What are the responsibilities and job description for the Cloud Security Architect :: Pittsburgh, PA (Onsite) position at CISO Aid?
HI
Hope you are doing well!
I have an urgent requirement with one of my clients. Please find the job details below and forward me your updated resume along with your contact details ajeet@realtekconsulting.net
Cloud Security Architect
Location :: Pittsburgh, PA
Job Summary
We are seeking an experienced Cloud Security Architect to design, implement, and govern secure cloud solutions across AWS, Azure, and/or Google Cloud Platform (GCP). The ideal candidate will have deep expertise in cloud security architecture, identity and access management, compliance frameworks, DevSecOps, and security automation. This role will partner with infrastructure, application, and security teams to ensure enterprise cloud environments meet business, regulatory, and security requirements.
Key Responsibilities
- Design and implement secure cloud architectures for AWS, Azure, and GCP.
- Develop enterprise cloud security standards, policies, and best practices.
- Perform cloud security assessments, architecture reviews, and threat modeling.
- Design and implement Zero Trust security architecture.
- Configure and manage Identity and Access Management (IAM), RBAC, MFA, and Privileged Access Management (PAM).
- Secure cloud-native services including compute, storage, networking, containers, Kubernetes, and serverless applications.
- Implement security controls for Infrastructure as Code (Terraform, CloudFormation, ARM/Bicep).
- Integrate security into CI/CD pipelines using DevSecOps practices.
- Implement cloud workload protection and container security solutions.
- Configure cloud-native security services such as:
- AWS Security Hub, GuardDuty, Inspector
- Microsoft Defender for Cloud, Microsoft Sentinel
- Google Security Command Center
- Develop cloud logging, monitoring, and incident response capabilities.
- Conduct vulnerability assessments and coordinate remediation activities.
- Ensure compliance with security standards including ISO 27001, SOC 2, NIST, CIS Benchmarks, HIPAA, PCI DSS, and GDPR.
- Implement encryption strategies for data at rest and in transit.
- Work with development teams to integrate secure coding practices.
- Participate in security audits, risk assessments, and penetration testing initiatives.
- Mentor engineering teams on cloud security best practices.
Required Skills
Cloud Platforms
- AWS
- Microsoft Azure
- Google Cloud Platform (GCP)
Cloud Security
- Cloud Security Architecture
- Zero Trust
- Secure Landing Zones
- Network Security
- Identity Security
- Encryption
- Secrets Management
- Cloud Governance
Identity & Access Management
- IAM
- Azure AD / Microsoft Entra ID
- AWS IAM
- GCP IAM
- MFA
- SSO
- OAuth
- SAML
- OpenID Connect
- PAM
DevSecOps
- CI/CD Security
- GitHub Actions
- Azure DevOps
- Jenkins
- GitLab CI
- Security Automation
- SAST
- DAST
- Software Composition Analysis (SCA)
Infrastructure as Code
- Terraform
- CloudFormation
- ARM Templates
- Bicep
- Ansible
Container Security
- Docker
- Kubernetes
- AKS
- EKS
- GKE
- Kubernetes Security
- Admission Controllers
Security Tools
- Prisma Cloud
- Wiz
- Lacework
- CrowdStrike Falcon
- Microsoft Defender for Cloud
- Microsoft Sentinel
- AWS GuardDuty
- AWS Security Hub
- AWS Inspector
- Google SCC
- Splunk
- QRadar
Networking
- Firewalls
- VPN
- WAF
- IDS/IPS
- Load Balancers
- DNS Security
- VPC/VNet
- Private Link
- Transit Gateway