AWS-02 · CCoE Cloud Architect - Architecture & Security

MegazoneCloud

$150K — $180K *
Manufacturing & Automotive
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years in cloud infrastructure, 4+ years designing on AWS at enterprise scale (multi-account, multi-VPC)
  • Demonstrable ownership of an AWS multi-account landing zone, including guardrails
  • Deep understanding of AWS security: IAM policies, SCPs, KMS, VPC security
  • Experience in governing design standards and conducting architecture reviews
  • Fluency in Korean and English, both written and spoken
  • Must work onsite in Irvine, CA.

Responsibilities

  • Own landing-zone and account architecture standards such as organizational units, networking, and identity
  • Review and approve business-unit architecture changes to align with standards
  • Manage security architecture, including IAM and encryption practices
  • Drive vulnerability and compliance improvements across the cloud estate
  • Produce reference patterns and documentation for platform and operations engineers
  • Serve as a senior technical escalation point for architecture and security incidents
  • Communicate architecture and risk decisions to Korean-speaking stakeholders.

Benefits

  • Onsite work environment with team collaboration
  • Exposure to a major automotive enterprise client and advanced cloud technology
  • Opportunity to influence architectural standards across multiple cloud platforms
  • Engagement with international teams across time zones
  • Utilization of ITIL practices for structured work delivery.
Full Job Description
The role

This seat joins a dedicated 22-person team delivering a multicloud managed service - AWS, Azure and Google Cloud across roughly 155 cloud accounts - to a major automotive enterprise client and its business units. You are the architecture and security authority inside the client's Cloud Center of Excellence: you set the standard for how AWS accounts are built and secured, you review what the business units want to deploy, and you are the person who decides whether a design is safe to run.

What you will do
  • Own landing-zone and account architecture standards - account structure, organizational units, networking, identity, logging and guardrails.
  • Review business-unit architectures and change requests, and approve, reject or improve them against the standard.
  • Own security architecture: IAM and least privilege, encryption, boundary protection, secrets handling and the security baseline every account is measured against.
  • Drive vulnerability and compliance posture across the estate (Security Hub, GuardDuty, Config, Inspector) and push remediation through the operations team.
  • Produce the reference patterns and documentation that platform and operations engineers build from.
  • Act as senior technical escalation for architecture and security incidents.
  • Explain architecture and risk decisions to Korean-speaking client and HQ stakeholders, in writing and in meetings.

What we need - must have
  • 7+ years in cloud infrastructure, including 4+ years designing on AWS at enterprise scale (multi-account, multi-VPC).
  • Demonstrable ownership of an AWS multi-account landing zone - Control Tower or an equivalent custom build - including guardrails and account vending.
  • Deep AWS security: IAM policy design, SCPs, KMS, VPC security architecture, centralized logging and the AWS security services.
  • Track record of governing other teams' designs: architecture review, standards enforcement, saying no constructively.
  • Professional working fluency in Korean and English.
  • Able to work onsite in Irvine, CA.

Nice to have

AWS Solutions Architect Professional or Security Specialty • MSP or consultancy background • Automotive, manufacturing or Korean-affiliated enterprise experience • SOC 2 / ISO 27001 / NIST control mapping • Working knowledge of Azure and Google Cloud security

Working pattern - please read before applying
  • Core hours are standard US Pacific business hours, onsite in Irvine.
  • Evening and early-morning work is a regular part of this role: recurring calls with Megazone HQ and client teams in Korea (KST is 16 hours ahead of Pacific), plus planned maintenance windows outside business hours.
  • Senior escalation point for architecture and security incidents, including out of hours.

Standard terms

Onsite at the client site in Irvine, CA - this is a contractual commitment and the seat is not available remotely. Must be authorized to work in the US (sponsorship to be confirmed by Megazone US HR), able to pass client background screening, and able to work within our SOC 2 control environment. Work is delivered through a documented ITIL-style process - tickets, change control, runbooks, post-incident reviews - and most of the delivery record is written and read by the client.

Similar Jobs

More Jobs at MegazoneCloud

More Manufacturing & Automotive Jobs

Find similar AWS-02 · CCoE Cloud Architect - Architecture & Security jobs: