Security Architect

Tenarai

Bengaluru

On-site

INR 4,000,000 - 7,000,000

Full time

21 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Tenarai seeks an experienced security architecture engineer to secure our AWS platform and protect mission-critical workloads across the IRM product estate. You will design guardrails for accounts, landing zones, IAM/SCP, EKS security, network hardening, secrets management, and encryption patterns, with IaC guardrails enabling automated, auditable controls.

You will collaborate with CSA, CloudOps, DevOps, platform engineering, and PSOE product-security teams to drive posture improvements and

Qualifications

  • Senior hands-on experience securing production AWS environments for client-facing or mission-critical workloads.
  • Proven experience with AWS Organizations, multi-account architecture, landing zones, SCPs, IAM, VPC networking, EKS / Kubernetes, KMS, secrets management, and cloud logging.
  • Practical experience turning cloud posture findings into remediated infrastructure and reusable patterns. Experience working with DevOps, CloudOps, platform engineering, and product teams in delivery-oriented environments.

Responsibilities

  • Design and implement cloud security guardrails that allow engineering teams to move faster with less risk: AWS account structure, landing zones, IAM and SCP controls, EKS and container security, network exposure reduction, secrets and encryption patterns, cloud logging, posture management, and infrastructure-as-code guardrails.
  • Report through CSA with day-to-day alignment to CloudOps, DevOps, platform engineering, and PSOE product-security resources.

Skills

AWS security
Multi-account AWS
IAM & SCPs
Terraform
CIS AWS Benchmarks
NIST CSF
Zero Trust
Kubernetes security

Tools

Terraform

Job description

Position Summary

This is a hands-on architecture and engineering role within Cybersecurity Architecture (CSA). The role secures the AWS platform behind the IRM product estate, including Horizon, CRC & OCN (Masscomm), and Legacy Masscomm platforms.

You will design and implement the cloud security guardrails that allow IRM engineering teams to move faster with less risk: AWS account structure, landing zones, IAM and SCP controls, EKS and container security, network exposure reduction, secrets and encryption patterns, cloud logging, posture management, and infrastructure-as code guardrails.

This role reports through CSA, with dedicated day-to-day alignment to CloudOps, DevOps, platform engineering, and the product-security resources in PSOE.

Required Qualifications
Experience
  • Senior hands-on experience securing production AWS environments for client-facing or mission-critical workloads.
  • Proven experience with AWS Organizations, multi-account architecture, landing zones, SCPs, IAM, VPC networking, EKS / Kubernetes, KMS, secrets management, and cloud logging.
  • Practical experience turning cloud posture findings into remediated infrastructure and reusable patterns. Experience working with DevOps, CloudOps, platform engineering, and product teams in delivery-oriented environments.
Technical Skills
  • Strong AWS architecture and security engineering skills.
  • Infrastructure-as-code and policy-as-code experience, preferably with Terraform or equivalent tooling. Working knowledge of CSPM / CNAPP concepts, container security, cloud detection, and cloud resilience. Ability to design controls that are automated, auditable, and usable by engineering teams.
  • Familiarity with CIS AWS Benchmarks, NIST CSF, NIST SP 800-53, and Zero Trust concepts.
Soft Skills and Behaviours
  • Practical architecture judgment: able to reduce real risk without creating review bottlenecks.
  • Strong communication with platform engineers, product leaders, CyberOps, GRC, and executives.
  • Comfortable operating through influence in a federated environment.
  • Bias toward reusable patterns, measurable remediation, and clear ownership.
Certifications (Preferred)
  • AWS Security - Specialty, AWS Solutions Architect Professional, or equivalent cloud-security credentials.
  • CISSP, CCSP, Kubernetes security, or infrastructure-security certifications are assets.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cloud Security Architect
Cloud Security Architect

Liminal Custody • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Senior Cloud Security
Senior Cloud Security

Sourcebae • Mumbai

On-site
INR 4,000,000 - 6,500,000
Senior Cloud Security Architect (AWS & Ecosystem) | AWS Security
Senior Cloud Security Architect (AWS & Ecosystem) | AWS Security

Jero Technologies • Mumbai

On-site
INR 3,000,000 - 5,400,000
Aws Cloud Engineer
Aws Cloud Engineer

PwC • Hyderabad, Bengaluru

Hybrid
INR 2,600,000 - 3,600,000
AWS Cloud Security Architect
AWS Cloud Security Architect

Advance Career Solutions • Chennai District, Bengaluru, Mumbai

Hybrid
INR 1,800,000 - 3,200,000
AWS Cloud Security Architect
AWS Cloud Security Architect

Shashwath Solution • Pune District

On-site
INR 1,200,000 - 1,800,000
AWS Cloud Security Architect
AWS Cloud Security Architect

Shashwath Solution • Dadri

On-site
INR 1,200,000 - 1,800,000
Senior Security Engineer- 2
Senior Security Engineer- 2

42 Gears Mobility Systems • Bengaluru

On-site
INR 1,500,000 - 2,000,000
Security Architect
Security Architect

Workmates Core2Cloud Solution Pvt Ltd • Hyderabad

On-site
INR 1,800,000 - 2,500,000
Opportunities for career advancement
Collaborative work environment
Exposure to innovative technologies
Cloud Security Architect
Cloud Security Architect

Adfolks LLC • Ernakulam

On-site
INR 2,000,000 - 3,000,000