Cloud Security Architect
Openkyber
Job Role : Aws Cloud Security Engineer Location : Boston, MA, Arlington, VA, Atlanta, GA,:Austin, TX, Chicago, IL, Cleveland, OH: Experience: 10 Years Skills: This Senior Consultant role modernizes legacy workloads into cloud-native, resilient and observable AWS platforms. The consultant is expected to operate as an embedded AWS SME, provide hands-on implementation support, and create audit-ready technical documentation aligned to regulated Financial Services delivery expectations. Role Scope & Key Responsibilities:
- Multi-Account Governance (WS-2): Design AWS Organizations landing zone with OU structure, Service Control Policies (SCPs), centralized logging (CloudTrail, VPC Flow Logs, AWS Config), and automated account vending for Security Lab foundation
- Isolated Recovery Environment (WS-3): Architect IRE account with WORM vault locking (S3 Object Lock/Backup Vault Lock), cross-account/cross-region backup (3-2-1 strategy), AWS KMS CMKs, CyberArk break-glass integration, Amazon Macie data classification, AWS Network Firewall, Transit Gateway route isolation, and recovery orchestration
- Clean Room Forensics: Design forensic investigation environment with network isolation, immutable evidence storage, and controlled access patterns
- Security Lab Infrastructure: Establish Amazon EKS baseline and lab environment for testing security capabilities, threat simulation, and vulnerability assessments
- Compliance & Audit: Design AWS Backup Audit Manager compliance framework, Route 53 DNS isolation, and hardened compute baselines (AMI/container hardening)
- Documentation & Implementation: Author IRE & Clean Room Architecture & Design Document, Security Lab Architecture Document, lab operations guide, and account vending admin procedures
- Security Agent Infrastructure (WS-1): Design and support AWS Security Agent cloud infrastructure implementation Secrets Management: Implement AWS Secrets Manager/Parameter Store integration with CyberArk for break-glass scenarios
- Multi-Account Landing Zone Architecture with OU/SCP design
- IRE & Clean Room Architecture & Design Document
- Security Lab Architecture Document
- Backup Audit Manager compliance framework
- Hardened compute baselines (AMIs, EKS node configurations)
- Account vending automation and admin procedures Recovery orchestration runbooks
- AWS Organizations: OU structure design, SCP policies, consolidated billing, cross-account IAM strategies
- AWS Control Tower: Landing zone automation, guardrails, Account Factory customization
- AWS Service Catalog: Automated account vending, standardized resource provisioning
- AWS Resource Access Manager (RAM): Cross-account resource sharing for Transit Gateway, Route 53 Resolver
- AWS IAM: Advanced policies, permission boundaries, IRSA (IAM Roles for Service Accounts), cross-account roles, break-glass access patterns
- AWS KMS: Customer Managed Keys (CMKs), key policies, cross-account/cross-region key grants, envelope encryption
- AWS Secrets Manager: Secret rotation, CyberArk integration, cross-account secret access
- Amazon Macie: Sensitive data discovery, S3 bucket classification, compliance reporting
- AWS Security Hub: Centralized security findings, compliance standards (CIS, PCI-DSS)
- AWS GuardDuty: Threat detection, malware protection, runtime monitoring
- AWS Network Firewall: Stateful/stateless rules, intrusion prevention, domain filtering
- AWS WAF: Web application protection, managed rule groups
- AWS Backup: Centralized backup management, WORM vault locking (Vault Lock), cross-account/cross-region backup, 3-2-1 backup strategy
- AWS Backup Audit Manager: Compliance framework design, backup policy enforcement, audit reporting
- Amazon S3: Object Lock (WORM compliance), versioning, cross-region replication, Glacier Vault Lock
- AWS Elastic Disaster Recovery (DRS): Continuous replication, recovery orchestration, failover testing
- AWS CloudTrail: Multi-account trail design, log file validation, S3/CloudWatch Logs integration, event history analysis
- Amazon CloudWatch: Centralized logging, log aggregation, metric filters, alarms, dashboards
- VPC Flow Logs: Network traffic analysis, security group validation, threat detection
- AWS Config: Configuration compliance, resource inventory, change tracking, conformance packs
- Amazon VPC: Advanced networking, security groups, NACLs, VPC peering, PrivateLink
- AWS Transit Gateway: Hub-and-spoke architecture, route table isolation, network segmentation
