Cloud Security Architect (AWS)

Irvine, CA, US • Posted 1 hour ago • Updated 1 hour ago
Full Time
Part Time
On-site
Fitment

Dice Job Match Score™

🔗 Matching skills to job...

Job Details

Skills

  • Security Controls
  • Vulnerability Management
  • Request For Proposal
  • Cloud Security
  • ISO 9000
  • FX
  • Authentication
  • Authorization
  • Access Control
  • SAP PP
  • SIEM
  • Continuous Monitoring
  • Web Applications
  • Endpoint Protection
  • GL
  • GR
  • Amazon EC2
  • Migration
  • Kubernetes
  • Network
  • Cloud Computing
  • Risk Management
  • Penetration Testing
  • Security Architecture
  • High-level Design
  • Risk Assessment
  • Regulatory Compliance
  • WAF
  • Utilization Management
  • Identity Management
  • Encryption
  • Management
  • Vulnerability Assessment
  • Nessus
  • Qualys
  • Burp Suite
  • Fortify
  • Network Security
  • Firewall
  • IDS
  • IPS
  • Microsoft Windows Server
  • Microsoft Operating Systems
  • Red Hat Enterprise Linux
  • Database
  • PL/SQL
  • Oracle Exadata
  • Collaboration
  • Stakeholder Management
  • Java
  • .NET
  • TIBCO Software
  • Enterprise Service Bus
  • DevSecOps
  • Continuous Integration
  • Continuous Delivery
  • Audiovisual
  • AV
  • Amazon Web Services
  • CISSP
  • CISM
  • Cisco Certifications

Summary

Role: Cloud Security Architect (AWS)

Location: Irvine, CA (Onsite)

Experience: 10+ Years



Job Summary

We are seeking a highly experienced Cloud Security Architect to lead security architecture for a large-scale Data Center Exit to AWS initiative. This role focuses on designing and implementing enterprise-grade security controls across AWS environments, ensuring secure migration, compliance, and operational resilience.

The ideal candidate will have deep expertise in AWS security services, multi-account architecture, vulnerability management, and secure-by-design principles, with experience supporting mission-critical enterprise workloads.



Key Responsibilities

Cloud Security Architecture

  • Lead the design and implementation of secure AWS architectures for Data Center Exit programs
  • Define and implement AWS Landing Zone security, including:
    • IAM guardrails
    • Service Control Policies (SCPs)
    • Centralized logging and monitoring
  • Establish security baselines aligned with CIS, NIST, and ISO frameworks



Identity, Access & Encryption

  • Design and enforce IAM strategies, including least privilege and role-based access
  • Implement encryption standards using AWS KMS for data at rest and in transit
  • Validate authentication and authorization models across all workloads
  • Support identity federation and secure access controls



Threat Detection & Monitoring

  • Implement and manage AWS security services such as:
    • AWS WAF
    • GuardDuty
    • CloudTrail
    • Security Hub
  • Integrate AWS security telemetry with SIEM platforms for continuous monitoring
  • Define and implement detective and preventive controls



Application & Infrastructure Security

  • Conduct vulnerability assessments (VAPT) and define remediation strategies
  • Implement:
    • Web Application Firewall (WAF) rules
    • Network segmentation and firewall policies
    • Endpoint protection controls
  • Support secure development practices including code reviews and DevSecOps alignment



Migration Security & Governance

  • Secure workloads during migration from on-premise to AWS EC2
  • Ensure data consistency, integrity, and compliance during migration phases
  • Design security for hybrid architectures and integration-heavy systems
  • Support migration tools and enforce governance policies



Container & Platform Security

  • Design security for EKS/Kubernetes environments, including:
    • Pod and network policies
    • Image scanning and runtime protection
  • Secure cloud-native and distributed workloads



Risk Management & Compliance

  • Lead penetration testing cycles and coordinate remediation efforts
  • Produce:
    • Security architecture documents (HLD/LLD)
    • Risk assessments
    • Operational security runbooks
  • Ensure adherence to enterprise and regulatory compliance standards



Required Skills

  • Strong expertise in AWS security services:
    • IAM, KMS, CloudTrail, GuardDuty, WAF
  • Experience designing AWS multi-account Landing Zones and governance models
  • Deep understanding of:
    • Identity and access management
    • Encryption and key management
    • Zero Trust architecture and least privilege principles
  • Hands-on experience with vulnerability assessment tools:
    • Nessus, Qualys, Burp Suite, Fortify, Checkmarx
  • Strong knowledge of:
    • Network security (firewalls, IDS/IPS, segmentation)
    • OS-level security (Windows Server, RHEL)
  • Experience securing databases (Oracle, SQL Server, Exadata on AWS)
  • Strong collaboration and stakeholder management skills



Preferred Skills

  • Experience with AWS Shield and advanced threat protection tools
  • Knowledge of integration security for Java, .NET, and TIBCO ESB workloads
  • Experience with DevSecOps and CI/CD security integration
  • Certifications such as:
    • AWS Certified Security Specialty
    • CISSP / CISM / CCSP

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91018020
  • Position Id: PDT - 10791-11926-1775173177
  • Posted 1 hour ago

Company Info

About Purple Drive Technologies LLC

Founded in 2007, Purple Drive started as a tech solutions firm and has grown into a full-service consulting and talent partner. We help businesses navigate complex technology challenges while connecting top professionals with career-defining opportunities.

We believe in transforming businesses through smart IT solutions and empowering technologists to grow their expertise through challenging projects and meaningful partnerships. Built on over 20 years of trusted relationships, we create success stories for both our clients and the talented professionals who drive innovation forward.

Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Costa Mesa, California

Today

Full-time

USD 146,000.00 - 194,000.00 per year

Costa Mesa, California

Today

Full-time

USD 166,000.00 - 220,000.00 per year

Santa Ana, California

Today

Easy Apply

Full-time

USD 170,000.00 - 180,000.00 per year

Santa Ana, California

Today

Full-time

USD 120,001.00 - 160,000.00 per year

Search all similar jobs