Talent.com
Cloud Security Architect
Cloud Security ArchitectRecutify Inc. • Markham, Ontario, Canada
Cloud Security Architect

Cloud Security Architect

Recutify Inc. • Markham, Ontario, Canada
30+ days ago
Job type
  • Full-time
Job description

Position : Cloud Security Architect

Location : MarkhamON

Position : Full time / Subcon

Mode : Hybrid (Mandatorily need to visit office 3 days a week)

Need 10 Years Profile only.

Job Details :

Top Capability skills required

1. AWS architect

2. AWS security SME

3. IT security background

Senior AWS Cloud Security Architect

The Senior AWS Cloud Security Architect is responsible for designing implementing and governing secure compliant and resilient AWS environments across multi-account cloud infrastructures.

You will lead the architecture and automation of identity data protection threat detection and network segmentation controls across the AWS ecosystem.

Key Responsibilities :

  • Design and implement secure landing zones using AWS Control Tower AWS Organizations and Service Control Policies (SCPs).
  • Define multi-account security guardrails for shared services workloads and sandbox environments.
  • Create reference architectures covering security zones network segmentation and cross-account communication (PrivateLink AWS WAN).
  • Lead threat modelling and risk assessments for new workloads and services (Lambda ECS EC2 S3 RDS DynamoDB etc.).
  • Develop security-by-design templates integrated into Infrastructure as Code (IaC) pipelines.
  • Partner with compliance teams to maintain continuous alignment with CIS Benchmarks and organizational risk frameworks.
  • Implement federated access and single sign-on with AWS IAM Identity Center (AWS SSO) Okta and Azure AD.
  • Manage cross-account roles STS trust policies and temporary credentials for developers and third parties.
  • Automate secret and credential rotation with AWS Secrets Manager and AWS Systems Manager Parameter Store.
  • Enforce encryption at rest using AWS KMS CloudHSM and envelope encryption patterns.
  • Ensure encryption in transit (TLS 1.2 / 1.3) across internal and public endpoints.
  • Manage key rotation cross-region replication and HSM-based root of trust.
  • Implement S3 Object Lock Macie for data discovery and classification and Access Points for fine-grained data access.
  • Implement PrivateLink AWS WAN and Route 53 Resolver endpoints for service-to-service isolation.
  • Configure Web Application Firewall (WAF) and AWS Shield Advanced for DDoS mitigation.
  • Enforce egress control through Cloud NAT AWS Gateway Load Balancer (GWLB) or custom proxies.
  • Deploy and integrate AWS Security Hub GuardDuty Macie and Inspector for proactive threat detection.
  • Configure Amazon Detective for forensic investigation and anomaly correlation.
  • Integrate findings into SIEM / SOAR platforms such as FortiSOAR or Azure Sentinel.
  • Automate response playbooks with AWS Step Functions Lambda and SNS alerts.
  • Implement AWS Config rules and Conformance Packs to enforce compliance (e.g. CIS AWS Foundations Benchmark).
  • Use AWS Artifact for vendor assurance and control documentation.
  • Manage compliance dashboards via Security Hub Trusted Advisor and Control Tower drift detection.

Core AWS Security & Supporting Services

Identity & Access Management : IAM IAM Identity Center (SSO) AWS Organizations Access Analyzer Cognito Resource Access Manager (RAM) Directory Service.

Encryption & Key Management : KMS CloudHSM Secrets Manager SSM Parameter Store Certificate Manager (ACM) Private CA.

Network & Perimeter Security : Network Firewall WAF Shield (Standard & Advanced) PrivateLink AWS WAN Route 53 Resolver Network LoadBalancer Application LoadBalancer.

Threat Detection & Monitoring : GuardDuty Detective Security Hub Inspector Macie CloudTrail Config CloudWatch CloudWatch Logs CloudWatch Metrics.

Compliance & Governance : Audit Manager Artifact Control Tower Trusted Advisor Config Conformance Packs Service Catalog Organizations SCPs.

Data Protection : S3 Object Lock Macie Lake Formation DLP integrations S3 Access Points.

Vulnerability & Posture Management : Inspector (EC2 ECR Lambda) Trusted Advisor Config Security Hub.

Application & Container Security : ECR image scanning ECS task IAM roles Lambda least privilege Secrets Manager API Gateway authorization.

Incident Response & Automation : Step Functions Lambda Systems Manager Automation SNS CloudWatch Alarms EventBridge Rules.

Required Skills and Experience

  • 8 years in cybersecurity with 4 years in AWS cloud security architecture.
  • Deep understanding of AWS Well-Architected Framework (Security Pillar).
  • Preferred Certifications

  • AWS Certified Security Specialty
  • AWS Certified Solutions Architect Professional
  • CISSP / CISM / CCSP / GCSA / GIAC Cloud Security Automation
  • Key Skills

    APIs,Pegasystems,Spring,SOAP,.NET,Hybris,Solution Architecture,Service-Oriented Architecture,Adobe Experience Manager,J2EE,Java,Oracle

    Employment Type : Full Time

    Experience : years

    Vacancy : 1

    Create a job alert for this search

    Architect Cloud • Markham, Ontario, Canada

    Similar jobs
    Senior Cloud Security Architect

    Senior Cloud Security Architect

    Scotiabank • Toronto C6A, ON, Canada
    Full-time
    A leading bank in the Americas is seeking a Principal Cloud Security Engineer in Toronto.The role involves leading the design and development of cloud security patterns and ensuring alignment with ...Show more
    Last updated: 30+ days ago • Promoted
    Lead DevOps Architect : Cloud, Security & Automation

