AWS Cloud Security Architect [Remote]
Gdit
- Remote job
Public Trust: BI Full 6C (T4)
Requisition Type: Regular
Your Impact
Own your opportunity to support the missions that matter. From working with technologies like AI, cyber and cloud to careers in intelligence and health, we offer endless opportunities to apply your expertise to create a safer, smarter world while building new skills to propel your career forward.
Job Description
The CMM AWS Cloud Security Architect will work as part of an agile development team to build and support the modernization of enterprise-class software applications.
The successful candidate shall be capable of providing technical cloud security subject matter expertise to meet current and future security design and architecture requirements for IaaS, PaaS, and SaaS implementations. The candidate shall have experience with designing and implementing security measure to protect data as it moves from on-premises data center servers to cloud storage systems. The candidate shall have experience with network security and security compliance.
This role provides expert advisory services to ensure secure design and deployment of cloud-based systems, incorporating secure-by-design principles such as access control, encryption, and identity management. The Architect conducts thorough threat and vulnerability assessments, monitors risks, and ensures compliance with federal cybersecurity standards and Judiciary frameworks.
Key Responsibilities:
- Designing secure cloud architectures
- Performing risk assessments using enterprise tools
- Coordinating with ITSO and CISA to validate system security through independent evaluations.
- Creates essential security documentation, including System Security Plans, Business Continuity Analyses, and Disaster Recovery Plans
- Delivers a quarterly Cloud Security Roadmap
- Provides operational support to cover cloud firewalls, ACLs, SSL, API endpoints, authentication procedures, private image management, and secure network segmentation.
- Supports incident response planning
- Supports automation for legacy systems
- Ensures proper documentation of cybersecurity control artifacts
- Ensures continuous monitoring and secure data handling
- Engages in proactive risk mitigation
- Strengthens the security posture across production and non-production cloud environments within the CMSO ecosystem.
REQUIREMENTS
Education: Technical Training, Certification(s) or Degree required ; BA/BS strongly preferred. 4 years of general experience in information systems may be substituted in lieu of preferred degree.
Experience: 8+ years of specialized experience required
Container Security — Expert Level:
- Deep expertise in Amazon EKS security architecture : pod identity, multi-tier namespace isolation, and node group separation across security classification tiers
- Expert Kubernetes RBAC design and auditing: least-privilege ClusterRoles, service account hardening
- Strong expertise in Kubernetes NetworkPolicy
- Expert Pod Security Admission controls: restricted/baseline profile enforcement, Gatekeeper policy-as-code
- Full lifecycle container image security : ECR private registry, image tag immutability, Inspector Enhanced Scanning, cosign image signing, SBOM generation
- Expert GitLab CI/CD pipeline security : OIDC-based AWS authentication, build node egress restriction, pipeline-integrated scanning (Wiz, Trivy, Checkov, TestifySec), and immutable artifact promotion
- Experience implementing container performance monitoring using New Relic or equivalent (Prometheus, OpenTelemetry, Fluent Bit)
- Demonstrated experience designing FedRAMP High multi-tier web applications on EKS with tiered security classification boundaries
Network Security - Expert Level:
- Expert AWS VPC architecture : multi-tier subnet design, Transit Gateway, EKS hardening
- Deep experience with security groups, Network ACLs , and AWS Network Firewall : domain allowlist policies, and build node egress controls
- Expert VPC endpoint design: gateway and interface endpoints
- Expert AWS WAF
- Deep expertise in API Gateway security : designing private endpoints, JWT authorizers, resource policies, and mTLS
- Experience implementing AWS Direct Connect and Site-to-Site VPN with BGP route security and hybrid connectivity hardening
- Expert design of VPC Flow Log analysis pipelines using CloudWatch Logs Insights, Athena, and Splunk (SPL queries, correlation searches, network security dashboards)
Security Monitoring - Expert Level:
- Expert design of CloudWatch multi-account architectures : cross-account observability, centralized log aggregation, composite alarms, and metric filter-based real-time detection
