The roleThis seat joins a dedicated 22-person team delivering a multicloud managed service - AWS, Azure and Google Cloud across roughly 155 cloud accounts - to a major automotive enterprise client and its business units. You are the architecture and security authority inside the client's Cloud Center of Excellence: you set the standard for how AWS accounts are built and secured, you review what the business units want to deploy, and you are the person who decides whether a design is safe to run.
What you will do- Own landing-zone and account architecture standards - account structure, organizational units, networking, identity, logging and guardrails.
- Review business-unit architectures and change requests, and approve, reject or improve them against the standard.
- Own security architecture: IAM and least privilege, encryption, boundary protection, secrets handling and the security baseline every account is measured against.
- Drive vulnerability and compliance posture across the estate (Security Hub, GuardDuty, Config, Inspector) and push remediation through the operations team.
- Produce the reference patterns and documentation that platform and operations engineers build from.
- Act as senior technical escalation for architecture and security incidents.
- Explain architecture and risk decisions to Korean-speaking client and HQ stakeholders, in writing and in meetings.
What we need - must have- 7+ years in cloud infrastructure, including 4+ years designing on AWS at enterprise scale (multi-account, multi-VPC).
- Demonstrable ownership of an AWS multi-account landing zone - Control Tower or an equivalent custom build - including guardrails and account vending.
- Deep AWS security: IAM policy design, SCPs, KMS, VPC security architecture, centralized logging and the AWS security services.
- Track record of governing other teams' designs: architecture review, standards enforcement, saying no constructively.
- Professional working fluency in Korean and English.
- Able to work onsite in Irvine, CA.
Nice to haveAWS Solutions Architect Professional or Security Specialty • MSP or consultancy background • Automotive, manufacturing or Korean-affiliated enterprise experience • SOC 2 / ISO 27001 / NIST control mapping • Working knowledge of Azure and Google Cloud security
Working pattern - please read before applying- Core hours are standard US Pacific business hours, onsite in Irvine.
- Evening and early-morning work is a regular part of this role: recurring calls with Megazone HQ and client teams in Korea (KST is 16 hours ahead of Pacific), plus planned maintenance windows outside business hours.
- Senior escalation point for architecture and security incidents, including out of hours.
Standard termsOnsite at the client site in Irvine, CA - this is a contractual commitment and the seat is not available remotely. Must be authorized to work in the US (sponsorship to be confirmed by Megazone US HR), able to pass client background screening, and able to work within our SOC 2 control environment. Work is delivered through a documented ITIL-style process - tickets, change control, runbooks, post-incident reviews - and most of the delivery record is written and read by the client.