Why This Role Stands Out
You'll lead the design and implementation of cutting-edge AWS cloud security solutions, building secure, scalable environments and specialized labs that offer significant impact and continuous learning opportunities. This hybrid role is perfect for an experienced architect passionate about cloud security, ready to shape innovative strategies and advance their expertise within a reputable organization. Apply today to join a forward-thinking team and make your mark in cloud security architecture.
Quick Overview
Job Description
Job Title: Lead AWS Cloud Security Architect
Level: Senior Specialist Architecture
Experience: 10 15 Years
Location: Albany, New York, USA (Hybrid)
Employment Type: Fulltime
Job Summary
- We are looking for an experienced Lead AWS Cloud Security Architect to design, implement, and support secure, scalable, and resilient AWS cloud environments. The ideal candidate will have strong expertise in multi-account AWS architecture, security governance, AWS Organizations, Amazon EKS, backup and recovery architecture, and cloud security engineering.
- The role will focus on designing a Security Lab, Isolated Recovery Environment (IRE), Clean Room forensic environment, and secure AWS infrastructure while following AWS architecture and security best practices.
Key Responsibilities
- Design and implement multi-account AWS architecture using AWS Organizations and Landing Zone governance.
- Design the Security Lab foundation, including account structure, Organizational Units (OUs), Service Control Policies (SCPs), centralized logging, and automated account vending.
- Design and support AWS cloud security infrastructure and security agent implementations.
- Architect an Isolated Recovery Environment (IRE) with:
- WORM-protected backup vaults
- Cross-account and cross-region backup
- 3-2-1 backup strategy
- Customer Managed KMS Keys (CMKs)
- Recovery orchestration
- CyberArk break-glass access
- Amazon Macie integration
- AWS Network Firewall
- Transit Gateway and route isolation
- Design a Clean Room forensic environment for secure investigation and recovery activities.
- Establish backup governance and compliance using AWS Backup Audit Manager.
- Design isolated and secure Route 53 DNS architectures.
- Define and implement hardened compute baselines and secure secrets-management practices.
- Design, implement, and secure Amazon EKS infrastructure and associated security lab environments.
- Develop architecture and security documentation, including:
- IRE/Clean Room Architecture Design Document
- Security Lab Architecture Design Document
- Architecture diagrams and technical views
- Contribute to the Lab Operations Guide and Account Vending Administration Procedures.
- Collaborate with DevOps, Cloud Engineering, Cybersecurity, and Infrastructure teams to implement security architecture.
- Ensure cloud architecture aligns with AWS Well-Architected and security best practices.
Required Skills
- 10 15 years of experience in Cloud/Infrastructure Architecture, preferably with significant AWS experience.
- Strong experience designing AWS multi-account architectures.
- Hands-on experience with AWS Organizations, Landing Zones, OUs, SCPs, and account vending.
- Strong expertise in AWS security architecture.
- Strong knowledge of Amazon EKS architecture, configuration, and security.
- Experience with AWS Backup, cross-account/cross-region backup, and recovery architecture.
- Experience with AWS networking, including VPC, Transit Gateway, Network Firewall, Route 53, and route isolation.
- Experience with AWS CloudTrail, VPC Flow Logs, AWS Config, and centralized logging.
- Strong understanding of DevOps strategy and architecture design.
- Ability to create and communicate architectural diagrams and technical architecture views.
- Experience designing secure and resilient cloud infrastructure.
Good to Have
- AWS Well-Architected Framework and AWS Well-Architected Tools experience.
- Architecture principles and architecture viewpoint/view design.
- Experience with CyberArk and break-glass access patterns.
- Experience with Amazon Macie.
- Knowledge of forensic/security clean-room environments.
- Experience with hardened compute baselines and secrets management.
- Experience developing architecture standards, operational guides, and governance procedures.
- AWS certifications such as AWS Solutions Architect Professional or AWS Security Specialty.
Similar jobs
- TR
Cloud Architect
NewTryfacta
United States🇺🇸Remote21 hours agoTechnology - IC
Senior Java Cloud Architect- 10+ yrs- New York, United States- Onsite
NewiMedhas Consulting Services
New York, NY🇺🇸Hybrid21 hours agoAWSAgileConfluence+5Technology - RA
Cloud Infrastructure Support Engineer — Active TS Required with Security Clearance
NewRackner
Charlottesville, VA🇺🇸On-site21 hours agoAWSActive DirectoryAnsible+3Technology - DR
Sr. Data Center Network Engineer
NewDrevol LLC
Plano, TX🇺🇸Hybrid21 hours agoTechnology - SA
Cloud Security Engineer
NewSATCON Inc
Fort Worth, TX🇺🇸On-site21 hours agoAWSAzureGDPR+3Technology - KR
Cloud Infrastructure Architect with Security Clearance
NewKRYPTAURI
Columbia, DC🇺🇸Hybrid21 hours agoLLMTechnology