Terraform module for a standard STACKIT SKE cluster configuration that any workload team can use without needing to understand the networking and security details themselves.
Role profile: Cloud Security Engineer
Section titled “Role profile: Cloud Security Engineer”Profile: Security specialist with cloud background. Understands IAM, policy-as-code, DevSecOps, and the regulatory requirements of the organisation.
Responsibilities:
- IAM governance: role concept, service account standards, PAM implementation
- Policy-as-code: Terraform Sentinel or OPA for automated guardrails
- Security scanning integration into CI/CD pipelines
- Regulatory compliance mapping (GDPR, TISAX, BAIT, etc.)
- Incident response for security incidents in the cloud
Role profile: FinOps Analyst
Section titled “Role profile: FinOps Analyst”Profile: IT controller or finance professional with cloud cost model understanding. Understands both finance requirements and technical cost optimisation levers.
Responsibilities:
- Monitor and escalate tagging compliance
- Create monthly showback reports
- Identify optimisation potential (idle resources, right-sizing)
- Configure budget alerts and anomaly detection
- Develop FinOps maturity along Inform → Optimise → Operate
Staffing strategies
Section titled “Staffing strategies”Strategy 1: Internal redeployment Suitable internal employees are released for CCoE roles. Advantage: organisational context already known, no onboarding. Risk: cloud competency must be built up, can be slower.
Strategy 2: External recruitment Cloud experts are newly hired. Advantage: competency immediately available. Risk: onboarding takes time, market for cloud talent is competitive.
Strategy 3: Hybrid (recommended) CCoE core of 1–2 internal leaders + 2–3 external cloud specialists. Internal: organisational context and stakeholder relationships. External: technical cloud depth and transformation experience. After 12 months: knowledge transfer, more internal people.
Strategy 4: Partner-supported start Begin with a STACKIT partner or system integrator who temporarily covers CCoE roles while internal capacity is being built. More cost-intensive but faster to operational readiness.
Common mistakes
Section titled “Common mistakes”Staffing too late: CCoE build-up begins while migration teams are already starting. Result: no standards for early workloads, later remediation required.
Wrong profile for CCoE Lead: Purely technical profiles without business stakeholder capability cannot conduct strategic dialogue with CIO and CFO.
FinOps too small: 0.2 FTE for FinOps is not enough. Cost optimisation is not a part-time task — it can deliver significant cloud budget savings when taken seriously.
Practical steps
Section titled “Practical steps”- Role inventory: Which of the 7 roles can be filled internally? Which must be filled externally?
- Release plan: Clarify with department heads who can be released for CCoE roles
- Create role profiles and start the HR process for external recruitment
- Partner assessment: Which STACKIT partners can temporarily cover CCoE roles?