Cloud Network Security Architect - AWS / Zero Trust
$94.25k - $215.05kCapgemini
Choosing Capgemini means choosing a company where you will be empowered to shape your career in the way you’d like, where you’ll be supported and inspired by a collaborative community of colleagues around the world, and where you’ll be able to reimagine what’s possible. Join us and help the world’s leading organizations unlock the value of technology and build a more sustainable, more inclusive world.
About The Job You're Considering
The Cloud Network Security Architect is responsible for designing, implementing, and governing secure cloud network architectures across hybrid and multi‑cloud environments. This role ensures the confidentiality, integrity, and availability of enterprise systems by defining security‑by‑design network frameworks aligned with business, compliance, and risk management objectives.
Your Role
- Enterprise Zero Trust Network Architect: implement Zero Trust network architecture, including segmentation, least-privilege access, and consistent policy enforcement across users, workloads, and services in hybrid environments.
- Network Security Design: Design and validate secure on-prem and cloud networking patterns (VPC/VNet, subnets, routing, TGW/peering, ingress/egress) using cloud-native controls and enterprise platforms.
- Cross-Functional Requirements & Architecture Translation: Partner with application/platform/infrastructure teams to capture connectivity and security requirements (ports/protocols, data flows, trust boundaries) and translate them into actionable security architectures.
- Firewall & Segmentation Strategy Owner: Define and standardize firewall policies and segmentation models, providing clear guidance on use of Palo Alto/Prisma vs. cloud-native mechanisms (SG/NSG, NACLs, route controls).
- Architecture Governance & Adoption : Lead design reviews, threat modeling, and exception handling; produce and maintain standards, reference designs, and architecture decision records to drive secure-by-design outcomes.
- Operational Enablement & Continuous Improvement: Collaborate with perimeter defense/SecOps to streamline rule discovery, risk review, approvals, and deployments (including automation); support troubleshooting and optimization for performance and resiliency.
Your Skills And Experience
- 10+ years of experience in network and security architecture, with strong focus on cloud platforms.
- Deep expertise in cloud networking concepts: routing, DNS, load balancing, NAT, private connectivity, and network segmentation.
- Hands‑on experience securing AWS and/or Azure networking services (VPC/VNet, Gateway, Firewall, Private Link, NSGs, Route Tables).
- Strong understanding of network security technologies: firewalls, WAF, IDS/IPS, DDoS, proxy, and micro‑segmentation.
- Experience implementing zero‑trust and identity‑centric network access models.
- Proficiency with Infrastructure as Code and automation tools (Terraform, Ansible, CloudFormation).
- Solid understanding of TCP/IP, BGP, IPSec, TLS, and network encryption mechanisms.
- Experience working in regulated and compliance‑driven environments.
- Cloud certifications (AWS Certified Security – Specialty, Azure Security Engineer, CCSP).
- Experience with multi‑cloud or large‑scale cloud migration programs.
- Knowledge of SASE, CASB, and secure access service edge architectures.
- Familiarity with SIEM/SOAR and security monitoring integrations.
- Experience supporting DevSecOps and CI/CD security integration.
The base compensation range for this role in the posted location is: $94,248 - $215,050 .
Capgemini provides compensation range information in accordance with applicable national, state, provincial, and local pay transparency laws. The base compensation range listed for this position reflects the minimum and maximum target compensation Capgemini, in good faith, believes it may pay for the role at the time of this posting. This range may be subject to change as permitted by law.
The actual compensation offered to any candidate may fall outside of the posted range and will be determined based on multiple factors legally permitted in the applicable jurisdiction.
These may include, but are not limited to: Geographic location, Education and qualifications, Certifications and licenses, Relevant experience and skills, Seniority and performance, Market and business consideration, Internal pay equity.
It is not typical for candidates to be hired at or near the top of the posted compensation range.
In addition to base salary, this role may be eligible for additional compensation such as variable incentives, bonuses, or commissions, depending on the position and applicable laws.