- Experience integrating CloudTrail, GuardDuty, Security Hub, and Config across AWS Organizations with EventBridge-driven automated response
- Expert Splunk integration : CloudTrail, GuardDuty, VPC Flow Logs, and EKS audit log ingestion with high-fidelity correlation searches
Vulnerability Management - Expert Level:
- Expert design of multi-layer VM programs for containerized AWS workloads: Amazon Inspector (EC2, ECR Enhanced Scanning, Lambda, EKS workload association), pipeline-integrated image scanning, IaC scanning, and Kubernetes configuration assessment
- Deep experience with pipeline-integrated scanning tools : Tools such as Trivy and Grype for CVE detection, Syft for SBOM generation (CycloneDX), kube-bench for CIS Kubernetes Benchmark assessment
- Proficiency with AWS native VM tooling : Inspector , Security Hub finding aggregation, Systems Manager Patch Manager for EC2/EKS node OS patching, and Config conformance packs (NIST 800-53, FedRAMP High) for configuration vulnerability tracking
- Experience with enterprise VM platforms in federal environments: commercial CNAPPs for agentless cloud-native assessment and attack path analysis
- Expert runtime threat detection : GuardDuty EKS Runtime Monitoring, and correlation of runtime behavioral signals with static CVE findings for prioritized response
- Ability to design and measure VM program effectiveness metrics : MTTD and MTTR per severity tier, detection coverage gap analysis via threat-to-detection mapping
ATO and Compliance:
- Expert IAM least privilege : SCPs, permission boundaries, condition keys, and IAM Access Analyzer
- Demonstrated FedRAMP High ATO leadership: SSP authoring, NIST 800-53 rev5 control implementation statements, POA&M management, 3PAO assessment support, and continuous monitoring program design
Preferred Certifications:
AWS Certified Security - Specialty, Certified Kubernetes Security Specialist, and/or AWS Certified Solutions Architect - Professional
Security Clearance Level: Ability to pass a background check to obtain and maintain a position of Public Trust with the Administrative Office of the US Courts
Must be a US Person (Green Card Holder, US Permanent Resident Alien, Refugee, Asylee, US Citizen)
Location: Remote
At GDIT, the mission is our purpose, and our people are at the center of everything we do.
- Growth: AI-powered career tool that identifies career steps and learning opportunities
- Support: An internal mobility team focused on helping you achieve your career goals
- Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off
- Community: Award-winning culture of innovation and a military-friendly workplace
OWN YOUR OPPORTUNITY
Explore an enterprise IT career at GDIT and you’ll find endless opportunities to grow alongside colleagues who share your desire to drive operations forward.
#GDITLA
Work Requirements
Years of Experience
8 + years of related experience
* may vary based on technical training, certification(s), or degree
Certification
Certified Kubernetes Security Specialist (CKS) | Cloud Native Computing Foundation (CNCF) - Cloud Native Computing Foundation (CNCF)
AWS Certified Solutions Architect - Professional | Amazon Web Services (AWS) - Amazon Web Services (AWS)
AWS Certified Security - Specialty | Amazon Web Services (AWS) - Amazon Web Services (AWS)
Travel Required
Less than 10%
- ...fingerprinting and a drug screens due to the nature of their business Cloud Security Architect We are seeking an experienced Cloud Security Architect... ...design and drive security architecture across large-scale AWS environments. This is a highly strategic and hands-on role...Amazon Web ServiceFull timeRemote work
$130k - $170k
...As a Cloud Security Architect within Credera’s Security and Privacy capability group, you will serve as a senior subject matter expert responsible... ..., identity risks, and workload vulnerabilities across AWS and Azure environments Evaluate and implement Cloud Security...Amazon Web ServiceH1bRemote workFlexible hours2 days per week- ArdentMC seeks a remote Cloud Security Architect to design and enforce Zero Trust security across environments. Responsibilities include leading... ...degree in a relevant field is preferred, along with expertise in tools like AWS, Docker, and Kubernetes. #J-18808-Ljbffr ArdentMCAmazon Web ServiceRemote job
$138.2k - $172.8k
...Principal Cloud and AI Security Architect United States and 1 more (Remote) Job Info Job Identification 41609 Job Category Technology Posting Date... ...Hybrid Security : Expertise in securing AI workloads across AWS and Azure, and on-prem environments.Experience leading the...Amazon Web ServiceFull timeTemporary workPart timeWork experience placementInternshipSeasonal workRemote workShift work$146.2k - $243.6k
