The Role
Designs and governs secure multi-cloud architectures across AWS, Azure, and GCP. Responsibilities include zero-trust landing zones, IAM and RBAC, encryption and key management, container and Kubernetes security, CSPM and CWPP integration, policy-as-code automation, DevSecOps security testing, and incident-response readiness. The role requires extensive enterprise infrastructure security experience, cloud security architecture expertise, infrastructure-as-code knowledge, threat modeling skills, and a mandatory security certification.
Summary Generated by Built In
This is a remote position.
Cloud Security Architect (AWS / Azure / GCP)
Job Details
- Employment Type: Contract
- Work Mode: Remote
- Location: Offshore
- Total Experience Required: 8 to 12 years
- Relevant Experience Required: 5+ years of dedicated cloud security architecture experience across public cloud infrastructures
- Mandatory Certification: Certified Information Systems Security Professional (CISSP), CCSP, AWS Certified Security - Specialty, or Microsoft Certified: Azure Security Engineer Associate
Job Summary
We are seeking an experienced Cloud Security Architect to design, govern, and secure our enterprise multi-cloud infrastructure. The ideal candidate will establish cloud security blueprints, architect zero-trust landing zones, secure containerized microservices, and build guardrails to automate compliance and protect cloud-native applications from sophisticated threats.
Key Responsibilities
- Design and govern cloud security architectures across public cloud platforms (AWS, Azure, and GCP), establishing foundational multi-tenant landing zones and zero-trust perimeters.
- Configure Identity and Access Management (IAM) strategies, defining least-privilege access rules, role-based controls (RBAC), multi-factor authentication (MFA), and federated identity lifecycles.
- Implement cloud data protection layers, managing end-to-end cryptography, key management services (KMS), hardware security modules (HSM), and data-loss prevention (DLP) rules for data at rest and in transit.
- Secure containerized microservices environments, designing runtime security boundaries, image vulnerability scanning protocols, and network policy controls for Kubernetes (EKS/AKS/GKE).
- Integrate Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platforms (CWPP), writing automated policy-as-code scripts to enforce security configuration standards.
- Collaborate with DevSecOps engineering teams to embed automated security testing utilities, static/dynamic application analysis (SAST/DAST), and secret management vaults directly into CI/CD pipelines.
- Lead incident response readiness architecture, designing cloud telemetry dashboards, log aggregation feeds (SIEM), and automated threat hunting triggers to accelerate breach containment.
Requirements
- 8 to 12 years of core enterprise infrastructure security experience, with 5+ dedicated years actively designing, building, and governing multi-cloud safety frameworks.
- Strong technical mastery of cloud networking security components (VPC architecture, firewalls, WAF, DDoS protection), infrastructure-as-code scripting (Terraform, CloudFormation), and threat modeling.
- Deep structural understanding of cloud computing vulnerabilities, container security paradigms, API gateway perimeters, and modern cryptography standards.
- Mandatory certification: CISSP, CCSP, or cloud vendor-specific expert security certification (e.g., AWS Security Specialty / Azure Security Engineer).
Preferred Qualifications
- Prior experience implementing security frameworks within heavily regulated environments (e.g., PCI-DSS, HIPAA, SOC 2, ISO 27001).
- Familiarity with scripting languages (Python, Bash, Go) used to automate security compliance remediation flows.
Skills Required
- 8 to 12 years of core enterprise infrastructure security experience
- 5+ years of dedicated cloud security architecture experience across public cloud infrastructures
- Experience designing, building, and governing multi-cloud security frameworks
- CISSP, CCSP, AWS Certified Security Specialty, or Microsoft Certified Azure Security Engineer Associate certification
- Technical mastery of VPC architecture, firewalls, WAF, DDoS protection, Terraform, CloudFormation, and threat modeling
- Understanding of cloud vulnerabilities, container security, API gateway perimeters, and modern cryptography standards
- Experience with regulated-environment frameworks such as PCI-DSS, HIPAA, SOC 2, or ISO 27001
- Familiarity with Python, Bash, or Go for security compliance automation
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
FyerX is a Bengaluru-based digital marketing agency that helps businesses strengthen their online presence and generate leads and sales. Its services span branding, logo and brand-guideline development, photography and video production, UI/UX design, website development, social media marketing, search engine optimization, email marketing, ecommerce marketing, and digital advertising across platforms such as Google, Facebook, Instagram, and YouTube.