- Amazon Route 53: DNS isolation, private hosted zones, DNSSEC, resolver rules
- AWS PrivateLink: Service endpoint isolation, cross-account connectivity without internet exposure
- Amazon EKS: Cluster hardening, pod security policies/standards, IRSA, network policies, secrets encryption, runtime security
- Amazon ECR: Image scanning, vulnerability assessment, immutable tags, lifecycle policies
- AWS Systems Manager: Patch Manager, Session Manager (bastion replacement), Parameter Store, hardened AMI automation
- Amazon EC2: Hardened AMI creation, IMDSv2 enforcement, instance metadata security, EBS encryption
- Amazon Detective: Security investigation, graph-based analysis, threat hunting
- AWS Step Functions: Recovery orchestration workflows, automated incident response
- Amazon EventBridge: Event-driven security automation, cross-account event routing
- AWS Lambda: Automated remediation, forensic data collection, snapshot automation
- AWS CloudFormation: StackSets for multi-account deployments, nested stacks, drift detection
- AWS CDK: Programmatic infrastructure definition, construct libraries for security patterns
- AWS Service Catalog: Self-service account vending, compliance-approved resource templates
- AWS Cost Explorer: Cost allocation tags, backup storage optimization
- AWS Budgets: Cost alerts, anomaly detection
- AWS Trusted Advisor: Security and cost optimization recommendations Financial Services & Industry Skills
- Large regulated financial-services delivery with formal change-control, audit and risk governance
- Operational resilience expectations including RTO/RPO, multi-region DR and evidence for audit review
- Awareness of applicable controls and regulations such as DORA, NIST CSF 2.0, PCI DSS, SEC cyber rules, RegSCI and SIFMU/FMI expectations where relevant
- Ability to create Tech Risk-ready documentation including ADRs, runbooks, design docs, threat models and validation evidence
- Clear communication with client engineering, security, SRE, data and platform stakeholders as an embedded SME
- AWS Certified Solutions Architect - Associate / Professional
- AWS Certified Developer - Associate
- AWS Certified DevOps Engineer - Professional preferred
For applications and inquiries, contact:View email address on us.fitly.work
- ...Required Skills & Experience (Prioritized): AWS AI & Bedrock Security (5+ years Cloud, 12+ years AI Security): Direct hands-on experience configuring AWS Bedrock Guardrails, model access policies, content moderation filters, and foundation model protections. AWS...Suggested
$74 - $78 per hour
...Role Summary A senior-level AWS Cloud Security Engineer is responsible for designing, implementing, and maintaining security controls within AWS cloud environments supporting federal compliance standards such as FedRAMP Moderate. The role involves hands-on technical...SuggestedHourly payRemote work$131k - $197k
...opportunities and leave your mark, come join us.THE ROLEAs a Senior Security Architect at Everpure, you will drive the critical mission of embedding robust security by design across our global cloud, infrastructure, and platform environments. Partnering closely with engineering...SuggestedWork at officeFlexible hours$185 per hour
...Security Architect Enzo Health is a healthcare technology company transforming home health operations through purpose-built artificial intelligence... ...Python, TypeScript/Node, Go, or Rust ~ Experience securing cloud infrastructure (AWS preferred) and modern stacks: containers,...SuggestedFull timeWork at officeRemote workRelocation$147.8k - $236.4k
Role DescriptionThe delivery Enterprise Architect (EA) serves as the primary technical driver... ...more of the following Adobe Experience Cloud solution categories:Adobe Analytics or... ...Storage, Structured/Unstructured Data, Security and Data Ingress/Egress.Experience leading...SuggestedFull timeTemporary workLocal areaRemote workWorldwide- ...reached the point where we need a dedicated architect — not just an engineer — to own the... ...that sits above the infrastructure and security substrate owned by IT/Security, and below... ...deep hands-on Salesforce expertise (Sales Cloud, Service Cloud; CPQ and Revenue Cloud...Local area
- ...Delivery Enterprise ArchitectThe delivery Enterprise Architect (EA) serves as the primary technical driver for delivering high quality... ...or implementing three or more of the following Adobe Experience Cloud solution categories:Adobe Analytics or Customer Journey AnalyticsAdobe...
