Security Architect
Role: Security ArchitectLocation: Remote across USADuration: Long TermSummaryThese roles support the AWS delivery team by ensuring that workloads are migrated securely, that the enterprise Landing Zone meets client security standards, and that data governance requirements are satisfied throughout the migration lifecycle. The SRC resources work alongside AWS architects, Cloud Security, and partner delivery teams.Role ScopeLanding Zone Security Governance: Review and harden the enterprise Landing Zone architecture AWS Organizations, Service Control Policies (SCPs), Resource Control Policies (RCPs), managed VPCs, and integration with Cloud Security Posture Management (Wiz). Ensure guardrails are in place before workloads land.Security Architecture Review: Assess migrating workloads against security best practices; produce threat models, architecture decision records, and remediation guidance. Partner with Client Cloud Security to align with firm-level security standards.Data Security & Governance (1 of 2 roles): Support the database/data workstream with data classification, encryption-at-rest/in-transit strategy, access-control models for data stores (RDS, DynamoDB, Redshift, S3 data lakes), and data-residency compliance.Compliance & Controls: Map AWS-native controls to client regulatory and internal compliance requirements. Validate that migration patterns satisfy audit, logging, and monitoring expectations (CloudTrail, Config, GuardDuty, Security Hub).Infrastructure as Code Security: Review and contribute to IaC templates (CloudFormation / Terraform) to embed security controls as code ensuring least-privilege IAM, encryption defaults, and network segmentation are baked into deployment pipelines.Enablement & Documentation: Produce security architecture documentation, runbooks, and patterns suitable for client Tech Risk review. Enable the customer and partner teams to operate securely post-migration.Core SkillsEnterprise Landing Zone experience is the primary skill for this role, combined with broad AWS security depth and the ability to govern workload migrations at scale.Landing Zone & Multi-Account Governance (Primary)Advanced. AWS Organizations, SCPs, RCPs, AWS Control Tower, managed VPC architectures, account vending, and org-level policy enforcement at enterprise scale (15,000+ accounts).Identity & Access ManagementAdvanced. IAM policy design (least-privilege), permission boundaries, cross-account access patterns, federation (SAML/OIDC), and role chaining. Familiarity with CSPM integration (Wiz or equivalent).Data Security & GovernanceProficient to Advanced (required for 1 of 2 roles). Encryption strategies (KMS, CloudHSM), data classification, access-control models for RDS/DynamoDB/Redshift/S3, and data-residency requirements.Security Monitoring & ComplianceAdvanced. CloudTrail, AWS Config, GuardDuty, Security Hub, and detective controls. Mapping AWS-native controls to regulatory/internal frameworks.Infrastructure as CodeProficient. CloudFormation or Terraform. Embedding security controls into IaC pipelines; automated policy validation (cfn-guard, OPA, or equivalent).General Requirements5+ years of hands-on security experience across cloud and/or enterprise environments.2+ years of consulting or professional services delivery experience.1+ year of direct AWS experience in a security-focused capacity.AWS Certified Security Specialty (current) required; Solutions Architect Professional preferred.Infrastructure-as-Code proficiency (CloudFormation or Terraform).Prior delivery experience in a large, regulated enterprise environment (financial services strongly preferred); comfortable operating under change-control and audit scrutiny.Able to produce clear written documentation (architecture decision records, security patterns, runbooks) suitable for client Tech Risk review.Strong stakeholder communication; can work directly with client engineering, security, and compliance teams as an embedded SME.