Senior Security Consultant – AWS Cloud Architecture

Gruve

Maharashtra

On-site

INR 4,000,000 - 7,000,000

Full time

8 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Gruve in Maharashtra, India is seeking an experienced AWS Cloud Architect to design and own Gruve's AWS multi-account foundation for a Cisco ISE-as-a-Service offering. This hands-on role requires building Terraform modules, defining the landing zone, and enforcing security guardrails across tenants.

You will lead cost management, reliability practices, and CI/CD security checks while coordinating with ISE and automation teams.

Qualifications

  • 8+ years of experience in cloud infrastructure, platform engineering, or cloud architecture roles.
  • Experience designing and building a multi-account AWS Organization or landing zone from the ground up.
  • Strong hands-on Terraform experience — candidates should be able to describe modules they have personally authored.
  • Solid understanding of AWS networking, including Transit Gateway, VPN, and hybrid connectivity to on-premises environments.
  • Experience with cloud cost management, tagging strategy, and cost attribution in multi-tenant or managed service environments.
  • AWS Certified Solutions Architect - Professional preferred; AWS Advanced Networking or Security specialty certifications an advantage.
  • Experience in a managed services provider (MSP), multi-tenant SaaS, or hosted service environment is highly desirable.
  • Familiarity with Cisco ISE, NAC, or enterprise network security concepts is an advantage.
  • Strong documentation, design communication, and cross-team collaboration skills.

Responsibilities

  • Design multi-account AWS Organization structure and consolidated billing.
  • Enforce SCPs and guardrails for tenant isolation and compliance.
  • Design tenant network architecture: VPC, multi-AZ subnet design, route tables, VPC endpoints, NAT, DNS, and IPAM.
  • Implement AWS Transit Gateway hub-and-spoke connectivity with per-tenant route tables, Site-to-Site VPN, and Direct Connect.
  • Implement AWS security services: IAM and IAM Identity Center (SSO), KMS, CloudTrail, AWS Config, GuardDuty, and Security Hub.
  • Own cloud cost management and FinOps: per-tenant cost attribution, tagging strategy, budget alerts, Cost Explorer and CUR-based reporting.
  • Design for high availability and disaster recovery across Availability Zones and regions, including backup, restore, and recovery runbooks.
  • Apply reliability engineering practices: automation-first operations, toil reduction, failure-mode analysis, and infrastructure observability.
  • Implement policy-as-code and security scanning in CI/CD pipelines (Checkov, tfsec, or equivalent).
  • Partner with automation and ISE engineering teams to ensure infrastructure outputs integrate cleanly with configuration management.
  • Subscribe to and manage the Cisco ISE AMI listing on AWS Marketplace per Region, including EULA acceptance and AMI version/release validation before each tenant build.
  • Verify and manage AWS service quotas (EC2 instance types, EIPs, VPC limits) per Region/tenant.
  • Configure Network ACLs and manage Elastic IP allocation policy (use only where explicitly required; avoid public exposure of ISE by default).
  • Enable VPC Flow Logs for tenant VPCs/subnets where required by security or compliance standards.
  • Configure EC2 instance metadata options (IMDSv2) and other instance-level hardening attributes.
  • Own EC2 user-data / bootstrap configuration for the ISE AMI (hostname, management IP, NTP, DNS) so it hands off cleanly into the Platform Automation Engineer's post-bootstrap automation.
  • Define NTP source design for ISE nodes alongside the existing DNS/Route 53 designs.
  • Own the end-to-end AWS infrastructure validation checklist (EC2, EBS, security groups, routing, DNS, NTP, IAM, encryption, monitoring) at each tenant go-live.

Skills

Cloud infrastructure
Terraform
AWS networking
Cost management
Documentation
Cross-team collaboration
Security basics

Education

AWS certification (preferred)

Tools

Terraform
Git
CI/CD pipelines
Checkov / tfsec

Job description

About Gruve

Gruve is an innovative software services startup dedicated to transforming enterprises to AI powerhouses. We specialize in cybersecurity, customer experience, cloud infrastructure, and advanced technologies such as Large Language Models (LLMs). Our mission is to assist our customers in their business strategies utilizing their data to make more intelligent decisions. As a well-funded early-stage startup, Gruve offers a dynamic environment with strong customer and partner networks.