$122.6k
...CDM Smith is seeking a Senior Enterprise Architect to join our Corporate Business Technology... ...in alignment with our Microsoft-centric, cloud-first IT strategy. The Senior Enterprise... ...connect business capabilities with scalable, secure, and integrated technology solutions....Work experience placementH1bRemote work- ...Data Warehouses (EDW), Clinical Data Integration platforms, and cloud-based analytics environments. The ideal candidate will partner... ...modelling tools such as ER/Studio, ERwin, or IBM InfoSphere Data Architect ~ Solid understanding of SCD Type 1 and Type 2...Hourly payContract work
$144.8k - $261.45k
...crafting, building, and operationalizing scalable identity and SaaS security capabilities enterprise-wide. This technical role depends on... ...Adobe Acrobat Studio, Adobe Express, Adobe Firefly, Creative Cloud, Adobe Experience Platform, Adobe Experience Manager, and GenStudio...Full timeTemporary workLocal areaWorldwide- ...Kubernetes, CI/CD automation, Infrastructure as Code (IaC), and cloud-native technologies. The ideal candidate will have over 10 years... ...track record of designing, implementing, and managing scalable, secure, and highly available cloud infrastructure and DevOps platforms....Local area
$168.2k - $310.1k
...Hunting Team to conduct proactive and iterative hunts through cloud and enterprise networks, endpoints, and datasets to detect malicious... ...of Linux, MacOS, and Windows operating systems. Cloud Security: Extensive experience in administering, attacking, or defending...Full timeTemporary workLocal areaWorldwide- ...Senior Security Engineer American Fork, Utah, United States LVT is redefining how businesses operate in the physical world, moving... ...security events, and how exposure across our infrastructure, cloud, and endpoints is identified, prioritized, and remediated. You...Full timeWork at officeImmediate startFlexible hours
- ...innovation to help clear the way for millions of Americans to achieve more.About the RoleThe Sr Cloud Infrastructure Engineer owns the design, delivery, and operation of secure, reliable cloud infrastructure supporting Happen Bank's applications and technology platforms....Full timeWork at officeLocal areaRemote workRelocationFlexible hours
- DescriptionWe are looking for an experienced Cloud Engineer to lead the design, reliability,... .... This role focuses on building secure, resilient, and high-performing AWS environments... ...effectively in technical discussions with senior engineers and architects.Job typePerm
- ...at the intersection of financial data, cloud-scale infrastructure, and trust, and it... ...native platform designed for resilience, security, and developer velocity. It’s a chance to... ...workloads from on-premise data centers to GCP.Architect for Reliability: Design and implement...Work at office
- ...are seeking a Principal Platform Engineer to help shape the technical direction of our cloud platform capabilities and serve as a senior technical partner across engineering, security, and architecture. This role operates at an organizational level, driving platform...
$120k - $180k
...leave your mark, come join us.THE ROLEAs a Security Operations Engineer in the Global... ...reduce our global attack surface across cloud, endpoint, and SaaS environments. You will... ...moving beyond simple task execution to architecting automated, risk-based outcomes that enable...Work at officeFlexible hoursShift work$89.41k - $136.72k
The Security Operations Engineer II is responsible for leading day-to-day operations of the physical security systems and applications. In this role, the Security Operations Engineer will provide organizational expertise in usage of security equipment, train and monitor...Full timeRemote work$67.61 - $84.51 per hour
...Description Product Security Engineer Full-time Lehi, UT You'll be joining Adobe on a contract opportunity, employed... ...Here's What Else Might Help You Out Experience with cloud environments (AWS, Azure, GCP) and API security testing. Hands...Hourly payPermanent employmentFull timeContract work- ...Personal Lines team has already shown what’s possible, standing up cloud infrastructure and delivering a production-ready application in... ...the stack, integrate AI and third-party services, and ship in a secure cloud environment. You’ll join a small, high-trust team where...Work experience placement
$73k - $95k
...performance management, troubleshooting, root cause analysis, and security risk reduction. This team serves as a systems integration... ...Production Support Provide Level 3 support for on-premises and cloud-hosted systems Maintain reliability, performance, and...Temporary work$118.3k - $244.85k
...teams and suppliers to optimize spend across Adobe's indirect categories.What you'll doLead end-to-end commercial strategy for global cloud providers (e.g., AWS, Azure, GCP), including complex enterprise agreements, consumption optimization, and long-term capacity...Full timeContract workTemporary workLocal areaWorldwideFlexible hours$140k - $200k
...Proven experience in backend development: TS/Node (required) Direct experience with GCP and knowledge of AWS, Azure, or other cloud providers Efficiency in ideation and implementation, prioritizing tasks based on urgency and impact Preferred: Experience with...Work at office- ...TypeScript React Python Go PostgreSQL Docker REST APIs Protobuf /gRPC Distributed systems Linux CI/CD Cloud platforms No candidate is expected to have experience in every area. Backgrounds That Translate Well Engineering...Relocation package
- ...and enhancing our tooling for pain free security & compliance. This will require out of the... ...best practices.Work in a hybrid cloud infrastructure, considering the implementation... ...redundant, and observable servicesExpertise in architecting messaging systems, distributed data...
$87 per hour
...solution design, workflow automation, and governance to deliver secure, compliant, and intelligent employee experiences using Now... ...Flow Designer flows to support IRM processes. Work closely with architects and business analysts to translate requirements into technical...Contract workH1bLocal area$180k - $200k
...connect across an organization while respecting enterprise-grade security, governance, permissions, and ethical walls.Innovation is only... ...for developing and delivering scalable, secure, and innovative cloud-based systems that are the heart of NetDocuments’ Document...Immediate startFlexible hours- ...much more than talk the talk. We're looking for an Application Security Engineer joining our IT & Security team to build and mature our... ...your sleeves, solving real-world security problems, and making cloud products safer by design, this role is for you. What you...Local area
- ...independently manage and scale the platform Act as a technical advisor, helping client stakeholders understand best practices in: Cloud-native infrastructure o AI/ML platform operations o Reliability, performance, and cost optimization Ensure smooth handoff...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cloud Security Architect. Be the first to apply!


