Talent.com
Cloud Security Architect
Cloud Security ArchitectRecutify Inc. • Markham, Ontario, Canada
Cloud Security Architect

Cloud Security Architect

Recutify Inc. • Markham, Ontario, Canada
30+ days ago
Job type
  • Full-time
Job description

Position : Cloud Security Architect

Location : MarkhamON

Position : Full time / Subcon

Mode : Hybrid (Mandatorily need to visit office 3 days a week)

Need 10 Years Profile only.

Job Details :

Top Capability skills required

1. AWS architect

2. AWS security SME

3. IT security background

Senior AWS Cloud Security Architect

The Senior AWS Cloud Security Architect is responsible for designing implementing and governing secure compliant and resilient AWS environments across multi-account cloud infrastructures.

You will lead the architecture and automation of identity data protection threat detection and network segmentation controls across the AWS ecosystem.

Key Responsibilities :

  • Design and implement secure landing zones using AWS Control Tower AWS Organizations and Service Control Policies (SCPs).
  • Define multi-account security guardrails for shared services workloads and sandbox environments.
  • Create reference architectures covering security zones network segmentation and cross-account communication (PrivateLink AWS WAN).
  • Lead threat modelling and risk assessments for new workloads and services (Lambda ECS EC2 S3 RDS DynamoDB etc.).
  • Develop security-by-design templates integrated into Infrastructure as Code (IaC) pipelines.
  • Partner with compliance teams to maintain continuous alignment with CIS Benchmarks and organizational risk frameworks.
  • Implement federated access and single sign-on with AWS IAM Identity Center (AWS SSO) Okta and Azure AD.
  • Manage cross-account roles STS trust policies and temporary credentials for developers and third parties.
  • Automate secret and credential rotation with AWS Secrets Manager and AWS Systems Manager Parameter Store.
  • Enforce encryption at rest using AWS KMS CloudHSM and envelope encryption patterns.
  • Ensure encryption in transit (TLS 1.2 / 1.3) across internal and public endpoints.
  • Manage key rotation cross-region replication and HSM-based root of trust.
  • Implement S3 Object Lock Macie for data discovery and classification and Access Points for fine-grained data access.
  • Implement PrivateLink AWS WAN and Route 53 Resolver endpoints for service-to-service isolation.
  • Configure Web Application Firewall (WAF) and AWS Shield Advanced for DDoS mitigation.
  • Enforce egress control through Cloud NAT AWS Gateway Load Balancer (GWLB) or custom proxies.
  • Deploy and integrate AWS Security Hub GuardDuty Macie and Inspector for proactive threat detection.
  • Configure Amazon Detective for forensic investigation and anomaly correlation.
  • Integrate findings into SIEM / SOAR platforms such as FortiSOAR or Azure Sentinel.
  • Automate response playbooks with AWS Step Functions Lambda and SNS alerts.
  • Implement AWS Config rules and Conformance Packs to enforce compliance (e.g. CIS AWS Foundations Benchmark).
  • Use AWS Artifact for vendor assurance and control documentation.
  • Manage compliance dashboards via Security Hub Trusted Advisor and Control Tower drift detection.

Core AWS Security & Supporting Services

Identity & Access Management : IAM IAM Identity Center (SSO) AWS Organizations Access Analyzer Cognito Resource Access Manager (RAM) Directory Service.

Encryption & Key Management : KMS CloudHSM Secrets Manager SSM Parameter Store Certificate Manager (ACM) Private CA.

Network & Perimeter Security : Network Firewall WAF Shield (Standard & Advanced) PrivateLink AWS WAN Route 53 Resolver Network LoadBalancer Application LoadBalancer.

Threat Detection & Monitoring : GuardDuty Detective Security Hub Inspector Macie CloudTrail Config CloudWatch CloudWatch Logs CloudWatch Metrics.

Compliance & Governance : Audit Manager Artifact Control Tower Trusted Advisor Config Conformance Packs Service Catalog Organizations SCPs.

