Cloud Security Architect
Role details
Job location
Tech stack
Job description
This role is responsible for making our software secure by design and keeping it secure throughout its lifecycle - from architecture and development to deployment and operations. The Architect will define security standards, embed security into engineering workflows, and ensure our SaaS platform meets enterprise-grade security and compliance expectations.
A day in the life of our Cloud Security Architect:
- Define and maintain secure architecture patterns for cloud-native SaaS systems
- Review and approve system designs for security risks
- Lead threat modeling for new features and platform components
- Design secure multi-tenant isolation models
- Architect secure API frameworks and integration patterns
- Ensure tenant data isolation and encryption strategies
- Continuously improve Secure SDLC practices
- Define secure coding standards and guardrails
- Architect secure cloud environments
- Define IAM, least-privilege access models, and service-to-service authentication
- Participate in security audits and customer security reviews
- Lead security incident root-cause analysis for application-layer incidents
- Improve detection and monitoring for application-level threats
- Collaborate with SRE to ensure security does not compromise reliability, We have adopted a hybrid model that gives employees the ability to work remotely two days a week while ensuring that we come together as a team in the office the rest of the time. The designated in-office days are Tuesday through Thursday for innovation, collaboration and continuous learning.
Requirements
- 8+ years in software engineering, security engineering, or cloud architecture
- Strong expertise in cloud-native architecture (microservices, containers, Kubernetes)
- Deep understanding of application security (OWASP Top 10, secure coding)
- Strong knowledge of IAM, authentication protocols (OAuth2, OIDC, SAML)
- Experience designing secure multi-tenant SaaS systems
- Hands-on experience with one major cloud provider (AWS preferred), * Experience in enterprise SaaS environments
- Experience with regulated industries (FedRAMP, CMMC)
- Knowledge of tenant-based encryption models
- Experience implementing zero-trust architecture
- Background in vulnerability disclosure or bug bounty programs
Benefits & conditions
The salary range for this role is $240,000 - $260,000. Actual compensation packages within this range are based on a wide array of factors unique to each candidate and role requirements, including but not limited to skill set, years and depth of experience, certifications, and specific location.