AWS Security AWS Cloud Security Architect/Remote
AWS Security AWS Cloud Security Architect – Landing Zone & Cyber Resilience/Remote
Remote
Duration: Long term
Required
Alternates depending on seniority/framing: Sr. Cloud Security Engineer – IRE/Clean Room,
Principal Security Architect – AWS Multi-Account, or Cloud Infrastructure Security Architect
(EKS + Governance).
Scope
Multi-account AWS architecture design, AWS Organizations, and landing zone governance
Security Lab foundation and account vending design
Isolated Recovery Environment (IRE) architecture: WORM vault, cross-account backup,
recovery orchestration, Clean Room forensic environment
Amazon EKS baseline and lab environment for testing security capabilities
Key Responsibilities
- WS-1: AWS Security Agent cloud infrastructure design and implementation support
- WS-2 : (Security Lab): Design multi-account lab foundation, centralized logging (CloudTrail,
- VPC Flow Logs, Config), OU structure, SCPs, and automated account vending
- WS-3 (IRE & Clean Room): Design IRE account with WORM vault locking, crossaccount/
- cross-region backup (3-2-1), CMKs, CyberArk break-glass, Macie integration,
- Network Firewall, Transit Gateway route isolation, and recovery orchestration
- WS-5: Design and implement Amazon EKS infrastructure configuration and the security lab
- environment
- Design Backup Audit Manager compliance framework
- Design Route 53 DNS isolation and hardened compute baselines
- Implement hardened compute baselines and secrets management
- Author IRE & Clean Room Architecture & Design Document and Security Lab Architecture
- Document
- Contribute to lab operations guide and account vending admin procedures