Capgemini offers a comprehensive, non-negotiable benefits package to all regular, full-time employees. In the U.S. and Canada, available benefits are determined by local policy and eligibility and may include:
- Paid time off based on employee grade (A-F), defined by policy: Vacation: 12-25 days, depending on grade, Company paid holidays, Personal Days, Sick Leave
- Medical, dental, and vision coverage (or provincial healthcare coordination in Canada)
- Retirement savings plans (e.g., 401(k) in the U.S., RRSP in Canada)
- Life and disability insurance
- Employee assistance programs
- Other benefits as provided by local policy and eligibility
Important Notice: Compensation (including bonuses, commissions, or other forms of incentive pay) is not considered earned, vested, or payable until it becomes due under the terms of applicable plans or agreements and is subject to Capgemini’s discretion, consistent with applicable laws. The Company reserves the right to amend or withdraw compensation programs at any time, within the limits of applicable legislation.
Disclaimers
Capgemini is an Equal Opportunity Employer encouraging inclusion in the workplace. Capgemini also participates in the Partnership Accreditation in Indigenous Relations (PAIR) program which supports meaningful engagement with Indigenous communities across Canada by promoting fairness, accessibility, inclusion and respect. We value the rich cultural heritage and contributions of Indigenous Peoples and actively work to create a welcoming and respectful environment. All qualified applicants will receive consideration for employment without regard to race, national origin, gender identity/expression, age, religion, disability, sexual orientation, genetics, veteran status, marital status or any other characteristic protected by law.
This is a general description of the Duties, Responsibilities and Qualifications required for this position. Physical, mental, sensory or environmental demands may be referenced in an attempt to communicate the manner in which this position traditionally is performed. Whenever necessary to provide individuals with disabilities an equal employment opportunity, Capgemini will consider reasonable accommodations that might involve varying job requirements and/or changing the way this job is performed, provided that such accommodation does not pose an undue hardship. Capgemini is committed to providing reasonable accommodation during our recruitment process. If you need assistance or accommodation, please reach out to your recruiting contact.
Please be aware that Capgemini may capture your image (video or screenshot) during the interview process and that image may be used for verification, including during the hiring and onboarding process.
Click the following link for more information on your rights as an Applicant in the United States.
Capgemini is a global business and technology transformation partner, helping organizations to accelerate their dual transition to a digital and sustainable world, while creating tangible impact for enterprises and society. It is a responsible and diverse group of 340,000 team members in more than 50 countries. With its strong over 55-year heritage, Capgemini is trusted by its clients to unlock the value of technology to address the entire breadth of their business needs. It delivers end-to-end services and solutions leveraging strengths from strategy and design to engineering, all fueled by its market leading capabilities in AI, generative AI, cloud and data, combined with its deep industry expertise and partner ecosystem.
$160k - $190k
...Trusted Internet Connections 3.0 Cloud Network Security Architect Location: Fully Remote (East Coast) Clearance: Public Trust, Secret... ...network environments in AWS with an emphasis on Trusted Internet... ...(IaC), hybrid connectivity, and Zero Trust/TIC‑aligned security controls...Amazon Web ServiceCloudFull timeRemote work- A leading cloud security firm is seeking a Cloud Network Security Architect to design and maintain secure network environments in AWS. The role requires expertise in deploying Palo Alto VM-Series... ..., and a solid understanding of Zero Trust principles. Applicants should...Amazon Web ServiceCloudRemote work
- Palo Alto Networks, Inc. is seeking an experienced domain consultant for network security transformation in Seattle, WA. This role involves providing technical expertise... ...security solutions with a focus on the Zero Trust journey. Requirements include over 6 years in...Suggested
$170.6k - $390k
