Context
- For a large enterprise environment undergoing a significant cloud transformation, we are looking for an experienced Cloud Security Architect with a strong focus on AWS.
- You will join the Security Architecture team within the CISO Office and act as a technical authority on cloud security. The role combines hands-on cloud security expertise with architecture governance: defining security patterns and controls, reviewing and challenging solution designs, identifying risks and supporting engineering teams in implementing Security by Design.
Responsibilities
- Define cloud security standards, guardrails, patterns and reference architectures.
- Design security controls for AWS environments, with Azure as an additional plus.
- Define secure architectures around IAM, networking, encryption, containers, logging and monitoring.
- Review and challenge cloud solution architectures from a security perspective.
- Perform threat modelling and architecture risk assessments.
- Identify security gaps and define appropriate remediation measures.
- Contribute to and further develop the Cloud Security Control Framework.
- Define reusable security blueprints for cloud and cloud-native technologies.
- Support engineering teams during architecture, design and implementation.
- Embed Security by Design and Zero Trust principles across cloud initiatives.
- Collaborate with Security Risk and Security Operations teams.
- Assess the security implications of emerging cloud technologies and AI services.
- Participate in architecture governance and review boards.
Profile
- 10+ years of experience within IT / Cybersecurity.
- 5+ years of experience in Cloud Security Architecture.
- Strong hands-on expertise with AWS security architecture.
- Proven experience defining cloud security controls, patterns, guardrails and reference architectures.
- Experience with threat modelling and cloud architecture security assessments.
- Strong knowledge of:
- AWS IAM
- VPC, Transit Gateway, Security Groups & NACLs
- EKS / ECS & container security
- KMS, encryption & secrets management
- GuardDuty, Security Hub, Inspector & WAF
- Logging, monitoring & detection
- Terraform / CloudFormation
- DevSecOps & security automation
- Familiar with frameworks such as NIS2, ISO 27001, CIS and NIST CSF.
- AWS Security Specialty certification is a strong plus.
- Able to challenge architects and engineering teams while remaining pragmatic and solution-oriented.
- Fluent in English. Dutch and/or French is a plus.
What we are looking for
- We are looking for a genuine Cloud Security Architect rather than a general Enterprise Architect or GRC profile. You should be technically comfortable going deep into AWS architecture and translating security risks into concrete technical controls.
📌 Cloud security architect (España)
🏢 recurv
📍 España