...birth parents. The Information Security team protects all of Grainger,... ...infrastructure is powered by cloud, on-premises, and SaaS platforms... ...s technology. As the security architect responsible for Grainger’s... ...demonstrated experience with AWS is a requirement, with functional...Amazon Web ServiceFull timeWork experience placementH1bLocal areaRemote workShift work$125k - $180k
A leading cybersecurity firm seeks a Senior Cloud Security Architect to join its Security Architecture team. This remote role involves designing... ...cross-functionally. Ideal candidates will have expertise in AWS, GCP, and cloud security tools. The position offers competitive...Amazon Web ServiceRemote job- A leading cloud security firm is seeking a Sr. Cloud Security Architect to act as a technical lead in pre-sales engagements. You will utilize your cloud security expertise across AWS, Azure, and GCP to design secure multi-cloud environments. Your role includes collaborating...Amazon Web ServiceRemote job
- Booker DiMaio, LLC is seeking a Senior Cloud Cybersecurity Specialist for a remote opportunity... .... The role involves implementing security controls, risk management, and compliance... ...requires knowledge of NIST standards and AWS security services. #J-18808-Ljbffr Booker...Amazon Web ServiceRemote job
- OEConnection LLC is looking for a Senior Cloud Security Architect to design and improve AWS security architecture. The role requires 7+ years of experience in cloud security, proficiency with AWS security services, and strong communication skills. This position offers...Amazon Web ServiceRemote job
- Overview Caesars Entertainment is seeking a Principal Cloud Security Architect to drive secure cloud architecture across AWS and GCP, ensuring security is integrated from code to cloud for Caesars Sportsbook, iGaming, and digital platforms. This role will embed security...Amazon Web ServiceEarly shift
- A leading cloud security firm is seeking a Cloud Security Architect to ensure Zero Trust enforcement across environments. This remote position demands strong AWS expertise and 10+ years in software development. Responsibilities include leading Zero Trust solutions and ensuring...Amazon Web ServiceRemote job
- KellyMitchell Group is seeking a Software Architect III in Denver, Colorado. This role involves designing and delivering secure, scalable platforms on AWS, and leading AI integration... ...experience with AWS, Terraform, and cloud application development. The position...Amazon Web ServiceRemote work
$128.1k - $239.6k
...working world. EY Infosec is seeking a Cloud Security consultant with expertise in cloud security... ...other cloud platforms such as GCP and AWS. Role summary This position is a Business... ...collaboration with product owners, architects, developers, DevOps, and other information...Amazon Web ServiceSummer holidayLocal areaFlexible hoursShift work- Internetwork Expert is seeking a Cloud Security Architect to support the U.S. Air Force Cloud One contract based in Boston, MA. This hybrid remote... ...in cybersecurity across multiple cloud platforms, including AWS and Azure. The successful applicant will lead efforts to...Amazon Web ServiceContract workRemote work
- Cloud Security Lead / Architect (Remote) Get AI-powered advice on this job and more exclusive features. Responsibilities: 10+ years of hands-on experience... ...cloud security, and compliance, with at least 5 years in AWS security. Expert-level knowledge of AWS security services,...Amazon Web ServiceRemote jobContract work
- A leading cloud security company is seeking an experienced Solutions Architect to join their team. In this field sales engineering role, you will engage with customers... ...Additionally, familiarity with cloud platforms such as AWS, Azure, and Google Cloud is essential, with...Amazon Web ServiceRemote job
$86.8k - $198k
Enterprise Cloud Security Architect The Enterprise Cloud Security Architect provides architecture leadership across Booz Allen’s enterprise. The role requires deep technical expertise across AWS, Azure, and GCP cloud platforms, shaping how engineering teams design and implement...Amazon Web ServiceFull timePart timeWork at officeLocal areaRemote work- This role supports the U.S. Air Force Cloud One Architecture and Common Shared Services... ...currently has an opening for a Cloud Security Architect . This position will coordinate across multiple areas as the program supports AWS, Azure, Google, and Oracle clouds. This...Amazon Web ServiceContract workFor contractorsInterim roleRemote work
