Cloud Security Architect/Engineer

DevSecOps, Inc.
Nashville, TN, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$125,000.0 - $150,000.0
Working hours
Regular working hours

Tech stack

Java (Programming Language) Artificial Intelligence Amazon Web Services C Sharp (Programming Language) Cloud Computing Security Computer Programming Identity and Access Management Python (Programming Language) Zero Trust Network Access Security Information and Event Management Data Logging Scripting
+7 more
Cloudformation Kubernetes Terraform Devsecops Docker Static Application Security Testing Dynamic Application Security Testing

Job description

Our client is seeking a Cloud Security Architect/Engineer to help design, build, and continuously improve secure AWS cloud environments-while also addressing modern risks across workforce security, DevSecOps, and AI/GenAI use cases. This role partners closely with engineering, product, enterprise systems, and data science teams to embed security into how systems are built and operated.

What You’ll Do:

Cloud Security Architecture

  • Design and implement secure cloud architectures in AWS.
  • Build and maintain security guardrails and standards (IAM, network segmentation, encryption, etc.).
  • Apply Zero Trust principles across cloud systems and user endpoints.
  • Secure containerized and serverless workloads (ECS, Kubernetes, Docker, Lambda, etc.).
  • Review existing cloud implementations, identify gaps, and drive remediation priorities.

Workforce / Identity Security

  • Define and enforce endpoint and access controls.
  • Improve identity lifecycle processes and privileged access management (PAM).
  • Partner with engineering teams to implement a secure VDI environment to support PHI access.

AI/ML & GenAI Security

  • Define security controls for AI/ML and GenAI applications.
  • Work with Data Science to reduce risks like model poisoning, prompt injection, data leakage, and adversarial attacks.
  • Secure agentic AI systems (autonomous workflows / decision-making agents).
  • Help embed security into the model development lifecycle (MLSecOps).

Compliance, Risk, and Assurance

  • Partner with GRC to support compliance with healthcare frameworks and regulations (HIPAA, HITRUST, SOC 2, etc.).
  • Perform risk assessments and threat modeling for cloud and AI systems.
  • Support audits by ensuring controls and documentation are in place.

Detection, Response, and Automation

  • Implement and tune cloud-native monitoring/detection (SIEM, CSPM, CWPP).
  • Build automated response/remediation workflows.
  • Support incident response for cloud security events.

DevSecOps

  • Integrate security into CI/CD pipelines and infrastructure-as-code (Terraform, CloudFormation).
  • Automate scanning and enforcement using tools and modern practices (SAST, DAST, SCA), including AI-assisted coding tools.
  • Partner with engineering to “shift security left.”

Leadership

  • Mentor teammates and promote best practices across teams.
  • Stay current on emerging cloud and AI security threats.

Requirements

  • 5+ years in cloud security or cybersecurity engineering.
  • Strong AWS security fundamentals (IAM, networking, encryption, logging/monitoring).
  • Experience securing containers (Kubernetes and/or Docker).
  • Experience working in regulated environments (HIPAA, HITRUST, SOC 2).
  • Experience implementing automation to improve security outcomes.
  • Experience with Zero Trust architecture concepts and implementation.
  • Scripting/programming ability (e.g., Python; familiarity with Java/Node.js/C# is a plus).
  • Ability to influence and lead cross-functional work without direct authority.

Nice-to-Haves

  • CISSP, CCSP, and/or AWS Security certifications.
  • Master’s degree in a relevant field.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on gravityitresources.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · WWC 2025

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

Videos

See all

Related articles

See all