About Gruve

Gruve is an innovative software services startup dedicated to transforming enterprises to AI powerhouses. We specialize in cybersecurity, customer experience, cloud infrastructure, and advanced technologies such as Large Language Models (LLMs). Our mission is to assist our customers in their business strategies utilizing their data to make more intelligent decisions. As a well-funded early-stage startup, Gruve offers a dynamic environment with strong customer and partner networks.

Position Summary

AWS Cloud Architect responsible for designing, building, and owning the complete AWS foundation for Gruve's Cisco ISE-as-a-Service (ISEaaS) multi-tenant managed service, with 8+ years of experience in cloud infrastructure and network security environments. Owns the AWS Organization and multi-account landing zone, tenant network architecture, security guardrails, Infrastructure-as-Code, and cloud cost management. This is a hands-on build role: the successful candidate will personally author Terraform modules and design the account structure that every customer tenant is provisioned from, while applying reliability engineering practices to reduce operational toil. Working knowledge of Cisco ISE, RADIUS, and enterprise network security concepts.

Key Responsibilities
  • Design and implement multi-account AWS Organization structure, including Organizational Units (OUs), management account separation, and consolidated billing.
  • Design and enforce Service Control Policies (SCPs) and organization-level guardrails for tenant isolation and compliance.
  • Design tenant network architecture: VPC, multi-AZ subnet design, route tables, VPC endpoints, NAT, DNS (Route 53 private zones including PTR records), and IP address management (IPAM).
  • Implement AWS Transit Gateway hub-and-spoke connectivity with per-tenant route tables, Site-to-Site VPN, and Direct Connect.
  • Implement AWS security services: IAM and IAM Identity Center (SSO), KMS customer-managed keys, CloudTrail, AWS Config, GuardDuty, and Security Hub.
  • Own cloud cost management and FinOps: per-tenant cost attribution, tagging strategy, budget alerts, Cost Explorer and CUR-based chargeback reporting, and cost modeling to support service pricing and margin analysis.
  • Design for high availability and disaster recovery across Availability Zones and regions, including backup, restore, and recovery runbooks.
  • Apply reliability engineering practices: automation-first operations, toil reduction, failure-mode analysis, and infrastructure observability.
  • Implement policy-as-code and security scanning in CI/CD pipelines (Checkov, tfsec, or equivalent).
  • Partner with automation and ISE engineering teams to ensure infrastructure outputs integrate cleanly with configuration management.
  • Subscribe to and manage the Cisco ISE AMI listing on AWS Marketplace per Region, including EULA acceptance and AMI version/release validation before each tenant build.
  • Verify and manage AWS service quotas (EC2 instance types, EIPs, VPC limits) per Region/tenant.
  • Configure Network ACLs and manage Elastic IP allocation policy (use only where explicitly required; avoid public exposure of ISE by default).
  • Enable VPC Flow Logs for tenant VPCs/subnets where required by security or compliance standards.
  • Configure EC2 instance metadata options (IMDSv2) and other instance-level hardening attributes.
  • Own EC2 user-data / bootstrap configuration for the ISE AMI (hostname, management IP, NTP, DNS) so it hands off cleanly into the Platform Automation Engineer's post-bootstrap automation.
  • Define NTP source design for ISE nodes alongside the existing DNS/Route 53 designs.
  • Own the end-to-end AWS infrastructure validation checklist (EC2, EBS, security groups, routing, DNS, NTP, IAM, encryption, monitoring) at each tenant go-live.
Basic Qualifications
  • 8+ years of experience in cloud infrastructure, platform engineering, or cloud architecture roles.
  • Demonstrable experience designing and building a multi-account AWS Organization or landing zone from the ground up.
  • Strong hands-on Terraform experience — candidates should be able to describe modules they have personally authored.
  • Solid understanding of AWS networking, including Transit Gateway, VPN, and hybrid connectivity to on-premises environments.
  • Experience with cloud cost management, tagging strategy, and cost attribution in multi-tenant or managed service environments.
  • AWS Certified Solutions Architect - Professional preferred; AWS Advanced Networking or Security specialty certifications an advantage.
  • Experience in a managed services provider (MSP), multi-tenant SaaS, or hosted service environment is highly desirable.
  • Familiarity with Cisco ISE, NAC, or enterprise network security concepts is an advantage.
  • Strong documentation, design communication, and cross-team collaboration skills.
Preferred Qualifications
  • AWS Core: AWS Organizations, Control Tower, Account Factory, Service Control Policies (SCPs), IAM, IAM Identity Center (SSO), EC2, EBS, S3, KMS, Secrets Manager, Systems Manager (SSM), CloudWatch.
  • AWS Networking: VPC, Subnets, Route Tables, Transit Gateway, Site-to-Site VPN, Direct Connect, Route 53, VPC Endpoints, NAT Gateway, IPAM.
  • Infrastructure as Code: Terraform (module authoring, remote state, workspaces), Git, CI/CD pipelines, policy-as-code (Checkov / tfsec / Sentinel).
  • Security & Governance: CloudTrail, AWS Config, GuardDuty, Security Hub, KMS key policies, least-privilege IAM design, multi-tenant isolation patterns.
  • Cloud Financial Management: Cost Explorer, Cost and Usage Report (CUR), tagging strategy, budgets and alerts, per-tenant chargeback and cost modeling.
  • Scripting & Automation: Python, Bash, PowerShell (any one or more), REST API integration.
  • Familiar with Technologies: Cisco ISE, RADIUS / RADSec, 802.1X, Ansible, Azure, Kubernetes.
Why Gruve