- ...Temp‑to‑Hire, W‑2, fully remote position based in the U.S. The Cloud Security Architect will serve as a key technical resource in the Global Cyber... ...Minimum 2 years of experience with other cloud platforms (AWS, GCP, Oracle). Minimum 1 year of experience reviewing detailed...Amazon Web ServiceContract workTemporary workWork experience placementRemote workFlexible hours
- ...choose Ardent and make a difference with us. Ardent is seeking a Cloud Security Architect to join our team. This is a remote position . Position... ...environment Developing and maintaining secure deployments to AWS and multi-cloud environment and other tasks Scripting and...Amazon Web ServiceLocal areaRemote work
$125k - $180k
Sr. Cloud Security Architect (Remote) page is loaded## Sr. Cloud Security Architect (Remote)locations: USA - Remote, CAtime type: Full timeposted... ...tasks as required. **What You'll Need:** * Amazon Web Services (AWS) and Google Cloud Platform (GCP).* Cloud Security Posture...Amazon Web ServiceRemote jobWork experience placementWork at officeLocal area- Senior Cloud Security Architect- Cleveland, OH, Austin, TX or Atlanta, GA Job Description OEC provides software solutions to those who work in the... ...Role Summary Designs, implements, and continuously improves AWS security architecture. Partners with cloud engineering,...Amazon Web ServiceRemote workHome office
- Sr. Cloud Security Architect | CNAPP/CSPM/Presales (Remote) We are looking for a former hands-on cloud security practitioner ready to take technical... ...a Subject Matter Expert (SME) in cloud security covering AWS, Azure, and GCP, who can help our sales organization understand...Amazon Web ServiceRemote jobFull timeLocal area
- ...Data Management is seeking a mission‑driven Senior Zero Trust Cloud Security Architect to lead the design, implementation, and maturation of Zero... ...architectures, patterns, and implementation roadmaps across AWS, Azure, hybrid, and on‑premise environments. Lead the integration...Amazon Web ServiceFor contractorsLocal areaRemote work
- Description Summary We are seeking a hands‑on Cloud & Security Administrator / Cloud Solutions Architect to manage, secure, and optimize our cloud‑hosted SaaS and... ...role is responsible for designing and maintaining AWS infrastructure, supporting client‑hosted...Amazon Web ServiceLocal areaRemote work
$153k - $207k
...: Software Engineering Job Qualifications: Skills: AWS Cloud Computing, Cloud Computing, Cloud Security Certifications: None Experience: 8 + years of related... ...: No Job Description: The CMM AWS Cloud Security Architect will work as part of an agile development team to build...Amazon Web ServicePermanent employmentFull timeTemporary workWork at officeImmediate startRemote workWorldwideFlexible hours- ...environment, the contract-to-hire Cyber Security Architect will engineer, optimize, and maintain vulnerability... ...platforms with enterprise systems like AWS, CyberArk, and Splunk Required... ...Proficiency in web application scanning and cloud-native security tools Strong...Amazon Web ServiceContract workRemote work
- ...Enterprise Security Architect Location: Hybrid (3 days onsite, 2 days remote) About the Role We are seeking an experienced... ...Qualifications TOGAF certification. SABSA certification. Cloud security certifications such as AWS Security Specialty, Azure Security Engineer, or...Amazon Web ServiceRemote workShift work
- ...SECURITY ARCHITECT MILITARY FRIENDLY & PREFERRED - HOH SPONSOR SUMMARY Zermount Inc. is seeking a highly talented, technical hands‑on Security... ..., CICD. Designing and/or implementing security in Cloud (AWS required, Azure or GCP optional): Multi‑Cloud, Hybrid Cloud,...Amazon Web ServiceRemote work
- ...We are hiring an experienced security Architect who is responsible for designing and implementing security within our architecture. This role... ...and guide other engineers. Nice to have You are a certified AWS Solutions Architect. Experience with designing medical software...Amazon Web ServiceLive inLocal areaRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to AWS Cloud Security Architect [Remote]. Be the first to apply!
- cloud developer Remote
- senior principal cloud computing engineer Remote
- aws cloud infrastructure engineer Remote
- principal cloud computing engineer Remote
- informatica cloud developer Remote
- software engineer - cloud services Remote
- cloud architect Remote
- big data cloud engineer Remote
- aws cloud architect Remote
- senior cloud network engineer Remote

