Cloud Security Architect

Irvine, CA, US • Posted 8 hours ago • Updated 8 hours ago
Contract Independent
Contract Corp To Corp
Contract W2
No Travel Required
On-site
$60 - $63/hr
Fitment

Dice Job Match Score™

✨ Finding the perfect fit...

Job Details

Skills

  • AWS IAM
  • WAF
  • KMS
  • CloudTrail
  • GuardDuty

Summary

Job Title: Cloud Security Architect

Location: Irvine, CA - onsite

Duration: 6 months

Rate: $60 - $63/hr on C2C

 

Note: Should be local only; no relocation

 

Cloud Security Architect

• AWS IAM, WAF, KMS, CloudTrail, GuardDuty

• Lead cloud security architecture for the Data Center Exit migration to AWS EC2.

• Design and implement AWS Landing Zone security including IAM guardrails, SCPs, and logging.

• Conduct application and infra vulnerability assessments and define remediation plans.

• Implement WAF rules, firewall policies, secure segmentation, and endpoint protection.

• Validate authentication, authorization, and encryption models for all migrated workloads.

• Support secure deployment practices, code reviews, and remediation of development gaps.

• Integrate SIEM systems with AWS native security tools for continuous monitoring.

• Define and enforce cloud security baselines aligned with CIS, NIST, and ISO controls.

• Lead penetration testing cycles and coordinate mitigation activities.

• Produce security HLD/LLD, risk assessments, and operational security runbooks.

• Hands-on experience designing secure AWS multi-account Landing Zones and guardrail policies.

• Strong understanding of EC2 security, IAM, encryption, and identity federation models.

• Integration knowledge for Oracle Exadata on AWS, SQL Server, and middleware security flows.

• Experience with AWS WAF, Shield, GuardDuty, Security Hub, and detective controls.

• Ability to design security for EKS workloads including pod/network policies and image scanning.

• Understanding of security in hybrid cloud migrations and AWS migration tooling.

• Strong expertise in AWS cloud security architecture including IAM, KMS, GuardDuty, and CloudTrail.

• Deep understanding of AWS Landing Zone, SCPs, governance, and enterprise security guardrails.

• Experience with security for custom applications including vulnerability identification and remediation.

• Proficiency with VAPT tools such as Nessus, Qualys, Burp Suite, Fortify, and Checkmarx.

• Strong understanding of WAF, firewall management, IDS/IPS, and network segmentation.

• Knowledge of OS-level security for Windows Server 2016–2025 and RHEL 7/8/9.

• Familiarity with securing Java, .NET, TIBCO ESB, and integration-heavy workloads.

• Understanding of database security for Oracle 19c, Exadata on AWS, and SQL Server.

• Ability to apply Zero Trust, least privilege, encryption, and secure-by-design principles.

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: technonj
  • Position Id: VK_CSA
  • Posted 8 hours ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Irvine, California

Today

Easy Apply

Full-time, Part-time, Contract, Third Party

Irvine, California

4d ago

Easy Apply

Contract

Depends on Experience

Santa Ana, California

Today

Easy Apply

Contract

$90 - $100

Tustin, California

Today

Contract

USD 140,000.00 - 150,000.00 per year

Search all similar jobs