AWS Cloud Architect

Kastech Software Solutions Group

United States

On-site

USD 140,000 - 210,000

Full time

16 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Kastech Software Solutions Group seeks an Expert Cloud Architect to lead architecture, IaC development with Terraform, and security automation across enterprise cloud platforms. You will build scalable landing zones in AWS/Azure, design multi-stage CI/CD pipelines, and integrate security workflows with tools like Tenable and Infoblox.

You will also guide Kubernetes-based agents and Bedrock integration, ensuring zero-trust practices and policy-as-code enforcement throughout deployment pipelines.

Qualifications

  • 8+ years of hands-on cloud infrastructure experience.
  • Deep expertise in AWS or Azure.
  • 5+ years Terraform at scale and multi-environment state management.
  • 4+ years designing CI/CD pipelines in Azure DevOps or GitHub Actions.
  • Experience integrating security tools into automated cloud workflows.

Responsibilities

  • Own and evolve enterprise landing zone architectures (AWS/Azure).
  • Design and implement multi-stage CI/CD pipelines with policy-as-code enforcement.
  • Develop Terraform module libraries with secure defaults and modular design.
  • Architect automated vulnerability and threat path mappings using Tenable/Infoblox data.
  • Integrate security tooling into deployment pipelines (SCPs, IAM policies).
  • Provide technical leadership and ADRs across engineering squads.

Skills

Python Programming
Terraform
CI/CD
Cloud Architecture
Kubernetes
Security Integration

Education

Bachelor’s degree in Computer Science, Information Technology, or equivalent industry experience

Tools

Tenable
Infoblox
Palo Alto firewalls

Job description

We are seeking an Expert Cloud Architect to lead the architecture, design, and automation of our enterprise cloud platform and security integration frameworks. In this role, you will bridge cloud platform engineering with advanced automation—architecting landing zones, designing Infrastructure-as-Code (IaC) module libraries, and integrating intelligent agentic workflows that orchestrate data from enterprise platforms like Tenable, Infoblox, and firewall management systems.

This is a hands-on technical role for a builder who can author enterprise Terraform at scale, design resilient multi-stage CI/CD pipelines, and design automated security attack path mapping and compensating control frameworks.

Key Responsibilities

  • Landing Zone Evolution: Own and evolve enterprise landing zone architectures, network segmentation, and identity federation in AWS or Azure.
  • LLM & Bedrock
  • Build agent on Kubernetes and Bedrock
  • Strong Python Programing
  • Terraform Module Engineering: Author, version, and maintain reusable enterprise Terraform module libraries, setting strict security defaults and modular design principles.
  • Pipeline Architectures: Build multi-stage CI/CD pipeline architectures in Azure DevOps or GitHub Actions, incorporating policy-as-code enforcement, drift detection, and automated validation.
  • Hybrid Networking: Design secure enterprise network topologies, including transit networks, private endpoints, DNS resolution frameworks, and micro-segmentation.

2. Security Automation & Agentic Workflow Design

  • Vulnerability & Topology Integration: Architect automated workflows and agentic integrations that connect directly to security tooling (e.g., Tenable) to extract vulnerability data.
  • Network & Firewall Intelligence: Leverage network topology data (e.g., Infoblox) and active firewall rule sets to model potential attack vectors and exposure paths across hosted workloads.
  • Compensating Controls & Remediation: Implement automated governance and architecture frameworks to identify required compensating controls (e.g., preventing data exfiltration or lateral movement).
  • Policy-as-Code Enforcement: Embed security standards into deployment pipelines using tools such as Azure Policy, AWS SCPs, OPA/Rego, or Sentinel.

3. Escalation & Technical Leadership

  • Technical Unblocking: Serve as the top-tier escalation point for Senior Cloud Engineers, resolving complex state migration, provider upgrades, and cross-account orchestration issues.
  • Architecture Decision Records (ADRs): Document and enforce binding technical patterns, non-functional requirements, and architectural standards across engineering squads.

Required Qualifications

  • Experience: 8+ years of hands-on experience in cloud infrastructure, systems engineering, or cloud platform architecture.
  • Cloud Platform: Deep expertise in AWS (preferred) or Azure (single-cloud depth in either environment is acceptable).
  • Infrastructure-as-Code: 5+ years of hands-on experience writing Terraform at scale (enterprise module libraries, multi-environment state management, and custom provider/module development).
  • CI/CD Automation: 4+ years designing CI/CD pipelines using Azure DevOps, GitHub Actions, or equivalent frameworks.
  • Security & Network Integration: Proven track record of integrating enterprise security/networking tools (e.g., Tenable API, Infoblox, Palo Alto/NVA firewalls) into automated cloud infrastructure workflows.
  • Education: Bachelor’s degree in Computer Science, Information Technology, or equivalent industry experience.
  • AWS Certified Solutions Architect – Professional OR Azure Solutions Architect Expert.
  • HashiCorp Certified: Terraform Associate.
  • Familiarity with agentic AI integration concepts, API-driven security orchestrations, and automated threat/attack path modeling.
  • Hands-on experience with container platforms (EKS / AKS) and GitOps workflows.
  • Knowledge of zero-trust architecture, identity federation (SAML/OIDC), and secrets management.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Expert Cloud Architect
Expert Cloud Architect

Enexus Global Inc. • Oakland (CA)

On-site
USD 180,000 - 240,000
AWS Cloud Architect
AWS Cloud Architect

VTG Defense • Chantilly (VA)

On-site
USD 130,000 - 160,000
AWS Cloud Architect
AWS Cloud Architect

VTG Defense • McLean (VA)

On-site
USD 120,000 - 150,000
AWS Architect
AWS Architect

Compunnel, Inc. • Fort Lauderdale (FL)

On-site
USD 140,000 - 180,000
Principal Engineer – Cloud Platform
Principal Engineer – Cloud Platform

Jobtailor • Jacksonville (FL)

On-site
USD 140,000 - 180,000
AWS Solution Architect
AWS Solution Architect

Shrive Technologies LLC • Raleigh (NC)

On-site
USD 150,000 - 210,000
Cloud Engineer
Cloud Engineer

Gotham Technology Group • United States

On-site
USD 120,000 - 160,000
Senior Cloud Infrastructure Engineer
Senior Cloud Infrastructure Engineer

Angeion Group • United States

On-site
USD 110,000 - 150,000
AWS Cloud Architect
AWS Cloud Architect

Tieto • Irving (TX)

On-site
USD 120,000 - 180,000
Lead Cloud Platform Engineer
Lead Cloud Platform Engineer

Insight Global • Dallas (TX)

On-site
USD 120,000 - 150,000