AWS Security AWS Cloud Security Architect/Remote
AWS Security AWS Cloud Security Architect – Landing Zone & Cyber Resilience/Remote
Remote
Duration: Long term
Required:
Alternates depending on seniority/framing: Sr. Cloud Security Engineer – IRE/Clean Room,
Principal Security Architect – AWS Multi-Account, or Cloud Infrastructure Security Architect
(EKS + Governance).
Scope
Multi-account AWS architecture design, AWS Organizations, and landing zone governance
Security Lab foundation and account vending design
Isolated Recovery Environment (IRE) architecture: WORM vault, cross-account backup,
recovery orchestration, Clean Room forensic environment
Amazon EKS baseline and lab environment for testing security capabilities
Key Responsibilities
WS-1: AWS Security Agent cloud infrastructure design and implementation support
WS-2 : (Security Lab): Design multi-account lab foundation, centralized logging (CloudTrail,
VPC Flow Logs, Config), OU structure, SCPs, and automated account vending
WS-3 (IRE & Clean Room): Design IRE account with WORM vault locking, crossaccount/
cross-region backup (3-2-1), CMKs, CyberArk break-glass, Macie integration,
Network Firewall, Transit Gateway route isolation, and recovery orchestration
WS-5: Design and implement Amazon EKS infrastructure configuration and the security lab
environment
Design Backup Audit Manager compliance framework
Design Route 53 DNS isolation and hardened compute baselines
Implement hardened compute baselines and secrets management
Author IRE & Clean Room Architecture & Design Document and Security Lab Architecture
Document
Contribute to lab operations guide and account vending admin procedures