Why This Role Stands Out
This role offers a significant opportunity to shape and enhance critical network security architecture within AWS and hybrid environments, fostering substantial professional growth. You'll thrive here if you possess a passion for complex problem-solving and a strong understanding of cloud security principles, and you are encouraged to apply to make a tangible impact.
Quick Overview
Seniority
Mid Senior
Work mode
On Site
Location
Chicago, IL, United States
Posted
2 days ago
AWSEncryptionAnsibleConfluenceJenkinsRESTZero Trust
Job Description
AWS Network Architect
Chicago IL - 3 days Onsite
Overview:
We are seeking an External Perimeter Security Architect for our client on a contract basis. You will lead a security architecture engagement focused on redesigning the external perimeter for both cloud and on-premises environments with the goal of reducing real risk exposure and deliver structured, milestone-based remediation plans that drive informed decisions.
Responsibilities:
Perimeter & Network Security Architecture
Assess, redesign, and reengineer the existing external perimeter. Deliver a feasibility assessment with a phased remediation roadmap, documented in Confluence.
Conduct a connection-by-connection assessment of high-risk network paths, document replacement options, and break findings into milestone-based remediation phases.
Extend architecture controls across on-premise and hybrid cloud environments, ensuring operationally effective security controls that minimize friction for the business.
AWS Security Hardening
Design and implement SCPs, Resource Policies, and VPC Endpoints to enforce isolation
Harden IAM controls and access patterns through guardrails
Configure data flow controls and encryption in transit/at rest
Work across multiple AWS accounts with an ability to prioritize and scale remediation
Embed AI-augmented tooling into architecture review workflows
CI/CD & Infrastructure-as-Code Security
Evaluate and harden CI/CD pipeline architecture and IaC configurations
Ongoing Architecture Review
Maintain correctness throughout the change lifecycle
Establish segmentation and zero-trust enclaves to contain blast radius
Map findings to TTPs to support early detection before remediation is complete
Identify and prioritize key operational risks surfaced during the engagement
Qualifications:
Required Qualifications:
Deep knowledge of traditional network security and SD-WAN
Zero trust architecture
AWS security configuration and best practices across cloud-native services (Control Tower, Security Hub, Config, Guardduty)
Cloud networking, integration patterns, and cross-account security management
Data encryption — at rest and in flight
Preferred Qualifications:
Privileged Access Management fundamentals
CI/CD pipeline security using third-party tools (Ansible, Jenkins, or similar)
Hands-on experience with AI coding agents (e.g., Claude Code, OpenAI Codex, Gemini CLI) — professional or personal
Similar jobs
- CG
Network Engineer with Security Clearance
CSA Global LLC
Annville, PA🇺🇸Hybrid6 weeks agoEncryptionDNSTechnology - AS
SR. AZURE ENGINEER - HYBRID with Security Clearance
ASD, Inc.
Dept Commerce, DC🇺🇸On-site4 weeks agoLoad BalancingScrumActive Directory+6 - AS
Principal Network Engineer/ SME with Security Clearance
American Systems Corporation
Colorado Springs, CO🇺🇸$175k - $185k/yrOn-site5 weeks agoAWSAzureVMwareTechnology - NG
Principal/Sr. Principal Cloud Engineer with Security Clearance
Northrop Grumman
Warner Robins, GA🇺🇸$103.6k - $155.4k/yrHybrid6 weeks agoDockerExpressMicroservices+13Technology - VT
Network Engineer with Security Clearance
VTG
Fredericksburg, VA🇺🇸$76k - $100k/yrHybrid3 weeks agoActive DirectoryDNSTechnology - BA
Network Engineer, Senior with Security Clearance
Booz Allen Hamilton
Virginia Beach, VA🇺🇸$77.5k - $176k/yrOn-site6 weeks agoVMwareTechnology