Senior Cloud Security Architect – Terraform

Jobtailor

Deutschland

Vor Ort

EUR 90.000 - 130.000

Vollzeit

14 Tage+

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Zusammenfassung

Jobtailor is seeking an experienced AWS security architect to design and implement secure-by-default patterns and guardrails across enterprise AWS workloads. You will collaborate with cloud engineering, DevOps, risk & compliance, and product teams, embedding security into CI/CD, conducting threat modeling, and guiding incident response and risk assessments.

This role emphasizes risk-driven design, governance mapping to CIS/NIST/ISO, and clear runbooks.

Qualifikationen

  • 7+ years of experience in cloud architecture and security.
  • Hands-on with AWS security services and controls, including Organizations, Control Tower, IAM Identity Center, KMS, Security Hub, GuardDuty, Detective, Macie, WAF/Shield, AWS Network Firewall, CloudTrail, Config, CloudWatch, VPC, Route 53, ECS, and Secrets Manager/Parameter Store.
  • Strong background in cloud identity and Zero Trust patterns, including workload identity, JIT access, break-glass design, and ABAC where appropriate.
  • Experience securing data at scale, including classification, DLP, tokenization, and access governance.
  • Deep understanding of networking and isolation patterns, including multi-region architectures, hybrid connectivity, egress controls, private endpoints, and service-to-service authentication.
  • Proficiency with infrastructure-as-code and automation tools (Terraform, Python/Bash, policy-as-code).
  • Experience with container and serverless security, including ECS hardening, image attestations, runtime controls, and least-privilege Lambda patterns.
  • Detection engineering experience, including logging strategies, detections-as-code, and SIEM/SOAR integration.
  • Familiarity with incident response and security investigations.
  • Strong governance, risk, and compliance knowledge with the ability to map controls to CIS, NIST, ISO, PCI, and HIPAA frameworks (as applicable).
  • Clear written and verbal communication skills, with the ability to produce concise design documentation and provide actionable guidance to engineering teams.
  • Ability to manage priorities effectively in a fast-changing environment.
  • Comfortable working in a remote or hybrid environment with limited in-person interaction.

Aufgaben

  • Design secure reference architectures and reusable security patterns for AWS workloads, including identity, networking, encryption, logging, monitoring, and secrets management.
  • Implements and operates enterprise AWS guardrails using Organizations, Control Tower, SCPs, AWS Config (managed and custom rules), Security Hub, GuardDuty, Detective, Macie, WAF/Shield, and AWS Network Firewall.
  • Applies least-privilege IAM using roles, permission boundaries, session policies, IAM Identity Center, SAML/OIDC federation, and ABAC/RBAC where appropriate.
  • Embeds security into CI/CD pipelines using policy-as-code, Terraform checks, container and image scanning, SBOMs, and pre-commit hooks.
  • Automates remediation and drift detection using Lambda, Step Functions, and Terraform.
  • Maps technical controls to security frameworks including CIS AWS Foundations, NIST, ISO 27001, SOC 2, PCI DSS, and HIPAA (as applicable).
  • Conducts threat modeling (e.g., STRIDE) and risk assessments and drives remediation to closure.
  • Reviews designs, provides architectural guidance, and produces clear documentation and runbooks.

Kenntnisse

AWS security architecture
Cloud security strategy
Zero Trust patterns
Incident response
Threat modeling
Documentation & guidance
IaC / automation (Terraform)
Container/serverless security
Networking design
SIEM/SOAR integration

