Role description
Title: Lead AWS Cloud Security Architect
Location: Location: Albany, New York (Hybrid)
Multi account AWS architecture design AWS Organizations and landing zone governance Security Lab foundation and account vending design Isolated Recovery Environment IRE architecture including WORM vault cross account backup recovery orchestration and Clean Room forensic environment Establish Amazon EKS baseline and lab environment for testing security capabilities
Key Responsibilities
• WS1 AWS Security Agent cloud infrastructure design implementation support
• WS2 Security Lab design multi account lab foundation centralized logging CloudTrail VPC Flow Logs Config OU structure SCPs and automated account vending
• WS3 IRE Clean Room design IRE account with WORM vault locking cross account, cross region backup 321 CMKs CyberArk break glass Macie integration Network Firewall Transit Gateway route isolation and recovery orchestration
• Design Backup Audit Manager compliance framework
• Design Route 53 DNS isolation hardened compute baselines
• Author IRE Clean Room Architecture Design Document and Security Lab Architecture Document
• Implement hardened compute baselines and secrets management
• Contribute to lab operations guide and account vending admin procedures
• WS5 Design implementation of Amazon EKS infrastructure configuration and security lab environment