...career in information security! The opportunity The Senior Network Security Architect is a strategic and hands... ...across on‑premises, cloud, and hybrid environments... ...experience in Zero Trust and Network security... ...network security expertise (AWS, Azure, GCP) Experience...Amazon Web ServiceCloudSummer holidayRemote workFlexible hours- ...Security Architect This role will heavily emphasize in-depth... ...of infrastructure and network security and a capability... ...Vulnerability, ZTNA, and cloud native firewall/access.... ...experience? Azure/AWS/GCP. 80% Azure, 20% GCP. ZTNA (zero trust network access) isn't commonly...Amazon Web ServiceCloudWork experience placement
- ...looking for a Principal Network Architect in the Greater Seattle... ...network. Using a zero trust and advanced network segmentation... ...focus on designing secure, scalable, efficient... ...hybrid on-premise and cloud ecosystem. Design... ...networking services in AWS and Azure. Proven experience...Amazon Web ServiceCloudWork at officeRemote work
- The Walt Disney Company is seeking a Security Engineer to design secure architecture solutions for its global technology ecosystem... ...Architecture & Engineering and experience with public cloud security, including AWS and Azure. The candidate will lead secure design...Amazon Web ServiceCloud
- ...Zscaler ZIA/ZPA and Zero Trust Architecture -... ...Zscaler (ZIA/ZPA) and secure access... ...eliminating legacy network assumptions, and delivering... ...SASE frameworks. Architect DIA‑first strategies... ...Familiarity with cloud security... ...architectures across Azure, AWS, GCP. Exposure to...Amazon Web ServiceCloudShift work
$121.1k - $190.1k
...Are you a security architect who enjoys both designing secure systems and building... ...implementation of secure application, network, and cloud architectures across AWS and Azure environments. You will... ..., logging, monitoring, and zero-trust principles. ~ Familiarity with...Amazon Web ServiceCloudWork at office$128.1k - $239.6k
...Infosec is seeking a Cloud Security consultant with expertise... ...such as GCP and AWS. Role summary This position... ...with product owners, architects, developers, DevOps, and... ...Management (IAM), network security, firewalls, audit... ..., while building trust in capital markets. Enabled...Amazon Web ServiceCloudSummer holidayLocal areaFlexible hoursShift work- Overview We are recruiting for a Network Architect for an upcoming client. The... ...OIG enclave, data center and cloud network architectures,... ...operations required to maintain secure and reliable enterprise network... ...Provide expertise with Azure and AWS cloud network technologies...Amazon Web ServiceCloudPermanent employmentWork experience placement
- ...Principal Cloud Security Architect About the Role What if your deep... ...cloud architectures across AWS, Azure, and GCP for security... ...Review IAM configurations, network segmentation, resource policies... ...multi-cloud environments, zero-trust architecture, or high-...Amazon Web ServiceCloudOngoing contractContract workFreelanceRemote workFlexible hours
- About the Role As a Mid-Level Security Architect, you will support the GIS Security... ...CompTIA Security+, GSEC, CCSP, AWS/Azure security associate) are... ...requirements. Practical experience with network security, firewall rules, endpoint protection, cloud platforms, and identity...Amazon Web ServiceCloudLocal areaWorldwide
- A leading robotics firm in Bellevue, Washington, is seeking a Senior Cloud Network Engineer (Architect) to design and manage secure multi-cloud network infrastructures, primarily using AWS, Azure, and Google Cloud. The ideal candidate will have extensive cloud network engineering...Amazon Web ServiceCloud
- ...technology firm is seeking a Cloud Network Engineer with DevOps experience... ...infrastructures focusing on AWS, Azure, and Google Cloud... ...in multi-cloud networking and security, proven experience in workload... ...work collaboratively with cloud architects and enhance network security...Amazon Web ServiceCloud
- ...based in Washington is seeking a Sr. Cloud Network Engineer (Architect). The ideal candidate will have extensive... ...engineering, particularly with AWS, Azure, and Google Cloud Platform. Key... ...responsibilities include architecting and managing secure cloud networks, automating...Amazon Web ServiceCloud
- A leading cloud solutions provider in Bellevue, WA seeks a Sr. Cloud Network Engineer (Architect) to architect and manage secure cloud network infrastructures. The ideal candidate will have extensive experience with AWS, Azure, and Google Cloud, and expertise in Terraform...Amazon Web ServiceCloud
- ...technology services company is seeking a Senior Cloud Network Engineer to design, deploy, and manage cloud network infrastructures across AWS, Azure, and Google Cloud. The candidate... ...optimize network performance and enforce security policies using cloud-native tools. Ideal...Amazon Web ServiceCloud