Data Protection : S3 Object Lock Macie Lake Formation DLP integrations S3 Access Points.

Vulnerability & Posture Management : Inspector (EC2 ECR Lambda) Trusted Advisor Config Security Hub.

Application & Container Security : ECR image scanning ECS task IAM roles Lambda least privilege Secrets Manager API Gateway authorization.

Incident Response & Automation : Step Functions Lambda Systems Manager Automation SNS CloudWatch Alarms EventBridge Rules.

Required Skills and Experience

  • 8 years in cybersecurity with 4 years in AWS cloud security architecture.
  • Deep understanding of AWS Well-Architected Framework (Security Pillar).
  • Preferred Certifications

  • AWS Certified Security Specialty
  • AWS Certified Solutions Architect Professional
  • CISSP / CISM / CCSP / GCSA / GIAC Cloud Security Automation
  • Key Skills

    APIs,Pegasystems,Spring,SOAP,.NET,Hybris,Solution Architecture,Service-Oriented Architecture,Adobe Experience Manager,J2EE,Java,Oracle

    Employment Type : Full Time

    Experience : years

    Vacancy : 1

    Create a job alert for this search

    Architect Cloud • Markham, Ontario, Canada

    Similar jobs
    Principal Cloud Security Engineer

    Principal Cloud Security Engineer

    Scotiabank • Toronto C6A, ON, Canada
    Full-time
    Principal, Cloud Security Engineer.Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture. Lead the design, development, and formalization of cloud sec...Show more
    Last updated: 30+ days ago • Promoted
    Senior Cloud Architect - Multi-Cloud & Security

    Senior Cloud Architect - Multi-Cloud & Security

    LanceSoft Inc • Toronto
    Full-time
    A leading technology services firm in Toronto seeks a Senior Technology Architect who will serve as an expert in cloud services for government initiatives. The role includes designing advanced cloud...Show more
    Last updated: 6 days ago • Promoted
    Senior Solution Architect : Cloud, Microservices & Security

    Senior Solution Architect : Cloud, Microservices & Security

    Mphasis • Toronto
    Full-time
    A leading global technology firm in Toronto is seeking a skilled Architect to design and implement enterprise solutions.The role demands expertise in Infrastructure and Security Architecture, along...Show more
    Last updated: 26 days ago • Promoted
    Cloud Security, Compliance & Governance Lead

    Cloud Security, Compliance & Governance Lead

    Metergy Solutions • Toronto, Canada, CA
    Full-time
    Seeking a Cloud Security Manager to lead security and compliance, ensuring regulatory adherence within a dynamic environment.Show more
    Last updated: 27 days ago • Promoted
    Senior Cloud Security & Infra Consultant

    Senior Cloud Security & Infra Consultant

    Amazon • Toronto, Canada, CA
    Full-time
    Senior Consultant, Cloud, Security & Infrastructure Join to apply for the Senior Consultant, Cloud, Security & Infrastructure role at MNP. MNP redefines how organizations succeed in the dig...Show more
    Last updated: 5 days ago • Promoted
    Cloud Solution Architect - Infrastructure

    Cloud Solution Architect - Infrastructure

    Forhyre • Toronto, ON, Canada
    Full-time
    We are looking for a Cloud Solution Architect - Infrastructure to design the structure of our clients IT systems and oversee programs to ensure the proper architecture is implemented.In this role, ...Show more
    Last updated: 30+ days ago • Promoted
    Solution Architect- Cloud and Security

    Solution Architect- Cloud and Security

    Delpath • Toronto
    Full-time
    Location : Hybrid - Toronto and Scarborough (3–4 days onsite).Contract Duration : 6 months with high possibility of extension & conversion to FTE. Hiring Manager : Information Security Senior Manager.B...Show more
    Last updated: 26 days ago • Promoted
    Senior DevOps Architect — Cloud, CI / CD & Security

