> Markdown version of [/jobs/ext/1531448-sr-cloud-security-architect](https://www.wearedevelopers.com/jobs/ext/1531448-sr-cloud-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr Cloud Security Architect - **Company:** Lenovo - **Location:** Morrisville, NC, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Microsoft Windows, Active Directory, Amazon Web Services, Confluence, JIRA, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Computing Security, Code Review, Cyber Security, Data Security, Relational Databases, Linux, Fuzz Testing, Github, Identity and Access Management, Intrusion Detection Systems, Python (Programming Language), Lightweight Directory Access Protocols (LDAP), Microsoft SQL Server, MySQL, Network Architecture, Oracle (Applications), Open Web Application Security, Systems Development Life Cycle, Cloud Services, Ansible, Security Assertion Markup Language (SAML), Security Information and Event Management, Scripting, Software Security, Infrastructure Automation Frameworks, Information Technology, Bitbucket, Terraform, Devsecops, Docker, Jenkins, Static Application Security Testing, Artifactory, Dynamic Application Security Testing - **Published:** July 2, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/9208756?backUrl=%2Fcareer%2F9208756%2FSr-Cloud-Security-Architect-North-Carolina-Raleigh ## About the Role familiar with cloud cybersecurity best practices, modern DevSecOps automation tools. The candidate should also be skilled in both AWS and Azure Cloud Security. AliBaba AliCloud Security experiences is a plus. We are looking for someone with a security mindset who "thinks like an attacker"., 5+ years of experience with cloud security (security researcher, security engineer, security architect). Bachelor's Degree in Computer Science or related field, or additional 5+ years of cybersecurity experience 3+ years experience with AWS and Azure. 2+ Experience in: Infrastructure security, security SDLC and secure SaaS practices Cloud Product Threat modeling experience Preferred Qualifications: Experience doing code review for configuration management tools and scripting languages Experience with all DevSecOps Tool Types including SAST, DAST, IAST, Feature Flag Tools, Threat Modeling, Fuzzing, etc. Experience with FedRAMP certification Hand-on experience with AWS security best practices and AWS services Security standards and practices (CSA, OWASP, SANS, etc.) Security of relational databases (MySQL, MS SQL Server, Oracle) Security management certificates (CISSP, CSSLP, CISM, etc.) Has presented at security conferences (BlackHat, OWASP, etc.) Experience with as many of these as possible; Terraform, Ansible, Jira, Bitbucket, and Confluence, Artifactory, JFrog, GitHub, Jenkins GCP and AliCloud experience Experience with GDPR and CCPA Security reviews for code/design/architecture and requirements: Cloud Security standards such as CSA CCM, ISO 27017, ISO 27018, Fedramp etc. Infrastructure Security and IAC Security Container Security Docker & Kubernetes Security Identity management and authentication systems and protocols (Active Directory, LDAP, SAML, RADIUS) Linux/Unix and Windows OS Network architecture and security configurations Python Ensure their accurate completion 1 or more Cloud Security Certifications such as CCSK, CCSP, or SANs Cloud Related Certs ## Description Overview This position is for a Sr. Cloud Security Architect in the PCSD Security Center of Excellence. This is an exciting role where you will get to help create and drive cloud security strategy for a multi-billion dollar organization that is the #1 PC maker in the world. You will also get to help design and test the security of Lenovo's Cloud Products and Services. Job Description: Lenovo is searching for a Sr. Cloud Security Architect to join our PCSD Product Security Team to help lead the secure design & development of Global Lenovo Cloud Products and to help oversee the operational security of Cloud products in production. The Cloud Security Architect will work with Lenovo Engineering and Product teams around the world to continuously improve the security posture of all cloud products and services in alignment with Lenovo Security policies, standards, and processes as well as local, regional and international cloud security standards and regulations. The ideal candidate is, * Perform cybersecurity control and risk assessments of proposed and existing product and infrastructure architecture for compliance with Lenovo Requirements and international cloud security best practices, recommending technical, administrative and physical remediations and mitigations for identified risks and vulnerabilities * Develop service security and compliance requirements for SaaS multi-tenant systems * Design and develop cloud security architectures and perform architecture design reviews * Help Design, Implement and Oversee Operation of DevSecOps solutions to secure complex CI/CD pipelines * Implement, maintain and improve existing industry best practices of cloud security controls such as: o Monitoring & Logging o Identity and Access Management o Encryption o Data Security & Privacy o Incident Response & Forensics o WAF, RASP, SIEM, IDS/IPS, etc. * Provide guidance to R&D and Product Management on defining and prioritizing development of secure SaaS offerings * Prepare and deliver training and security awareness activities to the Engineering teams * Acquire relevant knowledge, remain up to date, attend cloud security conferences and be involved with the cloud security community * Drive and help lead cloud security strategy, tools, training, processes, and tactics ## Related Videos - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [MySQL Protocol Features You Should Be Aware Of](https://www.wearedevelopers.com/videos/100267-mysql-protocol-features-you-should-be-aware-of) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 162: AI careers, MCP, AWS best practices & floppy sweaters](https://www.wearedevelopers.com/magazine/571-dev-digest-162-ai-careers-mcp-aws-best-practices-floppy-sweaters) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)