Position: Sr. Multi-Cloud Infrastructure & Security Architect
Duration: 12 Months Contract to Hire
Location: NYC, NY (Hybrid 3 Days a Week Onsite)
About the Role and our Mission:
- The Enterprise Email Security team is responsible for safeguarding the email communications for a complex global organization. Although the current team excels in platform architecture, threat mitigation, incident response, compliance, and governance, we are planning a significant transformation of our infrastructure. This initiative involves expanding from a legacy on-premises environment to a robust, multi-cloud ecosystem across leading global cloud service providers.
- While the organization possesses deep security expertise, there is a need for a highly skilled professional in cloud architecture and enterprise IT infrastructure to design and implement secure and resilient cloud solutions.
- The company is seeking a Senior Multi-Cloud Infrastructure and Security Architect for a full-time contractor role. This individual will serve as a technical leader, translating high-level security requirements into practical, scalable cloud engineering solutions. The role is critical to ensuring the organization’s systems are robust, resilient, and highly available.
Key Responsibilities
- Architect and implement secure, enterprise-grade multi-cloud infrastructure across AWS and Azure (GCP is a plus), ensuring alignment with benchmarks and corporate security policies.
- Adopt complex hybrid connectivity solutions to link on-premise and cloud based systems.
- Establish scalable IAM hierarchies, cross-account trust relationships, and organizational units across multiple cloud tenants.
- 2. Infrastructure Resiliency & Disaster Recovery (DR)
- Architect high-availability (HA) and disaster recovery topologies across disparate cloud providers to eliminate single points of failure (e.g., active-active cross-cloud replication).
- Develop, document, and test automated failover mechanisms for critical enterprise workloads to ensure zero-downtime objectives.
- 3. Infrastructure as Code (IaC) & Automation
- Define, build, and maintain the the IaC repository using automation platforms.
- Implement secure CI/CD deployment pipelines (Jenkins, GitHub Actions) embedded with automated security guardrails and static analysis tools.
- 4. Technical Advisory & Collaboration
- Serve as the primary subject matter expert (SME) on cloud infrastructure for the core Cyber Security team, translating security objectives into concrete cloud configurations.
- Collaborate with traditional on-prem network and sysadmin teams to systematically migrate or extend legacy workloads to the cloud without disrupting active operations.
Required Skills & Experience:
- Enterprise Scale: Minimum 8+ years of experience managing, architecture-designing, and deploying IT infrastructure within a Fortune 500 or equivalent large-scale enterprise.
- Multi-Cloud Mastery: Deep, hands-on production experience with at least two major cloud vendors (AWS and Azure are highly preferred). You know their native networking, identity systems, and edge security controls inside out.
- Networking: Strong foundational background in traditional on-premises networking (firewalls, load balancers, VLANs, proxies) and how those concepts map directly to cloud-native constructs (VPCs, VNets, Transit Gateways).
- Automation-First Mindset: Advanced proficiency with automation toolsets.
- Pragmatic Security Knowledge: While you don't need to be a penetration tester, you must thoroughly understand cloud security frameworks and modern identity protocols.
- Scripting & Systems Proficiency: Strong proficiency with Python programming, Shell scripting, and Unix/Linux operating systems.
Desired Certifications:
(While your hands-on experience matters most, we highly value the following credentials)
- AWS Certified Solutions Architect – Professional / AWS Certified Security – Specialty
- Microsoft Certified: Azure Solutions Architect Expert / Azure Security Engineer Associate
- CCSP (Certified Cloud Security Professional) or equivalent infrastructure-focused certifications
Preferred / Plus Qualifications:
- Familiarity with Secure Email Gateway (SEG) products such as Proofpoint and Fortimail
- Familiarity with Exchange-Online security products such as Sublime security and Abnormal Email Security
- Experience with large scale email broadcast or bulk messaging platforms
- Exposure to compliance frameworks, audits, and regulatory examinations
- Experience integrating email platforms with monitoring, logging, and AIOps tooling
- Prior experience mentoring senior or mid level engineers
Russell Tobin is an equal opportunity employer. We do not discriminate on the basis of the race, religious creed, color, national origin, ancestry, physical disability, mental disability, reproductive health decision making, medical condition, genetic information, marital status, sex, gender, gender identity, gender expression, age, sexual orientation, veteran or military status, or any other characteristic protected by applicable federal, state, or local law.
Russell Tobin is a Fair Chance employer. We consider all qualified applicants, including those with criminal histories, in a manner consistent with applicable state and local Fair Chance laws and ordinances, including, the California Fair Chance Act and all applicable local Fair Chance ordinances.
Accommodations
We are committed to providing reasonable accommodations to applicants and employees with disabilities. If you require a reasonable accommodation to participate in the application or interview process, or to perform the essential functions of this role, please contact us.
Only applicable for San Francisco Candidates
Under the San Francisco Lactation in the Workplace Ordinance, we will provide written notice of lactation accommodation rights, and this notice will automatically be given upon hiring, any inquiry of parental leave or lactation accommodation.