Lead AWS Cloud Security Architect

Hybrid in Albany, NY, US • Posted 4 hours ago • Updated 4 hours ago
Full Time
Hybrid
Depends on Experience
Company Branding Image
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • AWS Organizations
  • AWS Landing Zone
  • Amazon EKS
  • AWS Backup
  • AWS Backup Audit Manager
  • AWS KMS
  • AWS CloudTrail
  • AWS Config
  • VPC Flow Logs
  • AWS Network Firewall
  • Transit Gateway
  • Route 53
  • Amazon Macie
  • CyberArk

Summary

Job Title: Lead AWS Cloud Security Architect

Level: Senior Specialist Architecture

Experience: 10 15 Years

Location: Albany, New York, USA (Hybrid)

Employment Type: Fulltime

Job Summary

  • We are looking for an experienced Lead AWS Cloud Security Architect to design, implement, and support secure, scalable, and resilient AWS cloud environments. The ideal candidate will have strong expertise in multi-account AWS architecture, security governance, AWS Organizations, Amazon EKS, backup and recovery architecture, and cloud security engineering.
  • The role will focus on designing a Security Lab, Isolated Recovery Environment (IRE), Clean Room forensic environment, and secure AWS infrastructure while following AWS architecture and security best practices.

Key Responsibilities

  • Design and implement multi-account AWS architecture using AWS Organizations and Landing Zone governance.
  • Design the Security Lab foundation, including account structure, Organizational Units (OUs), Service Control Policies (SCPs), centralized logging, and automated account vending.
  • Design and support AWS cloud security infrastructure and security agent implementations.
  • Architect an Isolated Recovery Environment (IRE) with:
  • WORM-protected backup vaults
  • Cross-account and cross-region backup
  • 3-2-1 backup strategy
  • Customer Managed KMS Keys (CMKs)
  • Recovery orchestration
  • CyberArk break-glass access
  • Amazon Macie integration
  • AWS Network Firewall
  • Transit Gateway and route isolation
  • Design a Clean Room forensic environment for secure investigation and recovery activities.
  • Establish backup governance and compliance using AWS Backup Audit Manager.
  • Design isolated and secure Route 53 DNS architectures.
  • Define and implement hardened compute baselines and secure secrets-management practices.
  • Design, implement, and secure Amazon EKS infrastructure and associated security lab environments.
  • Develop architecture and security documentation, including:
  • IRE/Clean Room Architecture Design Document
  • Security Lab Architecture Design Document
  • Architecture diagrams and technical views
  • Contribute to the Lab Operations Guide and Account Vending Administration Procedures.
  • Collaborate with DevOps, Cloud Engineering, Cybersecurity, and Infrastructure teams to implement security architecture.
  • Ensure cloud architecture aligns with AWS Well-Architected and security best practices.

Required Skills

  • 10 15 years of experience in Cloud/Infrastructure Architecture, preferably with significant AWS experience.
  • Strong experience designing AWS multi-account architectures.
  • Hands-on experience with AWS Organizations, Landing Zones, OUs, SCPs, and account vending.
  • Strong expertise in AWS security architecture.
  • Strong knowledge of Amazon EKS architecture, configuration, and security.
  • Experience with AWS Backup, cross-account/cross-region backup, and recovery architecture.
  • Experience with AWS networking, including VPC, Transit Gateway, Network Firewall, Route 53, and route isolation.
  • Experience with AWS CloudTrail, VPC Flow Logs, AWS Config, and centralized logging.
  • Strong understanding of DevOps strategy and architecture design.
  • Ability to create and communicate architectural diagrams and technical architecture views.
  • Experience designing secure and resilient cloud infrastructure.

Good to Have

  • AWS Well-Architected Framework and AWS Well-Architected Tools experience.
  • Architecture principles and architecture viewpoint/view design.
  • Experience with CyberArk and break-glass access patterns.
  • Experience with Amazon Macie.
  • Knowledge of forensic/security clean-room environments.
  • Experience with hardened compute baselines and secrets management.
  • Experience developing architecture standards, operational guides, and governance procedures.
  • AWS certifications such as AWS Solutions Architect Professional or AWS Security Specialty.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91166696
  • Position Id: 9078236
  • Posted 4 hours ago

Company Info

About Black Rock Group

At Black Rock Groups Inc, we specialize in providing top-tier human resource services tailored to meet the evolving needs of businesses across the United States. Our expertise spans talent acquisition, workforce management, employee engagement, compliance, and strategic HR consulting.

We empower organizations by delivering customized HR solutions that drive efficiency, productivity, and long-term growth. Whether you're a startup looking to build a strong team or an enterprise seeking to optimize workforce strategies, our dedicated professionals are here to support your business success.

Contact the job poster
AS

Aditya Singh

Recruiter @ Black Rock Group
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Hybrid in Jersey City, New Jersey

Today

Easy Apply

Full-time

Depends on Experience

Tampa, Florida

Today

Easy Apply

Full-time

Depends on Experience

Tampa, Florida

Today

Easy Apply

Full-time

Depends on Experience

Search all similar jobs