Design and implement secure, scalable, and resilient AWS cloud architectures aligned with enterprise security standards and best practices.
Define security controls for AWS environments, including account structures, landing zones, workload isolation, and security boundaries.
Design and implement network segmentation using VPCs, subnets, security groups, Network ACLs, AWS Network Firewall, and other cloud-native security controls.
Establish appropriate security controls for internet-facing, internal, and highly sensitive workloads.
Design secure connectivity between AWS, on-premises data centers, and third-party environments.
Implement encryption for data at rest and in transit using services and technologies such as AWS KMS, TLS/SSL, and certificate management.
Conduct security architecture reviews for new cloud workloads, migrations, application modernization, and cloud transformation initiatives.
Identify security risks in proposed architectures and provide practical recommendations to mitigate those risks.
Develop and maintain cloud security reference architectures, security patterns, standards, and design guidelines.
Ensure security controls are consistently applied across development, testing, and production environments.
2. Identity & Access Management (IAM)
Design and maintain robust Identity and Access Management (IAM) controls based on the principles of least privilege and zero trust.
Define and manage IAM roles, policies, permission boundaries, service roles, and cross-account access.
Implement and enforce Multi-Factor Authentication (MFA) and strong authentication mechanisms.
Establish appropriate access controls for employees, administrators, applications, workloads, and third-party users.
Implement secure privileged-access mechanisms for administrative and high-risk accounts.
Integrate AWS environments with enterprise Identity Providers and Single Sign-On (SSO) platforms.
Regularly review IAM permissions to identify excessive, unused, or inappropriate access.
Identify and remediate risks such as overly permissive IAM policies, exposed credentials, inactive accounts, and inappropriate privilege escalation paths.
Establish processes for joiner, mover, and leaver access management.
Support periodic access reviews and provide evidence for security and compliance audits.
3. Security Automation & DevSecOps
Integrate security controls and automated security checks into CI/CD pipelines.
Implement security testing across infrastructure, application, container, and cloud configurations.
Use Infrastructure-as-Code (IaC) tools such as Terraform to consistently deploy and manage cloud security controls.
Implement automated checks for infrastructure misconfigurations, insecure configurations, and policy violations before deployment.
Introduce policy-as-code and automated compliance validation where appropriate.
Automate remediation of common cloud security misconfigurations and security findings.
Work closely with DevOps and engineering teams to embed DevSecOps practices into the software development lifecycle.
Develop reusable Terraform modules, security templates, policies, and automation frameworks.
Ensure security controls are repeatable, auditable, version-controlled, and integrated into automated deployment processes.
Continuously improve the organization's security posture through automation and standardization.
Key Attributes
Strong analytical and problem-solving skills.
Ability to translate security requirements into practical cloud architectures and technical controls.
Strong communication and stakeholder-management skills.
Ability to work across architecture, engineering, DevOps, infrastructure, and security teams.
Strong ownership of security risks and remediation.
Ability to balance security, business requirements, operational considerations, and delivery timelines.