Cloud Security Architect (AWS / Azure / GCP)
FyerxJob Description
This is a remote position.
Cloud Security Architect (AWS / Azure / GCP)
Job Details
- Employment Type: Contract
- Work Mode: Remote
- Location: Offshore
- Total Experience Required: 8 to 12 years
- Relevant Experience Required: 5+ years of dedicated cloud security architecture experience across public cloud infrastructures
- Mandatory Certification: Certified Information Systems Security Professional (CISSP), CCSP, AWS Certified Security - Specialty, or Microsoft Certified: Azure Security Engineer Associate
Job Summary
We are seeking an experienced Cloud Security Architect to design, govern, and secure our enterprise multi-cloud infrastructure. The ideal candidate will establish cloud security blueprints, architect zero-trust landing zones, secure containerized microservices, and build guardrails to automate compliance and protect cloud-native applications from sophisticated threats.
Key Responsibilities
- Design and govern cloud security architectures across public cloud platforms (AWS, Azure, and GCP), establishing foundational multi-tenant landing zones and zero-trust perimeters.
- Configure Identity and Access Management (IAM) strategies, defining least-privilege access rules, role-based controls (RBAC), multi-factor authentication (MFA), and federated identity lifecycles.
- Implement cloud data protection layers, managing end-to-end cryptography, key management services (KMS), hardware security modules (HSM), and data-loss prevention (DLP) rules for data at rest and in transit.
- Secure containerized microservices environments, designing runtime security boundaries, image vulnerability scanning protocols, and network policy controls for Kubernetes (EKS/AKS/GKE).
- Integrate Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platforms (CWPP), writing automated policy-as-code scripts to enforce security configuration standards.
- Collaborate with DevSecOps engineering teams to embed automated security testing utilities, static/dynamic application analysis (SAST/DAST), and secret management vaults directly into CI/CD pipelines.
- Lead incident response readiness architecture, designing cloud telemetry dashboards, log aggregation feeds (SIEM), and automated threat hunting triggers to accelerate breach containment.
Requirements
- 8 to 12 years of core enterprise infrastructure security experience, with 5+ dedicated years actively designing, building, and governing multi-cloud safety frameworks.
- Strong technical mastery of cloud networking security components (VPC architecture, firewalls, WAF, DDoS protection), infrastructure-as-code scripting (Terraform, CloudFormation), and threat modeling.
- Deep structural understanding of cloud computing vulnerabilities, container security paradigms, API gateway perimeters, and modern cryptography standards.
- Mandatory certification: CISSP, CCSP, or cloud vendor-specific expert security certification (e.g., AWS Security Specialty / Azure Security Engineer).
Preferred Qualifications
- Prior experience implementing security frameworks within heavily regulated environments (e.g., PCI-DSS, HIPAA, SOC 2, ISO 27001).
- Familiarity with scripting languages (Python, Bash, Go) used to automate security compliance remediation flows.