FyerX

FyerX

·3 days ago

Cloud security architect (aws / azure / gcp)

Apply now

Location

remote (anywhere)

Commitment

Full Time

Level

Senior (5+ years)

Required skills

Cloud Security ArchitectureMulti-Cloud SecurityZero-Trust ArchitectureIdentity and Access ManagementData Protection and CryptographyKubernetes SecurityCloud Security Posture ManagementCloud Workload ProtectionPolicy as CodeDevSecOpsCI/CD SecurityIncident ResponseCloud Networking SecurityInfrastructure as CodeThreat ModelingSecurity Compliance Automation

Job Description

This is a remote position.

Job Details

Employment Type: Contract

Work Mode: Remote

Location: Offshore

Total Experience Required: 8 to 12 years

Relevant Experience Required: 5+ years of dedicated cloud security architecture experience across public cloud infrastructures

Mandatory Certification: Certified Information Systems Security Professional (CISSP), CCSP, AWS Certified Security - Specialty, or Microsoft Certified: Azure Security Engineer Associate

Job Summary

We are seeking an experienced Cloud Security Architect to design, govern, and secure our enterprise multi-cloud infrastructure. The ideal candidate will establish cloud security blueprints, architect zero-trust landing zones, secure containerized microservices, and build guardrails to automate compliance and protect cloud-native applications from sophisticated threats.

Key Responsibilities

  • Design and govern cloud security architectures across public cloud platforms (AWS, Azure, and GCP), establishing foundational multi-tenant landing zones and zero-trust perimeters.
  • Configure Identity and Access Management (IAM) strategies, defining least-privilege access rules, role-based controls (RBAC), multi-factor authentication (MFA), and federated identity lifecycles.
  • Implement cloud data protection layers, managing end-to-end cryptography, key management services (KMS), hardware security modules (HSM), and data-loss prevention (DLP) rules for data at rest and in transit.
  • Secure containerized microservices environments, designing runtime security boundaries, image vulnerability scanning protocols, and network policy controls for Kubernetes (EKS/AKS/GKE).
  • Integrate Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platforms (CWPP), writing automated policy-as-code scripts to enforce security configuration standards.
  • Collaborate with DevSecOps engineering teams to embed automated security testing utilities, static/dynamic application analysis (SAST/DAST), and secret management vaults directly into CI/CD pipelines.
  • Lead incident response readiness architecture, designing cloud telemetry dashboards, log aggregation feeds (SIEM), and automated threat hunting triggers to accelerate breach containment.

Requirements

8 to 12 years of core enterprise infrastructure security experience, with 5+ dedicated years actively designing, building, and governing multi-cloud safety frameworks.

Strong technical mastery of cloud networking security components (VPC architecture, firewalls, WAF, DDoS protection), infrastructure-as-code scripting (Terraform, CloudFormation), and threat modeling.

Deep structural understanding of cloud computing vulnerabilities, container security paradigms, API gateway perimeters, and modern cryptography standards.

Mandatory certification: CISSP, CCSP, or cloud vendor-specific expert security certification (e.g., AWS Security Specialty / Azure Security Engineer).

Preferred Qualifications

Prior experience implementing security frameworks within heavily regulated environments (e.g., PCI-DSS, HIPAA, SOC 2, ISO 27001).

Familiarity with scripting languages (Python, Bash, Go) used to automate security compliance remediation flows.

Ready to join the team?

Apply now