    Senior DevOps Architect — Cloud, CI / CD & Security

    SimCorp • Toronto
    Full-time
    A leading FinTech company in Toronto is seeking a Principal DevOps Engineer to design and oversee scalable cloud infrastructure and secure delivery pipelines. You will collaborate with cross-functio...Show more
    Last updated: 26 days ago • Promoted
    Cloud Security Advisor — Zero Trust & Iam Expert

    Cloud Security Advisor — Zero Trust & Iam Expert

    Intact • Toronto, Canada, CA
    Full-time
    Acts as the main point of contact for customer security and compliance inquiries, requiring IT audit experience and strong communication skills.Show more
    Last updated: 23 days ago • Promoted
    Strategic Security Architect — AI, Cloud & Enterprise

    Strategic Security Architect — AI, Cloud & Enterprise

    Manulife Financial • Toronto C6A, ON, Canada
    Remote
    Full-time
    A leading financial services provider in Toronto is seeking a Lead Security Architect to develop security strategies and frameworks supporting business operations. This role involves collaborating w...Show more
    Last updated: 2 days ago • Promoted
    Senior Azure Cloud Architect (MSP)

    Senior Azure Cloud Architect (MSP)

    Venture Computers of Canada Inc. • Markham, ON, Canada
    Full-time
    We are seeking a Senior Azure Architect to join our Toronto-based Managed Service Provider team.In this role, you will lead the design, implementation, and management of Azure cloud environments fo...Show more
    Last updated: 24 days ago • Promoted
    Enterprise Solutions Architect – Cloud, Networking & Security

    Enterprise Solutions Architect – Cloud, Networking & Security

    Rogers Communications • Toronto
    Full-time
    A telecommunications provider in Canada is looking for a Solution Architect to design and create customized technology solutions. This full-time role involves collaborating with clients, understandi...Show more
    Last updated: 6 days ago • Promoted
    Azure Cloud Engineer – Landing Zones & Security Lead

    Azure Cloud Engineer – Landing Zones & Security Lead

    TTEC Digital • Toronto, ON, Canada
    Full-time
    A leading cloud consulting company in Ontario is seeking a Senior Cloud Engineer specializing in Microsoft Azure.This critical role involves designing and hardening cloud solutions, automating infr...Show more
    Last updated: 4 days ago • Promoted
    Senior Network Architect - Cloud Edge & Security

    Senior Network Architect - Cloud Edge & Security

    Dayforce US, Inc. • Toronto
    Full-time
    A global HCM company in Toronto is seeking a Senior Network Engineer to enhance their cloud network infrastructure.The role involves providing strategic leadership for network systems, troubleshoot...Show more
    Last updated: 26 days ago • Promoted
    Cloud Solutions Architect - Orchestrator Infrastructure

    Cloud Solutions Architect - Orchestrator Infrastructure

    Hire DigITalent • Toronto, ON, Canada
    Full-time
    Hybrid – 2-3 days per week in the Toronto office.Only candidates whose experience closely matches the requirements will be contacted. Based in Toronto and embedded in Canada's thriving AI ...Show more
    Last updated: 30+ days ago • Promoted
    Enterprise Architect - Cloud, Security & Strategy

    Enterprise Architect - Cloud, Security & Strategy

    KPMG Canada • Toronto, Canada
    Full-time
    A leading professional services firm in North Bay, Canada, is seeking a motivated Enterprise Architect to join its Business Enablement Services Technology team. The role requires a strong understand...Show more
    Last updated: 1 day ago • Promoted
    Cloud Security Engineer

    Cloud Security Engineer

    Aquanow • Toronto
    Full-time
    Aquanow, a leading infrastructure and liquidity provider that provides institutional and enterprise application platforms for digital assets, is looking for a Cloud Security Engineer to join our te...Show more
    Last updated: 26 days ago • Promoted
    Cloud Architect

    Cloud Architect

    Starboard Recruitment • Toronto, ON, Canada
    Full-time
    Follow Starboard Recruitment on LinkedIn for ongoing job opportunities, market updates and advice : .Starboard Recruitment, on behalf of our client, is searching for an experienced Cloud Architect.Op...Show more
    Last updated: 30+ days ago • Promoted