Cloud Security Architect

Gridiron IT Solutions LLC
Washington, DC, United States
13 days ago

Role details

Contract type
Permanent contract
Employment type
Part-time / full-time
Experience level
Expert
Experience required
6 years minimum
Compensation
$156,000.0 - $208,000.0
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Amazon Web Services Microsoft Azure Bash Shell Cloud Computing Cloud Computing Security Cloud Engineering Encodings Cyber Security DevOps Identity and Access Management Information Security Management
+18 more
Python (Programming Language) Network Segmentation OpenID Zero Trust Network Access Security Assertion Markup Language (SAML) Wide Area Networks Policy as Code Google Cloud Large Language Models Multi-Cloud Cyber Threat Analysis Information Technology Machine Learning Operations CIS Benchmarks Terraform Devsecops Static Application Security Testing Dynamic Application Security Testing

Job description

As a Senior Cloud Security Architect, you will lead the strategic vision for protecting our multi-cloud ecosystem. You are responsible for designing the security blueprints that govern our entire digital footprint-from identity perimeters to AI-driven threat detection. This role requires a “Security as Code” mindset, where you build automated guardrails that empower developers to move at speed without compromising the safety of our data or infrastructure., * Security Architecture Vision: Lead the design of a global Zero Trust architecture, ensuring robust identity governance (IAM), network micro-segmentation, and data encryption across AWS, Azure, or Google Cloud Platform.

  • AI-Native Security Strategy: Architect specialized security frameworks for AI/ML pipelines, focusing on data privacy for training sets, model integrity, and securing LLM-integrated applications against emerging attack vectors.
  • Automated Guardrails (Policy as Code): Develop and enforce enterprise-wide security policies using Terraform, etc., ensuring that non-compliant infrastructure is automatically remediated or blocked from deployment.
  • Cloud Posture Management: Design and oversee the integration of CNAPP and CSPM tools to provide real-time visibility into misconfigurations, vulnerabilities, and excessive permissions.
  • Threat Modeling & Resilience: Conduct deep-dive threat modeling for complex cloud-native systems, simulating advanced persistent threats (APTs) and “blast radius” scenarios to strengthen system resilience.
  • Security Consultancy: Act as the lead security advisor for the Cloud Architecture team, bridging the gap between DevOps agility and rigorous regulatory compliance (SOC2)., * Zero Standing Privilege: Help Transition the organization to a “Zero Standing Privilege” model for all production environments.
  • Automated Compliance: Help Achieve automated auditing for core compliance frameworks (e.g., NIST, CIS Benchmarks).
  • Mean Time to Detect (MTTD): Utilize AI-driven monitoring to reduce the detection time of anomalous cloud activity to minimum

Requirements

Security Platforms Mastery of cloud-native security suites (e.g., AWS Security Hub, Azure Defender, Google Cloud Platform Security Command Center). Identity & Access Expert knowledge of Identity-First Security, including CIEM, Just-In-Time (JIT) access, and complex OIDC/SAML flows. Automation Proficiency in Python, Go, or Bash to build custom security automations and integrate with SOAR platforms. DevSecOps Deep experience embedding automated security testing (SAST/DAST/SCA) directly into CI/CD pipelines. Cloud Networking Advanced understanding of secure connectivity, including SD-WAN, Cloud WAF, and Zero Trust Network Access (ZTNA).

Preferred Experience

  • Experience: 12+ years in Cybersecurity, with at least 6 years focused on architecting secure cloud environments at scale.
  • Certifications: Top-tier credentials.
  • Education: Advanced degree in Computer Science, Cybersecurity, or a related engineering field.
  • Soft Skills: Strong ability to bridge the gap between “Speed of DevOps” and “Rigors of Security” while communicating clearly with executive leadership
  • Leadership: Proven ability to influence technical roadmaps and present security risks clearly to C-suite stakeholders.

Benefits & conditions

Clearance: Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information. Compensation and Benefits: Salary Range: $75/hr - $100/hr (Compensation is determined by various factors, including but not limited to location, work experience, skills, education, certifications, seniority, and business needs. This range may be modified in the future.) Benefits: Gridiron offers a comprehensive benefits package including medical, dental, vision insurance, HSA, FSA, 401(k), disability & ADD insurance, life and pet insurance to eligible employees. Full-time and part-time employees working at least 30 hours per week on a regular basis are eligible to participate in Gridiron’s benefits programs. Gridiron IT Solutions is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status or disability status. Gridiron IT is a Women Owned Small Business (WOSB) headquartered in the Washington, D.C. area that supports our clients’’ missions throughout the United States. Gridiron IT specializes in providing comprehensive IT services tailored to meet the needs of federal agencies. Our capabilities include IT Infrastructure & Cloud Services, Cyber Security, Software Integration & Development, Data Solution & AI, and Enterprise Applications. These capabilities are backed by Gridiron IT’’s experienced workforce and our commitment to ensuring we meet and exceed our clients’’ expectations.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira ¡ Coffee With Developers

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo ¡ LIVE

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum ¡ WWC Europe 2026

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis ¡ LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin ¡ WWC 2022

2:52 min

Implementing IAM with Keycloak and OpenID Connect

Thomas SßdbrÜcker ¡ LIVE

Videos

See all

Related articles

See all