Key Responsibilities

1. Cloud Security Architecture & Design Controls

  • Design and implement secure, scalable, and resilient AWS cloud architectures aligned with enterprise security standards and best practices.
  • Define security controls for AWS environments, including account structures, landing zones, workload isolation, and security boundaries.
  • Design and implement network segmentation using VPCs, subnets, security groups, Network ACLs, AWS Network Firewall, and other cloud-native security controls.
  • Establish appropriate security controls for internet-facing, internal, and highly sensitive workloads.
  • Design secure connectivity between AWS, on-premises data centers, and third-party environments.
  • Implement encryption for data at rest and in transit using services and technologies such as AWS KMS, TLS/SSL, and certificate management.
  • Conduct security architecture reviews for new cloud workloads, migrations, application modernization, and cloud transformation initiatives.
  • Identify security risks in proposed architectures and provide practical recommendations to mitigate those risks.
  • Develop and maintain cloud security reference architectures, security patterns, standards, and design guidelines.
  • Ensure security controls are consistently applied across development, testing, and production environments.

2. Identity & Access Management (IAM)

  • Design and maintain robust Identity and Access Management (IAM) controls based on the principles of least privilege and zero trust.
  • Define and manage IAM roles, policies, permission boundaries, service roles, and cross-account access.
  • Implement and enforce Multi-Factor Authentication (MFA) and strong authentication mechanisms.
  • Establish appropriate access controls for employees, administrators, applications, workloads, and third-party users.
  • Implement secure privileged-access mechanisms for administrative and high-risk accounts.
  • Integrate AWS environments with enterprise Identity Providers and Single Sign-On (SSO) platforms.
  • Regularly review IAM permissions to identify excessive, unused, or inappropriate access.
  • Identify and remediate risks such as overly permissive IAM policies, exposed credentials, inactive accounts, and inappropriate privilege escalation paths.
  • Establish processes for joiner, mover, and leaver access management.
  • Support periodic access reviews and provide evidence for security and compliance audits.

3. Security Automation & DevSecOps

  • Integrate security controls and automated security checks into CI/CD pipelines.
  • Implement security testing across infrastructure, application, container, and cloud configurations.
  • Use Infrastructure-as-Code (IaC) tools such as Terraform to consistently deploy and manage cloud security controls.
  • Implement automated checks for infrastructure misconfigurations, insecure configurations, and policy violations before deployment.
  • Introduce policy-as-code and automated compliance validation where appropriate.
  • Automate remediation of common cloud security misconfigurations and security findings.
  • Work closely with DevOps and engineering teams to embed DevSecOps practices into the software development lifecycle.
  • Develop reusable Terraform modules, security templates, policies, and automation frameworks.
  • Ensure security controls are repeatable, auditable, version-controlled, and integrated into automated deployment processes.
  • Continuously improve the organization's security posture through automation and standardization.

Key Attributes

  • Strong analytical and problem-solving skills.
  • Ability to translate security requirements into practical cloud architectures and technical controls.
  • Strong communication and stakeholder-management skills.
  • Ability to work across architecture, engineering, DevOps, infrastructure, and security teams.
  • Strong ownership of security risks and remediation.
  • Ability to balance security, business requirements, operational considerations, and delivery timelines.

Required Skills

Network Security AWS Cybersecurity