At Gruve, we foster a culture of innovation, collaboration, and continuous learning. We are committed to building a diverse and inclusive workplace where everyone can thrive and contribute their best work. If you’re passionate about technology and eager to make an impact, we’d love to hear from you.

Gruve is an equal opportunity employer. We welcome applicants from all backgrounds and thank all who apply; however, only those selected for an interview will be contacted.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Consultant (Cisco ISE/Ansible/AWS)
Senior Security Consultant (Cisco ISE/Ansible/AWS)

Gruve • Maharashtra

On-site
INR 3,500,000 - 5,200,000
Senior Security Consultant (Cisco ISE/Ansible/AWS)
Senior Security Consultant (Cisco ISE/Ansible/AWS)

Gruve • Pune District

On-site
INR 1,800,000 - 4,000,000
Senior Security Consultant
Senior Security Consultant

Gruve • Maharashtra

On-site
INR 2,200,000 - 3,800,000
Senior Software Engineer (Java Fullstack)
Senior Software Engineer (Java Fullstack)

Gruve • Maharashtra

On-site
INR 1,800,000 - 2,400,000
Technical Account Manager
Technical Account Manager

Gruve • Mumbai

On-site
INR 1,800,000 - 3,200,000
L3 Server Infrastructure Lead Windows Server VMware And Intune SCCM
L3 Server Infrastructure Lead Windows Server VMware And Intune SCCM

Gruve • Pune District

On-site
INR 3,000,000 - 6,000,000
L3 Server Infrastructure Lead (Windows Server, VMware & Intune/SCCM)
L3 Server Infrastructure Lead (Windows Server, VMware & Intune/SCCM)

gruve • Pune District

On-site
INR 3,000,000 - 5,500,000
Senior Pre-Sales Consultant - CyberSecurity
Senior Pre-Sales Consultant - CyberSecurity

Gruve • Mumbai

On-site
INR 1,500,000 - 2,500,000
Dynamic work environment
Inclusive workplace culture
Continuous learning opportunities
Security Consultant II
Security Consultant II

Gruve • Pune District

On-site
INR 1,200,000 - 1,800,000
Security Consultant II
Security Consultant II

Gruve • Maharashtra

On-site
INR 1,200,000 - 1,800,000