Tools

Terraform
AWS Config
CloudTrail
SIEM/SOAR integration
WAF/Shield

Jobbeschreibung

  • Designs, implements, and continuously improves AWS security architecture.
  • Partners with cloud engineering, platform engineering, DevOps, Risk & Compliance, and product teams to build secure-by-default patterns, guardrails, and automation that enable delivery velocity without compromising security.
  • Influences cloud security strategy while providing hands-on architectural and engineering support.
  • Designs secure reference architectures and reusable security patterns for AWS workloads, including identity, networking, encryption, logging, monitoring, and secrets management.
  • Implements and operates enterprise AWS guardrails using Organizations, Control Tower, SCPs, AWS Config (managed and custom rules), Security Hub, GuardDuty, Detective, Macie, WAF/Shield, and AWS Network Firewall.
  • Applies least-privilege IAM using roles, permission boundaries, session policies, IAM Identity Center, SAML/OIDC federation, and ABAC/RBAC where appropriate.
  • Uses IAM Access Analyzer and automated validation to identify and reduce risk.
  • Designs secure VPC architectures and establishes detection-as-code and telemetry standards using CloudTrail, VPC Flow Logs, Route 53, RDS, ALB/NLB, and S3 access logs; integrates detections with SIEM/SOAR platforms.
  • Supports incident response through detections, playbooks, and tabletop exercises.
  • Embeds security into CI/CD pipelines using policy-as-code, Terraform checks, container and image scanning, SBOMs, and pre-commit hooks.
  • Automates remediation and drift detection using Lambda, Step Functions, and Terraform.
  • Maps technical controls to security frameworks including CIS AWS Foundations, NIST, ISO 27001, SOC 2, PCI DSS, and HIPAA (as applicable).
  • Conducts threat modeling (e.g., STRIDE) and risk assessments and drives remediation to closure.
  • Reviews designs, provides architectural guidance, and produces clear documentation and runbooks.
Requirements
  • 7+ years of experience in cloud architecture and security, including leading cloud security programs or large-scale AWS transformations.
  • Hands-on expertise with AWS security services and controls, including Organizations, Control Tower, IAM/IAM Identity Center, KMS, Security Hub, GuardDuty, Detective, Macie, WAF/Shield, AWS Network Firewall, CloudTrail, Config, CloudWatch, VPC, Route 53, ECS, and Secrets Manager/Parameter Store.
  • Strong background in cloud identity and Zero Trust patterns, including workload identity, JIT access, break-glass design, and ABAC where appropriate.
  • Experience securing data at scale, including classification, DLP, tokenization, and access governance.
  • Deep understanding of networking and isolation patterns, including multi-region architectures, hybrid connectivity, egress controls, private endpoints, and service-to-service authentication.
  • Proficiency with infrastructure-as-code and automation tools (Terraform, Python/Bash, policy-as-code).
  • Experience with container and serverless security, including ECS hardening, image attestations, runtime controls, and least-privilege Lambda patterns.
  • Detection engineering experience, including logging strategies, detections-as-code, and SIEM/SOAR integration.
  • Familiarity with incident response and security investigations.
  • Strong governance, risk, and compliance knowledge with the ability to map controls to CIS, NIST, ISO, PCI, and HIPAA frameworks (as applicable).
  • Clear written and verbal communication skills, with the ability to produce concise design documentation and provide actionable guidance to engineering teams.
  • Ability to manage priorities effectively in a fast-changing environment.
  • Comfortable working in a remote or hybrid environment with limited in-person interaction.
Core Competencies

Demonstrates extensive expertise in AWS security architecture, including the design and implementation of secure reference architectures and automation for cloud environments. Proficient in risk management, compliance frameworks, and incident response, with a strong focus on integrating security into CI/CD pipelines.

Highest-signal resume keywords
  • AWS Security Services
  • Cloud Architecture
  • Infrastructure-as-Code
  • Risk Management
  • Incident Response
ATS Optimization Keywords
Hard Skills
  • AWS Security Architecture
  • IAM Access Management
  • Terraform
  • CloudTrail
  • VPC Design
  • Security Frameworks
  • Detection Engineering
  • Data Classification
  • Zero Trust Patterns
  • Container Security
Soft Skills
  • Clear Communication
  • Priority Management
Industry Keywords
  • CIS
  • NIST
  • ISO 27001
  • SOC 2
  • PCI DSS
  • HIPAA
  • DLP
  • Tokenization
  • ABAC
  • RBAC
Tools & Technologies
  • AWS Organizations
  • AWS Control Tower
  • AWS Config
  • AWS Security Hub
  • GuardDuty
  • Macie
  • WAF/Shield
  • SIEM/SOAR Integration
  • Lambda
  • Step Functions
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Cloud Security Engineer
Cloud Security Engineer

Jobtailor • Deutschland

Vor Ort
EUR 90.000 - 130.000
Security training
DevSecOps Engineer
DevSecOps Engineer

Jobtailor • Deutschland

Remote
EUR 90.000 - 140.000
AWS DevSecOps Engineer
AWS DevSecOps Engineer

Jobtailor • Deutschland

Hybrid
EUR 90.000 - 130.000
IS Principal Security Architect
IS Principal Security Architect

Jobtailor • Deutschland

Hybrid
EUR 130.000 - 190.000
Staff Cyber Security Engineer (AWS Cloud)
Staff Cyber Security Engineer (AWS Cloud)

Solaris • Berlin

Hybrid
EUR 90.000 - 130.000
Learning & development budget
Remote working allowance
Free online yoga
+8
Global Product Cyber Security Expert – R&D Digital Portfolio
Global Product Cyber Security Expert – R&D Digital Portfolio

Jobtailor • Mannheim

Vor Ort
EUR 110.000 - 150.000
Senior Site Reliability Engineer, SRE, Backend
Senior Site Reliability Engineer, SRE, Backend

Jobtailor • Berlin

Vor Ort
EUR 90.000 - 130.000
Senior AWS Architect
Senior AWS Architect

Jobtailor • Berlin

Vor Ort
EUR 90.000 - 130.000
Senior Manager, Information Security Architecture – Engineering
Senior Manager, Information Security Architecture – Engineering

Jobtailor • Deutschland

Remote
EUR 120.000 - 150.000
Senior Cloud Engineer – Consultant
Senior Cloud Engineer – Consultant

Jobtailor • Berlin

Vor Ort
EUR 90.000 - 130.000