About this Role
Quanta Services is seeking an IT Security Architect to join our IT Security team, reporting to the Director, IT Security. This is a senior, hands-on architecture role focused on securing the organization's multi-cloud footprint as Quanta executes a cloud-first transformation across 100+ operating companies. The role blends security architecture with forward-deployed engineering: the Architect both designs secure cloud architectures and embeds directly with cloud, data, and application teams to build and harden secure solutions — including agentic and AI-driven workloads on AWS and Microsoft Azure.
The Architect brings deep, current cloud security engineering expertise and is expected to produce both secure-by-design guidance and working reference implementations. This role complements the broader security architecture function: partnering with the enterprise security architecture team on threat-modeling methodology, framework governance, and cross-OpCo review standards, while providing the deep cloud-platform and data-platform engineering capability to turn those standards into deployed, defensible architectures.
What You'll Do
- Combine security architecture with forward-deployed engineering: design secure cloud architectures and embed with cloud, data, and application teams to build and harden secure solutions on AWS and Azure;
- Design and implement secure reference architectures and secure-by-design patterns for cloud workloads, including landing zones, network segmentation, identity, secrets management, and egress control;
- Architect and secure agentic and AI/LLM-driven workloads, including secure integration patterns, API and tool/MCP security, data protection, and guardrails for AI services on AWS and Azure;
- Provide security architecture and hands-on engineering for data-platform workloads, with particular focus on Databricks (Unity Catalog, workspace/network isolation, access governance, and secure app/endpoint exposure);
- Build working reference implementations, automation, and infrastructure-as-code that engineering teams can adopt directly, rather than design documents alone;
- Architect secure patterns for internet-exposed cloud workloads, including WAF, application gateway, private connectivity, and egress controls;
- Partner with the enterprise security architecture function to apply threat models, control baselines, and review standards to cloud and data-platform designs;
- Provide technical guidance and mentorship to cloud and engineering teams, and communicate cloud security risk and posture to senior leadership; and
- Adhere to internal standards, policies, and procedures, and perform other duties as assigned.
What You'll Bring
Required Education and Experience
- Bachelor's degree in Computer Science, Cyber Security, or a related field, or commensurate experience in cloud security architecture and engineering;
- 7 or more years of relevant IT experience in cloud and application development;
- 5 or more years devoted specifically to security, with deep, hands-on AWS security and Azure cloud security engineering experience;
- Demonstrated experience building and securing solutions on both AWS and Azure (not single-cloud); and
- Hands-on experience building applications or automation, including the ability to develop agentic and AI-driven solutions on AWS and/or Azure.
Preferred Education and Experience
- Master's degree in Computer Science, Cyber Security, or a related field preferred;
- Hands-on Databricks security experience (Unity Catalog, network isolation, access governance, Databricks Apps exposure) preferred;
- Forward-deployed and embedded engineering experience working directly inside delivery teams preferred;
- Experience with CNAPP/CSPM tooling (e.g., Wiz or Cortex Cloud), EDR/XDR (e.g., CrowdStrike), and modern SIEM preferred; and
- Experience in a large, federated, or multi-business-unit enterprise a plus.
Licenses / Certifications
Required: N/A
Preferred: Microsoft Azure Security Engineer Associate (AZ-500) — strongly preferred; AWS Certified Security – Specialty — strongly preferred (or required within an agreed timeframe of hire); CISSP or CCSP — preferred; Databricks or data-platform certification — a plus
Supervisory Responsibilities
N/A
Travel Requirements
Travels: No
Percent of time: N/A
Overnight required: No
Physical Demands
Stationary Position: Frequently
Pushing/Pulling/Reaching: Seldom
Climb: N/A
Kneel: N/A
Grab: N/A
Bend: N/A
Lift/carry over: Less than 10 LBS
Vision: Constantly
Hearing: Frequently
Working Conditions
Wet or Humid: N/A
Working near or on moving mechanical parts: N/A
Working near or on heavy machinery: N/A
Working in high places: N/A
Exposed to fumes or airborne particles: N/A
Exposed to toxic or caustic chemicals: N/A
Frequency of working in outdoor weather conditions: N/A
Work with Electricity: N/A
Work with explosives: N/A
Work on or near a source of radiation: N/A
Loud noise conditions (above 87dB): N/A
Other Environmental Factors including weather conditions: N/A