What are the responsibilities and job description for the Cloud Security Architect position at System Soft Technologies?
Job Title: Cloud Security Architect
Location: Colorado Springs CO (Must be Local)
Duration: 6 Months
Position Summary
Our client is seeking an experienced Cloud Security Architect to lead the security strategy, governance, and compliance efforts for a modern Azure-based data platform. This role will be responsible for establishing security standards, ensuring regulatory compliance, designing identity and access controls, protecting sensitive data, and providing ongoing security oversight throughout the platform lifecycle.
The ideal candidate will possess strong expertise in cloud security architecture, regulatory compliance, risk management, identity governance, data protection, and security operations within Microsoft Azure environments.
Key Responsibilities
Security Strategy & Risk Management
- Develop and maintain the overall security architecture and strategy for the enterprise data platform.
- Identify, assess, and mitigate security risks throughout the project lifecycle.
- Ensure security requirements are incorporated into architecture, design, and implementation decisions.
- Collaborate with business and technical stakeholders to align security objectives with organizational goals.
Compliance & Regulatory Governance
- Interpret and apply applicable compliance and regulatory requirements, including:
- CJIS
- HIPAA
- NIST
- State and Federal Security Standards
- Ensure cloud platforms, applications, and data environments meet compliance obligations.
- Support audit readiness and regulatory assessments.
Identity & Access Management
- Design and govern role-based access control (RBAC) and least-privilege access models.
- Establish identity governance frameworks and access review processes.
- Define authentication, authorization, privileged access, and conditional access standards.
- Collaborate with infrastructure and application teams to ensure secure user provisioning and access management.
Data Protection & Security Architecture
- Establish enterprise standards for protecting sensitive and regulated data.
- Design security controls for employee, financial, citizen, public safety, and operational data.
- Implement encryption, data classification, key management, retention, and data loss prevention strategies.
- Ensure secure data handling throughout the data lifecycle.
Network & Connectivity Security
- Review and approve secure network connectivity designs between:
- Azure environments
- On-premises systems
- Third-party vendors
- External integrations
- Ensure implementation of secure connectivity controls, segmentation, and access restrictions.
Security Monitoring & Incident Response
- Define security monitoring, alerting, and incident response frameworks.
- Establish processes for threat detection, investigation, escalation, and remediation.
- Collaborate with operational teams to ensure rapid response to security events.
- Support implementation of SIEM, monitoring, and security analytics capabilities.
Security Validation & Readiness
- Conduct security architecture reviews and security assessments throughout project phases.
- Validate that security controls are operating effectively before production deployment.
- Perform risk assessments, vulnerability reviews, and security readiness evaluations.
Ongoing Security Governance
- Provide continuous oversight following production deployment.
- Support internal and external audits.
- Conduct compliance reviews and policy assessments.
- Recommend and implement security improvements based on evolving threats and business requirements.
- Maintain security standards, procedures, and governance documentation.
Required Qualifications
- Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Systems, or a related field.
- 8 years of experience in Information Security, Security Architecture, or Cloud Security.
- Strong expertise in Azure Security, Identity & Access Management, and Cloud Governance.
- Experience implementing security frameworks such as NIST, CJIS, HIPAA, ISO 27001, or similar standards.
- Experience with risk management, compliance assessments, and security governance programs.
- Strong understanding of network security, data protection, encryption, and incident response processes.
- Excellent communication and stakeholder management skills.