> Markdown version of [/jobs/ext/239848-cloud-security-architect-337](https://www.wearedevelopers.com/jobs/ext/239848-cloud-security-architect-337). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud Security Architect (337) - **Company:** WSP - **Location:** United States - **Experience:** Expert - **Salary:** $86,100.0 - $150,590.0 - **Contract:** Permanent contract - **Skills:** Microsoft Azure, Software as a Service, Cloud Computing Security, Cyber Security, DevOps, Information Security Management, Intrusion Detection and Prevention, Key Management, Microsoft Security Essentials, Network Segmentation, Zero Trust Network Access, Software Engineering, Systems Integration, Software Security, Information Technology - **Published:** May 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=b9cc213147366537 ## About the Role * 5 + years of experience, including experience specializing in information security roles. * Strong analytical skills with a keen eye for detail and accuracy. * Experience designing security architecture for Azure-hosted platforms. * Experience with Azure Landing Zones (CAF-aligned) / enterprise-scale reference architecture. * Proven ability to translate regulatory and compliance requirements into enforceable technical architecture. * Familiarity with zero-trust architecture principles applied to Azure deployments. * Knowledge and experience using Microsoft security platforms, other vendor security systems are highly desirable. * Knowledge about advanced security capabilities, including integrations with other systems. * Prior participation in architecture review or governance forums.Strong written communication: you will author and review ADRs, security architecture documents, and pattern guides that vendor teams and corporate governance rely on. If you don't meet every qualification, we still encourage you to apply. Preferred Experience * Experience working in a regulated SaaS environment with multi-region data residency requirements. * Hands-on Infrastructure-as-Code experience.Experience working with third-party vendor development teams. Skills / Competency / Other requirements * Excellent written and spoken English. * Ability to work independently with low-level supervision and in a global team distributed geographically. * Strong organization skills (set priorities, meets deadlines, multiple simultaneous projects) and excellent documentation skills. * Excellent analytical and diagnostic problem-solving skills with the ability of providing solutions to identified problems. * Demonstrated experience in understanding, designing, delivering, and demonstrating compliance with information security requirements.Knowledge and experience in performing information security practices in the management and delivery of infrastructure and operations., * Bachelor's degree or equivalent experience in Information Technology, Computer Science, Engineering, or a related field.Advanced degrees or certifications are a plus but not required., The selected candidate must be authorized to work in the United States. ## Description This role is a hands-on, senior individual contributor responsible for designing, building, and operating secure, scalable Azure platform capabilities, while enforcing enterprise guardrails and compliance requirements. The successful candidate will work in a consultative capacity, owning platform roadmaps and backlogs, responding to intake requests, and providing architectural guidance and sign-off. You will have a governance dotted line to the Corporate Security & Compliance team, ensuring alignment with enterprise security policy., Security Architecture Design * Design and maintain the security architecture for the Digital Services Azure platform across all regions, including network segmentation, Private Endpoint strategy, and zero-trust network posture. * Architect the controls that align with enterprise security, compliance, and operational standards. * Define security patterns for vendor application teams: authentication flows, secrets management, API security, data-at-rest and data-in-transit encryption standards. * Identify gaps, risks, and opportunities for improvement across Azure environments.Contribute to standards, patterns, and reference architectures. Detection Engineering * Design and govern detection engineering.Define the security telemetry strategy: what gets collected, where it's stored, how long it's retained, and how it aligns with regional data residency constraints (noting that security telemetry is centralised by design). Governance & Compliance Architecture * Implement corporate security and compliance requirements within the Digital Services platform using policy-as-code (Azure Policy, custom initiatives) and automated evidence capture. * Design the compliance evidence architecture so that audit readiness is a continuous state. * Own security exception governance: assess exception requests, document risk acceptance, and ensure appropriate approval chains.Contribute to architecture decision records (ADRs) for all security-impacting design decisions. Cross-Team Security Standards * Define security architecture standards that apply horizontally across all Digital Services teams - platform engineering, vendor application development, and vendor DevOps. * Review and approve vendor security patterns and access models. * Work with the Development teams to embed security practices and controls.Serve as security escalation point for the platform engineering team during incidents. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [This Machine Ends Data Breaches](https://www.wearedevelopers.com/videos/574-this-machine-ends-data-breaches) - [Azure-Well Architected Framework - designing mission critical workloads in practice](https://www.wearedevelopers.com/videos/1529-azure-well-architected-framework-designing-mission-critical-workloads-in-practice) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market)