Senior Cloud Security Architect
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+24 more
Job description
AgreeYa is seeking an experienced Senior Cloud Security Architect to lead the strategic vision and architecture for securing enterprise multi-cloud environments. This role is responsible for designing scalable, secure, and automated cloud security frameworks across AWS, Azure, and GCP ecosystems. The ideal candidate will possess deep expertise in Zero Trust Architecture, Security-as-Code, DevSecOps, AI/ML security, cloud governance, and automated compliance enforcement., The Senior Cloud Security Architect will partner with cloud engineering, DevOps, infrastructure, and executive leadership teams to develop enterprise-wide security guardrails that enable secure innovation while maintaining regulatory and operational compliance., * Lead the design and implementation of enterprise-wide Zero Trust security architecture, including identity governance, micro-segmentation, encryption, and secure access controls across AWS, Azure, and GCP environments
- Architect and implement security frameworks for AI/ML pipelines and LLM-integrated applications, focusing on data privacy, model integrity, and protection against emerging AI-related threats
- Develop and enforce Policy-as-Code and Security-as-Code frameworks using Terraform and automation tools to ensure secure and compliant infrastructure deployments
- Design and oversee integration of CNAPP, CSPM, and cloud-native security platforms to monitor misconfigurations, vulnerabilities, permissions, and cloud security posture in real time
- Conduct advanced threat modeling, risk assessments, and resilience planning for cloud-native applications and distributed systems
- Define secure architecture patterns, standards, and automated security guardrails for enterprise cloud environments
- Serve as the primary security advisor to cloud architecture and engineering teams, balancing DevOps agility with enterprise security and compliance requirements
- Integrate automated security testing tools including SAST, DAST, and SCA into CI/CD pipelines to enable secure software delivery practices
- Collaborate with infrastructure, networking, DevOps, and compliance teams to ensure alignment with enterprise cybersecurity strategy and regulatory standards such as SOC2, NIST, and CIS Benchmarks
- Develop automation and orchestration solutions using Python, Go, or Bash to support security operations and SOAR integrations
- Evaluate emerging technologies, evolving threats, and cloud-native security capabilities to strengthen enterprise cybersecurity posture
- Present security architecture recommendations, risk assessments, and strategic roadmaps to executive leadership and stakeholders
Requirements
Do you have experience in Solution architecture design?, * 12+ years of experience in Cybersecurity, including 6+ years focused on architecting secure enterprise cloud environments at scale
- Strong expertise in AWS, Azure, and/or GCP cloud security architecture and governance
- Deep understanding of Zero Trust Architecture, Identity-First Security, CIEM, Just-In-Time (JIT) access, OIDC, and SAML authentication flows
- Hands-on experience implementing Security-as-Code and Infrastructure-as-Code using Terraform or similar automation frameworks
- Experience integrating and managing cloud-native security platforms such as:
- AWS Security Hub
- Microsoft Defender for Cloud
- GCP Security Command Center
- Strong DevSecOps expertise with automated integration of SAST, DAST, SCA, and security controls into CI/CD pipelines
- Advanced knowledge of secure cloud networking including:
- SD-WAN
- Cloud WAF
- Zero Trust Network Access (ZTNA)
- Network segmentation and secure connectivity
- Experience with CNAPP, CSPM, cloud posture management, and automated compliance monitoring
- Strong scripting and automation skills using Python, Go, Bash, or similar technologies
- Experience performing cloud threat modeling, security architecture reviews, and resilience analysis for enterprise systems
- Strong communication, leadership, and stakeholder management skills with the ability to influence enterprise security decisions, * Industry-recognized cloud and cybersecurity certifications such as:
- CISSP
- CCSP
- AWS Certified Security - Specialty
- Azure Security Engineer Associate
- Google Professional Cloud Security Engineer
- Experience securing AI/ML and LLM-based environments
- Experience implementing automated auditing and compliance frameworks aligned with NIST and CIS Benchmarks
- Prior experience presenting cybersecurity strategies and risk posture to executive leadership and C-suite stakeholders
Education Required:
- Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, Engineering, or a related field
- Advanced degree preferred
- Equivalent relevant experience may be substituted in lieu of formal education requirements, * Do you have experience in multi-cloud security architecture (AWS, Azure, GCP)?
- Do you have experience in Zero Trust, Security-as-Code, automation and AI security ?
Benefits & conditions
$75 - $80 an hour - Contract, Pulled from the full job description
- Health insurance
- Vision insurance
- Dental insurance, * Dental insurance
- Health insurance
- Vision insurance
About the company
AgreeYa is a global systems integrator delivering competitive advantage for its customers through software, solutions, and services. Established in 1999, AgreeYa is headquartered in Folsom, California, with a global footprint and a team of more than 2,200 staff across offices. AgreeYa works with 500+ organizations ranging from Fortune 100 firms to small and large businesses across industries such as Telecom, Banking, Financial Services & Insurance, Healthcare, Utility & Energy, Technology, Public sector, Pharma & Biotech, and others. Please visit us at www.agreeya.com for more information.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud
7 Cloud Computing Trends Coming in 2025 for Developers
Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence