External Perimeter Security Architect
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+10 more
Job description
Perimeter & Network Security Architecture
- Lead the assessment, redesign, and modernization of the organization’s external perimeter security architecture.
- Conduct feasibility analyses and develop phased remediation roadmaps, with comprehensive documentation maintained in Confluence.
- Perform detailed connection-by-connection reviews of high-risk network paths, identifying secure alternatives and prioritizing remediation activities.
- Design and implement security controls across on-premises, cloud, and hybrid environments while maintaining operational efficiency and minimizing business disruption.
- Establish scalable network segmentation and Zero Trust architectures to reduce attack surface and contain potential threats.
AWS Security Architecture & Hardening
- Design and implement AWS Service Control Policies (SCPs), Resource Policies, and VPC Endpoint strategies to enforce security boundaries and workload isolation.
- Strengthen IAM architecture through secure access models, governance controls, and preventive guardrails.
- Implement encryption and secure data flow controls for data in transit and at rest.
- Assess and remediate security risks across multiple AWS accounts, prioritizing efforts based on business impact and risk exposure.
- Leverage AI-assisted security and automation tools to improve architecture review, analysis, and remediation workflows.
CI/CD & Infrastructure as Code (IaC) Security
- Evaluate, design, and enhance the security of CI/CD pipelines and Infrastructure-as-Code implementations.
- Identify pipeline risks and implement security controls that support secure software delivery practices.
Security Architecture Governance & Risk Management
- Conduct ongoing security architecture reviews to ensure design integrity throughout the technology change lifecycle.
- Map security findings to adversary tactics, techniques, and procedures (TTPs) to improve detection coverage during remediation efforts.
- Identify, assess, and prioritize operational and architectural risks discovered throughout the engagement.
- Provide actionable recommendations and executive-ready reporting that supports strategic decision-making.
Requirements
Core Security Architecture Expertise
- Deep expertise in network security architecture, including traditional perimeter security technologies and SD-WAN environments.
- Strong practical experience implementing Zero Trust security principles and architectures.
-
Advanced knowledge of AWS security services and best practices, including:
- AWS Control Tower
- AWS Security Hub
- AWS Config
- Amazon GuardDuty
Strong understanding of cloud networking, hybrid-cloud integration patterns, and multi-account AWS security management.
Expertise in encryption technologies and secure data protection strategies for data at rest and in transit.
Proven experience leading large-scale security architecture assessments and remediation programs. Additional Technical Experience
- Working knowledge of Privileged Access Management (PAM) concepts and controls.
- Experience securing CI/CD platforms and automation frameworks such as Jenkins, Ansible, GitHub Actions, GitLab CI/CD, or similar technologies.
- Familiarity with threat modeling, attack path analysis, and security control validation methodologies.
AI & Modern Engineering Tools
- Hands-on experience using AI-powered development or security tooling, such as Claude Code, OpenAI Codex, Gemini CLI, or similar AI coding agents, in professional or personal projects.
- Ability to integrate AI-assisted solutions into security architecture, assessment, and remediation workflows., * AWS Security Specialty, Solutions Architect, CISSP, CCSP, SABSA, or equivalent security certifications.
- Experience designing and implementing enterprise-scale Zero Trust transformation programs.
- Strong stakeholder management, documentation, and communication skills with the ability to present complex security concepts to both technical and executive audiences.
Ideal Candidate: A hands-on security architect who can bridge traditional network security and modern cloud-native architectures, driving measurable risk reduction through pragmatic, scalable, and business-aligned security solutions.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.dice.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
The Overflow: Security and Privacy
Navigating the AI Shift
Dev Digest 134 - Where pixels sing?
Dev Digest 196: AI Killed DevOps, LLM Political Bias & AI Security