Principal Cybersecurity Engineer/Architect

RED SKY Consulting

United States

On-site

USD 170,000 - 260,000

Full time

12 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

RED SKY Consulting is seeking a Principal Cybersecurity Architect/Engineer to drive CNAPP implementations across Azure and AWS, focusing on secure-by-default designs and automation.

You will own security architecture, cloud guardrails, IAM, network segmentation, and workload security, collaborating with product and platform teams to meet FedRAMP and regulatory requirements.

Qualifications

  • Bachelor's degree or equivalent experience in a technical field.
  • 10+ years in security engineering/architecture with strong cloud security.
  • Hands-on CNAPP deployment and policy design at scale.
  • Experience with IaC, Terraform Enterprise/Cloud, and policy-as-code.
  • Familiarity with FedRAMP/NIST/CIS controls and cloud compliance.

Responsibilities

  • Lead CNAPP implementation and policy design across Azure and AWS.
  • Harden cloud footprints and enforce guardrails and IAM controls.
  • Integrate security into CI/CD pipelines and Terraform workflows.
  • Translate regulatory requirements into technical controls and evidence.
  • Advise on secure cloud designs and mentor engineers.
  • Partner with SecOps/AppSec to improve posture and respond to findings.

Skills

Cloud security architecture
Azure security
CNAPP (Wiz)
Terraform/IaC
CI/CD security

Education

Bachelors in CS/Engineering

Tools

Wiz
Terraform
Azure Defender for Cloud
Kubernetes security
Bicep/ARM

Job description

Job Title: Principal Cybersecurity Architect / Engineer

Location: Remote in US (EST Ideal)

Type: Direct Hire

  • Top 3-5 Must Have Skills for the Position: Principal-level cloud security architecture/Engineer in Azure with the ability to drive design decisions and guide implementations for a FedRAMP-targeted environment.
  • Strong hands-on cloud security engineering: Terraform/IaC, YAML, configuring and hardening Azure services, securing CI/CD pipelines for AKS/Kubernetes.
  • CNAPP experience with Wiz (strongly preferred) or Microsoft Defender for Cloud; ability to fine-tune policies and configure Admission Controller for container/workload compliance.
  • Familiarity with FedRAMP Moderate/High and FIPS L2/L3 cryptography requirements, and related compliance processes for regulated environments.
  • Excellent communication and cross-functional collaboration across time zones; able to consult, advise, and work with APJ and North America teams; U.S.-based with U.S. Citizen preferred (GC acceptable).
Job Description:

The Cloud Security team is seeking a Principal Cloud Security Engineer to serve as a hands-on technical expert and trusted advisor across our cloud programs. Our team owns the security of multiple cloud environments-primarily Azure and AWS and the implementation of security controls to meet regulatory requirements across geographies. Beyond identifying issues, we partner closely with product and platform teams to design and deliver secure cloud-based solutions.

You will lead CNAPP implementation, harden our Azure and AWS footprint, embed security into CI/CD and Terraform workflows, and support our path to FedRAMP, PBMM, and other public-sector compliance programs.

In this role, you will develop and drive the implementation of our Cloud Security Architecture and CNAPP architecture-defining secure-by-default reference patterns, guardrails, and scalable control implementations for Azure (primary) and AWS (in scope). You will partner with platform engineering, SRE, product, and compliance teams to translate architectural intent into actionable engineering work and measurable posture improvements.

You will map regulatory requirements (e.g., FedRAMP, NIST SP 800-53, PBMM, GC Cloud Guardrails, ITSG-33 or equivalent) to cloud security capabilities such as identity and access management, network segmentation, encryption and key management, logging/monitoring, vulnerability management, container/Kubernetes security, and continuous compliance. You will then engineer, implement, and operationalize these controls using cloud-native services and Wiz (policies, sensors, and workflows), integrated into Terraform and CI/CD pipelines with policy-as-code, drift detection, and automated evidence where feasible.

You’ll thrive in a dynamic, fast-paced environment, operate as a self-starter, work independently, and stay relentlessly results-oriented.

