Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cloud Security Architect

Openkyber

Job Role : Aws Cloud Security Engineer Location : Boston, MA, Arlington, VA, Atlanta, GA,:Austin, TX, Chicago, IL, Cleveland, OH: Experience: 10 Years Skills: This Senior Consultant role modernizes legacy workloads into cloud-native, resilient and observable AWS platforms. The consultant is expected to operate as an embedded AWS SME, provide hands-on implementation support, and create audit-ready technical documentation aligned to regulated Financial Services delivery expectations. Role Scope & Key Responsibilities:

  • Multi-Account Governance (WS-2): Design AWS Organizations landing zone with OU structure, Service Control Policies (SCPs), centralized logging (CloudTrail, VPC Flow Logs, AWS Config), and automated account vending for Security Lab foundation
  • Isolated Recovery Environment (WS-3): Architect IRE account with WORM vault locking (S3 Object Lock/Backup Vault Lock), cross-account/cross-region backup (3-2-1 strategy), AWS KMS CMKs, CyberArk break-glass integration, Amazon Macie data classification, AWS Network Firewall, Transit Gateway route isolation, and recovery orchestration
  • Clean Room Forensics: Design forensic investigation environment with network isolation, immutable evidence storage, and controlled access patterns
  • Security Lab Infrastructure: Establish Amazon EKS baseline and lab environment for testing security capabilities, threat simulation, and vulnerability assessments
  • Compliance & Audit: Design AWS Backup Audit Manager compliance framework, Route 53 DNS isolation, and hardened compute baselines (AMI/container hardening)
  • Documentation & Implementation: Author IRE & Clean Room Architecture & Design Document, Security Lab Architecture Document, lab operations guide, and account vending admin procedures
  • Security Agent Infrastructure (WS-1): Design and support AWS Security Agent cloud infrastructure implementation Secrets Management: Implement AWS Secrets Manager/Parameter Store integration with CyberArk for break-glass scenarios
Key Deliverables:
  • Multi-Account Landing Zone Architecture with OU/SCP design
  • IRE & Clean Room Architecture & Design Document
  • Security Lab Architecture Document
  • Backup Audit Manager compliance framework
  • Hardened compute baselines (AMIs, EKS node configurations)
  • Account vending automation and admin procedures Recovery orchestration runbooks
AWS Skills & Services Governance & Multi-Account Architecture:
  • AWS Organizations: OU structure design, SCP policies, consolidated billing, cross-account IAM strategies
  • AWS Control Tower: Landing zone automation, guardrails, Account Factory customization
  • AWS Service Catalog: Automated account vending, standardized resource provisioning
  • AWS Resource Access Manager (RAM): Cross-account resource sharing for Transit Gateway, Route 53 Resolver
Security & Compliance:
  • AWS IAM: Advanced policies, permission boundaries, IRSA (IAM Roles for Service Accounts), cross-account roles, break-glass access patterns
  • AWS KMS: Customer Managed Keys (CMKs), key policies, cross-account/cross-region key grants, envelope encryption
  • AWS Secrets Manager: Secret rotation, CyberArk integration, cross-account secret access
  • Amazon Macie: Sensitive data discovery, S3 bucket classification, compliance reporting
  • AWS Security Hub: Centralized security findings, compliance standards (CIS, PCI-DSS)
  • AWS GuardDuty: Threat detection, malware protection, runtime monitoring
  • AWS Network Firewall: Stateful/stateless rules, intrusion prevention, domain filtering
  • AWS WAF: Web application protection, managed rule groups
Backup & Disaster Recovery:
  • AWS Backup: Centralized backup management, WORM vault locking (Vault Lock), cross-account/cross-region backup, 3-2-1 backup strategy
  • AWS Backup Audit Manager: Compliance framework design, backup policy enforcement, audit reporting
  • Amazon S3: Object Lock (WORM compliance), versioning, cross-region replication, Glacier Vault Lock
  • AWS Elastic Disaster Recovery (DRS): Continuous replication, recovery orchestration, failover testing
Logging & Monitoring:
  • AWS CloudTrail: Multi-account trail design, log file validation, S3/CloudWatch Logs integration, event history analysis
  • Amazon CloudWatch: Centralized logging, log aggregation, metric filters, alarms, dashboards
  • VPC Flow Logs: Network traffic analysis, security group validation, threat detection
  • AWS Config: Configuration compliance, resource inventory, change tracking, conformance packs
Networking & Isolation:
  • Amazon VPC: Advanced networking, security groups, NACLs, VPC peering, PrivateLink
  • AWS Transit Gateway: Hub-and-spoke architecture, route table isolation, network segmentation
  • Amazon Route 53: DNS isolation, private hosted zones, DNSSEC, resolver rules
  • AWS PrivateLink: Service endpoint isolation, cross-account connectivity without internet exposure
Container & Compute Security:
  • Amazon EKS: Cluster hardening, pod security policies/standards, IRSA, network policies, secrets encryption, runtime security
  • Amazon ECR: Image scanning, vulnerability assessment, immutable tags, lifecycle policies
  • AWS Systems Manager: Patch Manager, Session Manager (bastion replacement), Parameter Store, hardened AMI automation
  • Amazon EC2: Hardened AMI creation, IMDSv2 enforcement, instance metadata security, EBS encryption
Forensics & Incident Response:
  • Amazon Detective: Security investigation, graph-based analysis, threat hunting
  • AWS Step Functions: Recovery orchestration workflows, automated incident response
  • Amazon EventBridge: Event-driven security automation, cross-account event routing
  • AWS Lambda: Automated remediation, forensic data collection, snapshot automation
Infrastructure as Code & Automation:
  • AWS CloudFormation: StackSets for multi-account deployments, nested stacks, drift detection
  • AWS CDK: Programmatic infrastructure definition, construct libraries for security patterns
  • AWS Service Catalog: Self-service account vending, compliance-approved resource templates
Cost Optimization & Governance:
  • AWS Cost Explorer: Cost allocation tags, backup storage optimization
  • AWS Budgets: Cost alerts, anomaly detection
  • AWS Trusted Advisor: Security and cost optimization recommendations Financial Services & Industry Skills
  • Large regulated financial-services delivery with formal change-control, audit and risk governance
  • Operational resilience expectations including RTO/RPO, multi-region DR and evidence for audit review
  • Awareness of applicable controls and regulations such as DORA, NIST CSF 2.0, PCI DSS, SEC cyber rules, RegSCI and SIFMU/FMI expectations where relevant
  • Ability to create Tech Risk-ready documentation including ADRs, runbooks, design docs, threat models and validation evidence
  • Clear communication with client engineering, security, SRE, data and platform stakeholders as an embedded SME
Certifications / Qualifications
  • AWS Certified Solutions Architect - Associate / Professional
  • AWS Certified Developer - Associate
  • AWS Certified DevOps Engineer - Professional preferred

