For over the decade OTAKOYI designs and builds software products for Startups, Scaleups, and Industry Giants worldwide. Our main goal is to help businesses succeed by delivering digital products of world-class standard, made up by the best engineering teams from Eastern Europe.
28 липня 2026

Cloud Architect — Security & Guardrails (AWS/Azure) (вакансія неактивна)

віддалено

We are seeking a Cloud Architect with a deep specialization in Multi-Cloud Security Operations and Governance to secure our enterprise AWS and Azure footprints. This role focuses on moving beyond basic infrastructure design to build a resilient defense-in-depth architecture. You will be responsible for implementing automated compliance guardrails, integrating advanced security products (SIEM, EDR), and managing cloud-native vulnerability lifecycles. You will bridge the gap between cloud engineering and the Security Operations Center (SOC) to ensure our platforms are continuously monitored, defended, and compliant.

Requirements:

  • Multi-Cloud Architecture: Deep architectural knowledge of security services and infrastructure configurations within both AWS and Azure.
  • SecOps Toolkit Expertise: Direct experience engineering and tuning enterprise SIEM solutions, deploying EDR/XDR agents at scale, and managing enterprise vulnerability scanning suites.
  • Automated Policy-as-Code: Strong proficiency in implementing cloud governance tools (Azure Policy, AWS Control Tower) and secure Infrastructure as Code (Terraform) utilizing static security analysis.
  • Threat & Incident Context: Solid understanding of modern attack vectors, the MITRE ATT&CK framework, and how cloud misconfigurations translate into operational security risks.
  • Collaboration: Ability to serve as the core technical liaison between Cloud Infrastructure teams, Compliance/Audit units, and the SOC.

Preferred Certifications:

  • AWS Certified Security — Specialty / Certified Solutions Architect — Professional
  • Microsoft Certified: Azure Security Engineer Associate / Cybersecurity Architect Expert
  • CISSP (Certified Information Systems Security Professional) or CCSP (Certified Cloud Security Professional)

Responsibilities:

  • Cloud Security Guardrails & Governance: Design and enforce automated security baselines and preventative guardrails across AWS and Azure using tools like AWS Organizations, Service Control Policies (SCPs), Azure Policy, and landing zones.
  • SIEM & Logging Engineering: Architect and optimize multi-cloud log aggregation strategies. Engineer seamless telemetry pipelines from AWS (CloudTrail, GuardDuty) and Azure (Activity Logs, Defender) into centralized SIEM platforms (e.g., Microsoft Sentinel, Splunk) for real-time correlation and alerting.
  • EDR & Workload Protection: Strategy and deployment oversight for Endpoint Detection and Response (EDR) and Cloud Workload Protection Platforms (CWPP) across multi-cloud virtual machines, containers, and serverless environments.
  • Vulnerability & Posture Management: Implement and manage Cloud Security Posture Management (CSPM) and Vulnerability Management workflows. Operationalize continuous scanning for misconfigurations, OS-level vulnerabilities, and container images, establishing automated remediation playbooks.
  • Identity & Access Security: Architect strict Zero-Trust frameworks, implementing robust Identity and Access Management (IAM) governance, Just-In-Time (JIT) access, and Privileged Access Management (PAM) integrations.
  • Security Product Integration: Evaluate, deploy, and manage specialized third-party cloud security products (e.g., CyberArk, Wiz, Palo Alto Prisma, CrowdStrike) to augment native cloud security controls.