> Markdown version of [/jobs/ext/596837-cloud-security-architect](https://www.wearedevelopers.com/jobs/ext/596837-cloud-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud Security Architect - **Company:** Tata Consultancy Services Limited - **Location:** Irvine, CA, United States - **Salary:** $120,000.0 - $140,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), .NET Framework, Amazon Web Services, Amazon Elastic Compute Cloud, Software System Penetration Testing, Burp Suite, Cloud Computing Security, Code Review, Cyber Security, Computer Networks, Custom Software, Data Centers, Database Security, DevOps, Middleware, Oracle Exadata, Federated Identity Management, Identity and Access Management, Intrusion Detection Systems, Microsoft SQL Server, Windows Servers, Network Segmentation, Oracle (Applications), Role-Based Access Control, Red Hat Enterprise Linux, Fortify (Software), Zero Trust Network Access, Security Information and Event Management, Data Logging, HybridCloud, Information Technology, Nessus, Enterprise Integration, Checkmarx, Firewall Services Module, TIBCO (Software), Qualys, Vulnerability Analysis - **Published:** June 20, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=70060655e714714f ## About the Role Do you have experience in Zero Trust security?, Do you have a Bachelor's degree?, Must Have Technical/Functional Skills * Strong expertise in AWS cloud security architecture including IAM, KMS, GuardDuty, and CloudTrail. * Deep understanding of AWS Landing Zone, SCPs, governance, and enterprise security guardrails. * Experience with security for custom applications including vulnerability identification and remediation. * Proficiency with VAPT tools such as Nessus, Qualys, Burp Suite, Fortify, and Checkmarx. * Strong understanding of WAF, firewall management, IDS/IPS, and network segmentation. * Knowledge of OS-level security for Windows Server 2016-2025 and RHEL 7/8/9. * Familiarity with securing Java, .NET, TIBCO ESB, and integration-heavy workloads. * Understanding of database security for Oracle 19c, Exadata on AWS, and SQL Server. * Ability to apply Zero Trust, least privilege, encryption, and secure-by-design principles. * Strong collaboration skills across infra, app, DB, network, and DevOps teams., * Hands-on experience designing secure AWS multi-account Landing Zones and guardrail policies. * Strong understanding of EC2 security, IAM, encryption, and identity federation models. * Integration knowledge for Oracle Exadata on AWS, SQL Server, and middleware security flows. * Experience with AWS WAF, Shield, GuardDuty, Security Hub, and detective controls. * Ability to design security for EKS workloads including pod/network policies and image scanning. * Understanding of security in hybrid cloud migrations and AWS migration tooling., Qualifications : BACHELOR OF COMPUTER SCIENCE ## Description * Lead cloud security architecture for the Data Center Exit migration to AWS EC2. * Design and implement AWS Landing Zone security including IAM guardrails, SCPs, and logging. * Conduct application and infra vulnerability assessments and define remediation plans. * Implement WAF rules, firewall policies, secure segmentation, and endpoint protection. * Validate authentication, authorization, and encryption models for all migrated workloads. * Support secure deployment practices, code reviews, and remediation of development gaps. * Integrate SIEM systems with AWS native security tools for continuous monitoring. * Define and enforce cloud security baselines aligned with CIS, NIST, and ISO controls. * Lead penetration testing cycles and coordinate mitigation activities. * Produce security HLD/LLD, risk assessments, and operational security runbooks. ## Related Videos - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Trust Issues: Because Zero-Trust Isn’t Optional Anymore](https://www.wearedevelopers.com/videos/100089-trust-issues-because-zero-trust-isn-t-optional-anymore) - [#90DaysOfDevOps - The DevOps Learning Journey](https://www.wearedevelopers.com/videos/548-90daysofdevops-the-devops-learning-journey) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)