- ...Network Engineer Key Responsibilities: Architect and design enterprise-grade network... ...corporate offices, and cloud connectivity.... ...Engineer and maintain secure network... ...networking (Azure, AWS) and hybrid environments... .... Knowledge of Zero Trust architecture and network...Amazon Web ServiceCloud
- ...term contract Job Summary The Cloud Network Engineer with DevOps... ...infrastructure with a strong focus on AWS, Azure, and Google Cloud... ...expertise in multi-cloud networking, security, and workload migration to... .... Key Responsibilities Architect, deploy, and manage secure cloud...Amazon Web ServiceCloudLong term contractPermanent employmentContract workLocal area
- Nordstrom is seeking a Senior Security Engineer based in Seattle to manage network security controls. The role requires expertise in cloud security (AWS, Azure, GCP) and automation. Responsibilities include implementing zero-trust policies, building automation pipelines...Amazon Web ServiceCloud
- ...Security Engineer – Architecture & Engineering... ...applications, cloud platforms, and enterprise... ...with engineers, architects, and business... ...threats, including Zero Trust Architecture, cloud... ...environments (e.g., AWS, Azure, Google... ...Active Directory), and networking technologies (e.g....Amazon Web ServiceCloudWork experience placement
- A global entertainment leader is seeking a Security Engineer with strong expertise in Security Architecture and Engineering. The role involves... ...s operations. Candidates should have prior experience securing cloud environments and possess excellent communication skills to...Cloud
$162k - $235k
...We're searching for a Senior Cloud Security EngineerYou will be part of the... ...clouds such as like AWS, Azure, or GCP Manage the... ...Authentication, Authorization, Zero-Trust, and their application to cloud... ...management, supply-chain security, network security, and use of mTLS and...Amazon Web ServiceCloudWork at officeLocal area3 days per week- ...critical part of Salesforce's Cyber Security Operations Center (CSOC). As... ...(MBI) for a Moderate Public Trust position with the U.S. federal... ...of complex systems and Cloud environments (AWS, GCP, Azure). Technical knowledge of network fundamentals and common Internet...Amazon Web ServiceCloudLocal area
$126.3k - $160.05k
...Position: Senior Cloud Solution Architect Job... ...channel partner network. This role operates... ...Microsoft Azure and/or AWS), partner... ...cloud, data, AI, and security solutions through... ...Engagement Act as a trusted advisor to key... ...~ Knowledge of Zero Trust principles,...Amazon Web ServiceCloudHourly payFull timeTemporary workWork experience placementWork at officeLocal areaRemote work- ...Lead Network Designer The Boeing Company is currently... ...-scale, resilient, secure network architectures across... ...-site, data center, cloud, and hybrid network solutions... ...simultaneously Architect and document network... ...: Amazon Web Services (AWS) Advanced/Professional,...Amazon Web ServiceCloudLocal areaFlexible hours
$142k - $220.5k
...of highly skilled security and infrastructure... ...and automating the network security controls... ...deep expertise in cloud security, identity... ...closely with engineers, architects, and platform... ..., cloud (AWS, Azure, GCP), and... ...Implement and maintain zero-trust network access (ZTNA...Amazon Web ServiceCloud$148.5k - $223.9k
...ambition meets action. Tech meets trust. And innovation isn't a... ...critical part of Salesforce's Cyber Security Operations Center (CSOC). As... ...of complex systems and Cloud environments (AWS, GCP, Azure). Technical knowledge of network fundamentals and common Internet...Amazon Web ServiceCloudLocal area$124.6k - $168.2k
...for an AI Solution Architect. The AI Solution... ...evolution of AI and cloud-native systems... ...inference workloads on AWS. Operating as the... ...frameworks, and security controls that ensure... ..., and designs zero-trust security boundaries... ...strategies, and VPC/network segmentation. Define...Amazon Web ServiceCloudWork at officeMonday to Thursday
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cloud Network Security Architect - AWS / Zero Trust. Be the first to apply!
- aws cloud infrastructure engineer Seattle, WA
- remote cloud architect Seattle, WA
- senior cloud engineer Seattle, WA
- cloud architect Seattle, WA
- entry level cloud engineer Seattle, WA
- cloud engineering manager Seattle, WA
- cloud engineer remote Seattle, WA
- principal cloud engineer Seattle, WA
- senior principal cloud computing engineer Seattle, WA
- cloud operations engineer Seattle, WA