What You'll Do
  • Lead CNAPP implementation: Plan and execute end-to-end rollout of Wiz (and related CNAPP tooling) across Azure (and select AWS), including policy design, tuning, and alert-to-action workflows.
  • Harden clouds at scale: Design and enforce guardrails (Azure Policy, Defender for Cloud plans, identity controls, network segmentation, logging/monitoring) and extend patterns to AWS where applicable.
  • DevSecOps & IaC governance: Embed security into CI/CD and Terraform workflows (pre-merge checks, plan/policy gates, artifact signing, SBOMs/attestations) and establish reusable modules and policy-as-code patterns to prevent misconfigurations before deploying; enforce baselines at plan time.
  • Compliance engineering: Translate FedRAMP, CIS, and other frameworks into technical controls, automated evidence, continuous monitoring, and remediation playbooks.
  • Cloud security architecture & blueprint: Own and evolve the cloud security reference architecture (standardized landing zones, identity and access patterns, network segmentation, encryption standards, logging/monitoring baselines, and guardrails) for Azure (primary) and AWS (in scope); advise product and platform teams on secure designs, lead design reviews, and mentor engineers.
  • Incident & posture improvement: Partner with SecOps and AppSec teams to triage findings, evaluate risks, recommend remediation steps, and drive measurable improvements across vulnerabilities, identities, data, and workloads.
  • Executive advisory: Communicate risk, trade-offs, and roadmaps to senior leadership; influence prioritization through clear metrics and business outcomes.
  • Build automated guardrails and drift detection/auto-remediation using Terraform (and/or Bicep/ARM where applicable), integrating controls into CI/CD to consistently enforce secure defaults.
  • Kubernetes/AKS security: Partner with platform teams to harden AKS (RBAC, network policies, workload identity), implement admission controls, and operationalize Wiz Sensors and CNAPP findings into engineering workflows and secure runtime baselines.
What You Bring
  • Bachelor's degree in Computer Science, Engineering, or related field (or equivalent experience).
  • 10+ years in security engineering/architecture with significant cloud security experience (SaaS or technology companies preferred).
  • Deep, hands-on expertise with:
  • CNAPP (Wiz or equivalent) deployment at scale, policy design, tuning, automation; and Microsoft Defender for Cloud (policies, plans, recommendations, regulatory compliance, alerting).
  • DevSecOps / CI/CD: integrating security tests and gates in GitHub Actions (or similar), artifact/image scanning, and automated compliance evidence; securing pipeline identities, secrets, and supply chain integrity.
  • Infrastructure as Code (IaC): production-grade Terraform Enterprise/Terraform Cloud (modules, registries, workspaces), plan-time checks, and drift control.
  • Policy engineering: designing and implementing cloud security policies (Azure Policy initiatives; OPA/Sentinel policy-as-code) and mapping to frameworks (NIST, CIS).
  • Azure security (Entra ID/AAD, RBAC, networking, Key Vault, monitoring).
  • Multi-cloud, hands-on experience with Azure and AWS services.
  • Container and Kubernetes security: cluster hardening, workload identity/RBAC, network policies, admission controls, image signing/verification, runtime protection, and container registries (ACR/ECR, JFrog Artifactory).
  • Security automation: scripting (e.g., Python/PowerShell) to build guardrails, detections, and tooling.
  • Experience establishing and reporting KRIs/KPIs and improving cloud security posture at scale using data-driven metrics (e.g., NIST, CIS, STIG).
  • Experience delivering cloud implementations in regulated environments, including U.S. Government / U.S. Public Sector requirements (FedRAMP, NIST SP 800-53) and Canadian Government / Public Sector requirements (PBMM, GC Cloud Guardrails, ITSG-33 or equivalent) - including control mapping, automation, and continuous monitoring.
  • Excellent stakeholder skills-operate as a trusted advisor to product, platform, compliance, and executive teams.
  • Self-starter who can work independently, communicate clearly, and drive cross-functional outcomes with a bias for automation and measurable posture improvement.
  • Proven track record operating as a Cloud Security Architect across CNAPP, Wiz, Terraform, and CI/CD pipeline architectures—defining cloud policies, integrating cloud-native and CNAPP controls, and leveraging their control frameworks for continuous compliance.
  • Hands-on experience securing Kubernetes (AKS) using Wiz Sensor tooling (deployment, operations, and integration with detection and remediation workflows).
Preferred Qualifications
  • Microsoft AZ-500, SC-100, SC-200 certifications strongly preferred.
  • One of the security certifications, such as CISSP or CCSP.
  • DevOps experience with infrastructure, cloud, and application pipelines.
  • Hands-on experience with container and image scanning; SAST, DAST; and penetration testing tools.
  • Knowledge of large language models (LLMs) and hands-on experience designing and building generative-AI-powered agents.
  • Experience with Python, Java, .NET, C#, Rego, and YAML.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote Principal Cloud Security Architect & CNAPP Leader
Remote Principal Cloud Security Architect & CNAPP Leader

RED SKY Consulting • United States

On-site
USD 170,000 - 260,000
Security Architect
Security Architect

YASH Technologies • Chicago (IL)

On-site
USD 120,000 - 150,000
Cloud Security Architect
Cloud Security Architect

Compunnel, Inc. • Cumberland (RI)

On-site
USD 130,000 - 180,000
Cyber Security SME
Cyber Security SME

Estuate, Inc. • Houston (TX)

On-site
USD 150,000 - 180,000
Senior Security Engineer
Senior Security Engineer

Fintech Staffing Partners • United States

Remote
USD 130,000 - 160,000
Senior Security Engineer
Senior Security Engineer

Hiring Our Heroes • Arlington (VA)

On-site
USD 120,000 - 150,000
Cloud Security Engineering Manager
Cloud Security Engineering Manager

CIBR Warriors • Town of Texas (WI)

On-site
USD 150,000 - 210,000
Senior Security Engineer
Senior Security Engineer

Zermount, Inc. • United States Virgin Islands

On-site
USD 100,000 - 150,000
Senior Vice President, Senior Cloud Security Engineer
Senior Vice President, Senior Cloud Security Engineer

BNY • New York (NY)

On-site
USD 120,000 - 160,000
Health insurance
Dental insurance
Vision insurance
+3
Cyber Security Architect
Cyber Security Architect

Altimetrik • Princeton (NJ)

On-site
USD 150,000 - 185,000