Gotyto logo
Salary
$180K–$215K
Hiring from
United States
Work type
Remote
Posted
Is this job info correct?

513,883 remote jobs, straight from company career pages

100% free · New jobs every hour

Show job description

Description

Quantum Sky seeking an AWS Cloud Architect to lead the expansion of our existing Google Cloud (GCP) platform into AWS. This role will take the platform’s proven Google Cloud architecture, security controls, and compliance posture and deliver an equivalent, production-ready AWS offering.

The ideal candidate combines deep hands-on AWS engineering expertise with experience implementing cloud environments subject to federal cybersecurity and compliance requirements such as FedRAMP, FISMA, DoD Risk Management Framework (RMF), NIST SP 800-53, or comparable regulated security frameworks.

This role requires strong knowledge of AWS cloud security, containers, Infrastructure as Code, automation, DevSecOps, and hybrid infrastructure. Candidates must be capable of translating business requirements into secure, compliant, and production-ready cloud architectures.

Responsibilities:

  • Design and implement secure, scalable, and highly available solutions on Amazon Web Services (AWS), including AWS GovCloud (US), that meet security and compliance requirements including FedRAMP, NIST 800-53, CMMC, CIS Benchmarks, and Zero Trust principles.
  • Lead the expansion of our GCP-based platform into AWS, translating its existing architecture, landing zone, and security controls into equivalent AWS services and design patterns.
  • Map GCP services and NIST SP 800-53 control implementations to their AWS equivalents, maintaining feature and control parity across both clouds and documenting control inheritance and evidence for ATO.
  • Refactor and extend the platform’s Terraform modules and CI/CD pipelines to support AWS deployments alongside the existing GCP implementation.
  • Lead technical discovery sessions and develop solution architectures aligned with customer requirements.
  • Design secure networking architectures using Amazon VPC, AWS Transit Gateway, security groups and network ACLs, AWS Network Firewall, Route 53, Elastic Load Balancing, NAT Gateways, VPC endpoints and AWS PrivateLink, and hybrid connectivity via AWS Direct Connect and Site-to-Site VPN.
  • Deploy and operate services such as Amazon EC2, Amazon EKS, Amazon ECS, Amazon S3, Amazon RDS, AWS Secrets Manager, AWS KMS, Amazon CloudWatch, AWS CloudTrail, AWS Config, AWS Security Hub, Amazon GuardDuty, and related AWS services.
  • Implement cloud security controls including least-privilege IAM, network segmentation, encryption and key management, centralized logging, monitoring, vulnerability management, and secure configuration.
  • Build and support containerized platforms using Amazon EKS and Amazon ECS.
  • Develop Infrastructure as Code (IaC) using Terraform or similar automation frameworks.
  • Design and implement CI/CD pipelines supporting infrastructure and application deployments.
  • Automate infrastructure provisioning, configuration management, and operational tasks.
  • Develop technical documentation, architecture diagrams, and implementation guides.
  • Troubleshoot complex infrastructure, networking, security, and application issues.
  • Support security assessment, Authorization to Operate (ATO), continuous monitoring, and POA&M remediation activities, including collection and maintenance of technical evidence.
  • Provide technical leadership and mentor junior engineers.
  • Collaborate with customers, project managers, and engineering teams throughout project lifecycles.

Qualifications

Required:

  • Bachelor’s degree in Computer Science, Information Systems, Engineering, or equivalent experience.
  • 7+ years of experience designing and implementing enterprise IT infrastructure.
  • 4+ years of hands-on AWS architecture experience.
  • Strong knowledge of AWS architecture, including IAM roles and policies, AWS Organizations, Service Control Policies, and AWS Control Tower multi-account strategy, Amazon VPC and Transit Gateway, network security, EC2, EKS, S3, CloudWatch and CloudTrail, AWS KMS, and Secrets Manager.
  • Proven hands-on experience developing and customizing AWS landing zone templates using AWS Control Tower, Landing Zone Accelerator (LZA) on AWS, Account Factory for Terraform (AFT), or Customizations for Control Tower (CfCT), including multi-account structure, SCP guardrails, centralized logging and security services, and network baselines for regulated workloads.
  • Strong hands-on experience with Terraform or comparable Infrastructure as Code technologies.
  • Experience implementing CI/CD pipelines using GitHub Actions, GitLab CI, Jenkins, AWS CodeBuild, and AWS CodePipeline.
  • Strong Linux administration and troubleshooting skills.
  • Experience with scripting and automation using Python, Bash, or similar technologies.
  • Hands-on experience supporting systems governed by FedRAMP, FISMA, DoD RMF, NIST SP 800-53, or comparable federal cybersecurity frameworks.
  • Hands-on experience with containers and orchestration, including Docker, Amazon EKS, and Amazon ECS, and container security best practices.
  • Understanding of security control implementation, assessment evidence, continuous monitoring, vulnerability management, and remediation processes.
  • Strong understanding of cloud security concepts, including IAM, network segmentation, encryption, key management, logging, monitoring, vulnerability management, and secure configuration.
  • Ability to produce clear technical documentation and communicate effectively with engineering, security, compliance, and customer stakeholders.

Desired:

  • Working knowledge of Google Cloud Platform (GCP), including GKE, Shared VPC, Cloud IAM, Cloud KMS, and Security Command Center, sufficient to understand the existing GCP platform and translate it to AWS.
  • Advanced Kubernetes experience, including Red Hat OpenShift, container networking (CNI), service mesh technologies (e.g., Istio), and policy enforcement (e.g., OPA Gatekeeper, Kyverno).
  • Multi-cloud implementation experience across AWS and GCP (and/or Azure), including:
    • Identity and access: federated SSO and centralized identity (e.g., Okta, Entra ID, AWS IAM Identity Center), workload identity federation, and consistent least-privilege models across clouds.
    • Networking: cross-cloud connectivity (VPN, interconnect/Direct Connect), IP address management, DNS, and segmentation in hybrid and multi-cloud topologies.
    • Security tooling: cloud security posture management (CSPM), centralized logging and SIEM integration (e.g., Splunk, Sentinel), and vulnerability and compliance scanning across cloud providers.
  • AWS Certified Solutions Architect – Professional
  • AWS Certified Security – Specialty
  • Certified Kubernetes Administrator (CKA)
  • HashiCorp Terraform Associate
  • Security certifications such as CISSP, CCSP, or Security+

About Quantum Sky

Compensation:

  • Compensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary range for this position is typically between $180,000-$215,000. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.

Benefits:

  • Highlights of our benefits include Health/Dental/Vision, 401(k) match, Paid Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and parental leave.

The world the mission operates in is going post-quantum, contested, and machine-speed. Quantum Sky engineers the advantage across cyber, networks, software, and quantum because the mission demands dominance, not parity. We don't follow the map. We draw it.

At Quantum Sky, we believe that success starts with our people. We foster a collaborative, innovative, and mission-driven environment where every team member plays a critical role in shaping the future of technology. Are you ready to join #TeamQuantumSky?

Quantum Sky Engineering LLC is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, [sexual orientation, gender identity,] national origin, disability, status as a protected veteran, or any characteristic protected by applicable law.

Similar jobs

Apply for this job