For applications and inquiries, contact:View email address on us.fitly.work

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Cloud Security Architect in Arkansas County, AR vacancy
  •  ...Job Title: Senior SailPoint Identity Security Cloud (ISC) Engineer Location: Durham, NC, Orlando, FL, Columbia, SC, Atlanta, GA, Charlotte, NC, Tampa, FL, Raleigh, NC. Looking for W2 candidates. No C2C Job Summary We are seeking a Senior SailPoint Identity... 
    Suggested

    Openkyber

    Arkansas County, AR
    2 days ago
  •  ...Role: SAP Security Architect- RBAC framework, GRC solution in S4 HANA Mode of Hire:- Full Time/Subcon Visa:- Any Work Location:- Boise, Idaho(Onsite look for locals) JD Deep expertise with SAP security (10+ yrs). Demonstrated experience with SAP Security using RBAC... 
    Suggested
    Full time
    Local area

    Openkyber

    Arkansas County, AR
    2 days ago
  •  ...Job Title: Cyber Security Engineer Location: Remote (Contract) Our client is a premier global professional services and risk...  ..., integrating advanced threat monitoring systems, and securing cloud deployments to ensure stringent compliance standards are consistently... 
    Suggested
    Contract work
    Remote work

    Openkyber

    Arkansas County, AR
    2 days ago
  • $86.8k - $198k

    Enterprise Architect The Opportunity As an Enterprise Architect, you must be able to design architectural roadmaps for enterprise architecture...  ...at varying levels, including enterprise, segment, security, and solution architectures Possession of excellent interpersonal... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Stuttgart, AR
    1 day ago
  •  ...We are seeking an experienced Data Platform Engineer to architect, build, and operate our cloud-based data lakehouse platform. The role is responsible...  ...Collaboration Ensure the reliability, scalability, and security of the data platform across environments. Automate... 
    Suggested

    Openkyber

    Arkansas County, AR
    2 days ago
  •  ...AWS Cloud Solutions Engineer responsible for configuration, migration, and management of AIRS systems in AWS Cloud. On-site required first 2 weeks, optional remote after. Requirements: AWS expertise System migration experience Cloud configuration Large system... 
    Temporary work
    Remote work

    Department of Finance and Administration

    Arkansas County, AR
    24 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cloud Security Architect. Be the first to apply!