Job Description: Lead Cloud & Application Security Architect
Role Overview
We are seeking a Lead Cloud & Application Security Architect with a distinguished track record of securing enterprise-grade applications across highly complex, multi-cloud environments. With a minimum of 8 years of dedicated experience, you will serve as the premier technical authority bridging software engineering, cloud architecture, and modern threat defense.
This is a high-impact, hands-on leadership role. You will be responsible for defining the secure coding standards, threat modeling frameworks, and DevSecOps compliance guardrails that protect our software across AWS, GCP, and Azure. You are someone who commands the technical respect of elite developers, possesses deep multi-cloud infrastructure fluency, and can elegantly translate sophisticated technical risks into pragmatic business outcomes.
What You'll Do
- Define Multi-Cloud Guardrails: Architect, implement, and maintain consistent infrastructure-as-code (IaC) security standards and zero-trust Identity & Access Management (IAM) governance across our AWS, GCP, and Azure footprints.
- Establish Strategic DevSecOps Pipelines: Standardize and scale automated application security testing (SAST, DAST, SCA, and container scanning) globally within multi-cloud CI/CD ecosystems. Ensure these pipelines protect velocity while minimizing false positives.
- Lead Advanced Threat Modeling: Direct complex architectural reviews and threat modeling sessions (using STRIDE/PASTA) for flagship enterprise products, mapping trust boundaries across heterogeneous cloud infrastructures and distributed microservices.
- Engineered Remediations & Reference Architectures: Author high-quality, reusable software libraries and "secure-by-default" reference architectures (e.g., standardized encryption, multi-tenant data isolation, secret management) to eliminate entire vulnerability classes at the root.
- Champion Culture & Strategy: Drive the long-term AppSec roadmap, establish an enterprise-wide Security Champions program, and provide technical mentorship to senior engineering leads and security staff.
What You'll Bring
- Experience Blueprint: A minimum of 8+ years of deep technical experience in application security, product security, or DevSecOps engineering, preferably backed by an early career foundation in core software development.
- Multi-Cloud Mastery: Proven hands-on architecture experience across all three major public cloud providers:
- AWS: Deep knowledge of IAM, KMS, VPC security, GuardDuty, and AWS Organizations.
- GCP: Proficiency with Cloud IAM, Workload Identity, Cloud Key Management, and Google Kubernetes Engine (GKE) security.
- Azure: Experience with Microsoft Entra ID (formerly Azure AD), Azure Key Vault, Managed Identities, and Azure Kubernetes Service (AKS).
- Advanced Threat Mechanics: Comprehensive mastery of web application vulnerabilities (OWASP Top 10), API security, container security/isolation, and modern distributed system attacks.
- Pragmatic Executive Presence: Exceptional communication skills with a proven ability to collaborate with engineering squads to resolve issues while effectively presenting risk metrics to C-level executives.