AWS Solution architect

Russell Tobin

Alpharetta (GA)

On-site

USD 120,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Comprehensive healthcare coverage
401(k)-retirement savings
Life & disability insurance

Job summary

A leading staffing firm is seeking a skilled Assessment Roadmap Development Lead specializing in AWS security and cloud architecture. The role involves assessing existing AWS accounts, IAM roles, devising security policies, and managing cloud infrastructure security. Candidates should possess over 10 years of IT experience, at least 5 years in cloud roles, and relevant certifications. Strong leadership and communication skills are essential for collaboration across teams. This position offers a comprehensive benefits package.

Qualifications

  • Deep expertise in AWS security controls, IAM, SCPs, and compliance frameworks relevant to financial services.
  • Proven ability to design scalable, secure architectures and translate business requirements into technical solutions.
  • Experience leading cross-functional teams, conducting stakeholder workshops, and presenting architectural decisions.

Responsibilities

  • Lead discovery and assessment of current AWS accounts, IAM roles, SCPs, and Terraform modules.
  • Design and validate Service Control Policies (SCPs) to enforce least privilege.
  • Audit and refactor IAM roles to eliminate over-permissioning.

Skills

Cloud Security & Compliance
Solution Design
Technical Leadership
DevOps & Automation
Communication

Education

Bachelor’s or Master’s degree in Computer Science, Engineering, or related field

Tools

Terraform

Job description

Overview

Assessment Roadmap Development Lead discovery and assessment of current AWS accounts, IAM roles, SCPs, and Terraform modules.

Identify security gaps and develop a phased implementation roadmap in collaboration with stakeholders.

Security Policy Control Design Design and validate Service Control Policies (SCPs) to enforce least privilege, root user lockdown, and IP whitelisting.

Ensure policies are tested in non-production environments before rollout.

IAM Role Management Audit and refactor IAM roles to eliminate over-permissioning, deprecate shared roles, and implement least-privilege, function-specific access with clear permission boundaries.

Break-Glass Access Develop and document secure, auditable break-glass access procedures, including MFA enforcement, time-bound access, and approval workflows.

Infrastructure as Code (IaC) Review and update Terraform modules to ensure secure-by-default configurations, including encryption, tagging, and logging.

Oversee peer reviews and validation in staging environments.

Testing Validation Lead functional and negative testing of IAM and SCP changes, ensuring compliance with security benchmarks and operational requirements.

Production Rollout Documentation Oversee deployment of validated controls and modules to production, monitor for anomalies, and ensure comprehensive documentation and knowledge transfer

Key Responsibilities
  • Assessment & Roadmap Development: Lead discovery and assessment of current AWS accounts, IAM roles, SCPs, and Terraform modules. Identify security gaps and develop a phased implementation roadmap in collaboration with stakeholders.
  • Security Policy & Control Design: Design and validate Service Control Policies (SCPs) to enforce least privilege, root user lockdown, and IP whitelisting. Ensure policies are tested in non-production environments before rollout.
  • IAM Role Management: Audit and refactor IAM roles to eliminate over-permissioning, deprecate shared roles, and implement least-privilege, function-specific access with clear permission boundaries.
  • Break-Glass Access: Develop and document secure, auditable break-glass access procedures, including MFA enforcement, time-bound access, and approval workflows.
  • Infrastructure as Code (IaC): Review and update Terraform modules to ensure secure-by-default configurations, including encryption, tagging, and logging. Oversee peer reviews and validation in staging environments.
  • Testing & Validation: Lead functional and negative testing of IAM and SCP changes, ensuring compliance with security benchmarks and operational requirements.
  • Production Rollout & Documentation: Oversee deployment of validated controls and modules to production, monitor for anomalies, and ensure comprehensive documentation and knowledge transfer.
Required Skills & Experience
  • Cloud Security & Compliance: Deep expertise in AWS security controls, IAM, SCPs, and compliance frameworks relevant to financial services.
  • Solution Design: Proven ability to design scalable, secure architectures and translate business requirements into technical solutions.
  • Technical Leadership: Experience leading cross-functional teams, conducting stakeholder workshops, and presenting architectural decisions to both technical and non-technical audiences.
  • DevOps & Automation: Hands-on experience with Terraform, CI/CD pipelines, and automation of cloud infrastructure.
  • Communication: Strong documentation, presentation, and stakeholder management skills.
Qualifications
  • Bachelor’s or Master’s degree in Computer Science, Engineering, or related field.
  • Relevant certifications (e.g., AWS Certified Solutions Architect, TOGAF, CISSP) are highly desirable.
  • 10+ years of experience in IT, with at least 5 years in cloud architecture and security roles.

Note: Russell Tobin (Pride Global) offers eligible employees comprehensive healthcare coverage (medical, dental, and vision plans), supplemental coverage (accident insurance, critical illness insurance and hospital indemnity), a 401(k)-retirement savings, life & disability insurance, an employee assistance program, identity theft protection, legal support, auto and home insurance, pet insurance, and employee discounts with some preferred vendors

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Security Architect
Principal Security Architect

Francisco Partners • United States

On-site
USD 130,000 - 165,000
Senior Technical Lead/ Security Architect
Senior Technical Lead/ Security Architect

TechDigital Group • Frisco (TX)

On-site
USD 120,000 - 180,000
Senior Delivery Consultant - Security
Senior Delivery Consultant - Security

Amazon Web Services (AWS) • Denver (CO)

On-site
USD 154,000 - 208,000
Health insurance
401(k) matching
Paid time off
+2
Senior Delivery Consultant - Security
Senior Delivery Consultant - Security

Amazon Web Services (AWS) • San Francisco (CA)

On-site
USD 177,000 - 239,000
AWS Architect
AWS Architect

TechDigital Group • Raritan (NJ)

On-site
USD 130,000 - 160,000
Systems Architect
Systems Architect

Compunnel, Inc. • Irving (TX)

On-site
USD 140,000 - 190,000
Sr Security Architect Vulnerability Management
Sr Security Architect Vulnerability Management

Francisco Partners • United States

On-site
USD 140,000 - 190,000
Manager, IT Security
Manager, IT Security

Sun Communities & Sun Outdoors • Southfield (MI)

On-site
USD 100,000 - 130,000
Comprehensive Medical and Prescription coverage
401(k) Plan with matching contribution
Paid Time Off including holidays and parental leave
+2
Lead Software Engineer / Cloud Architect - AWS
Lead Software Engineer / Cloud Architect - AWS

Epitria Consulting • Melbourne (FL)

On-site
USD 140,000 - 180,000
Associate Director, Lead Cloud Architect
Associate Director, Lead Cloud Architect

Jobtailor • California (MO)

On-site
USD 150,000 - 210,000