    Lead DevOps Architect : Cloud, Security & Automation

    Sim • Toronto C6A, ON, Canada
    Full-time
    A leading FinTech firm in Toronto is looking for a Principal DevOps Engineer to design, implement, and oversee cloud infrastructure and delivery pipelines. This position requires strong experience i...Show more
    Last updated: 24 days ago • Promoted
    Lead InfoSec Engineer : Cloud & App Security Lead (Hybrid)

    Lead InfoSec Engineer : Cloud & App Security Lead (Hybrid)

    Nasdaq, Inc. • Toronto C6A, ON, Canada
    Remote
    Full-time
    A leading financial technology company in Canada is seeking a Lead Information Security Engineer to design and implement security solutions. This role requires over 10 years of experience in informa...Show more
    Last updated: 30+ days ago • Promoted
    Principal Cloud Security Architect

    Principal Cloud Security Architect

    Labelbox • Toronto C6A, ON, Canada
    Remote
    Full-time
    The Principal Cloud Security Architect evaluates cloud architectures, identity models, permissions, and security controls across large-scale environments. This role focuses on identifying architectu...Show more
    Last updated: 13 days ago • Promoted
    Senior Consultant, Cloud, Security & Infrastructure

    Senior Consultant, Cloud, Security & Infrastructure

    MNP • Toronto C6A, ON, Canada
    Full-time
    Senior Consultant, Cloud, Security & Infrastructure.Join to apply for the Senior Consultant, Cloud, Security & Infrastructure role at MNP. What do you think of when you hear the name MNP? We are mor...Show more
    Last updated: 22 days ago • Promoted
    Cloud Architect

    Cloud Architect

    freelance.ca • Toronto, Canada
    Full-time
    Job Title : Azure Cloud Architect Location : Toronto (Remote)Contract : 12+ MonthsClient : TCS / Banking SectorExp Level – 12-14 yearsEssential skills : -. API development experience)- SQL- API - Azure se...Show more
    Last updated: 5 days ago • Promoted
    AI & Cloud Security Architect Lead

    AI & Cloud Security Architect Lead

    Société Financière Manuvie • Toronto, Canada
    Full-time
    A leading financial services firm in Toronto is seeking a Lead Security Architect to design and implement robust security strategies. You will shape the global security posture, ensuring alignment w...Show more
    Last updated: 30+ days ago • Promoted
    Senior Solution Architect — Enterprise Cloud & Security

    Senior Solution Architect — Enterprise Cloud & Security

    Manulife Financial • Toronto
    Full-time
    A leading financial service provider in Toronto is seeking a Solution Architect with over 7 years of experience.This role involves collaborating with IT professionals to implement cross-platform so...Show more
    Last updated: 16 days ago • Promoted
    Senior DevOps Architect — Cloud, CI / CD & Security

    Senior DevOps Architect — Cloud, CI / CD & Security

    SimCorp • Toronto C6A, ON, Canada
    Remote
    Full-time
    A leading FinTech company in Toronto is seeking a Principal DevOps Engineer to design and oversee scalable cloud infrastructure and secure delivery pipelines. You will collaborate with cross-functio...Show more
    Last updated: 26 days ago • Promoted
    AWS Cloud Solution Architect

    AWS Cloud Solution Architect

    Tata Consultancy Services • Toronto C6A, ON, Canada
    Full-time
    Tata Consultancy Services (TCS) is an equal opportunity employer, and embraces diversity in race, nationality, ethnicity, gender, age, physical ability, neurodiversity, and sexual orientation, to c...Show more
    Last updated: 4 days ago • Promoted
    Azure Cloud Engineer – Landing Zones & Security Lead

    Azure Cloud Engineer – Landing Zones & Security Lead

    TTEC Digital • Toronto
    Full-time
    A leading cloud consulting company in Ontario is seeking a Senior Cloud Engineer specializing in Microsoft Azure.This critical role involves designing and hardening cloud solutions, automating infr...Show more
    Last updated: 5 days ago • Promoted
    Cloud Security Architect

    Cloud Security Architect

    Sopra Steria • Toronto, ON, Canada
    Full-time
    Sopra Steria is a European leader in consulting, digital services, and software development, supporting its clients in their digital transformation through innovative and collaborative solutions.Wi...Show more
    Last updated: 30+ days ago • Promoted
    Senior Azure Cloud Architect (MSP)

    Senior Azure Cloud Architect (MSP)

    Venture Computers of Canada Inc. • Markham, ON, Canada
    Full-time
    We are seeking a Senior Azure Architect to join our Toronto-based Managed Service Provider team.In this role, you will lead the design, implementation, and management of Azure cloud environments fo...Show more
    Last updated: 13 days ago • Promoted
    Solution Architect- Cloud and Security

    Solution Architect- Cloud and Security

    Delpath • Toronto, Canada
    Full-time
    Location : Hybrid - Toronto and Scarborough (3–4 days onsite).Contract Duration : 6 months with high possibility of extension & conversion to FTE Hiring Manager : Information Security Senior Manager R...Show more
    Last updated: 30+ days ago • Promoted
    Cloud Solutions Architect - Orchestrator Infrastructure

    Cloud Solutions Architect - Orchestrator Infrastructure

    Hire DigITalent • Toronto, ON, Canada
    Full-time
    Hybrid – 2-3 days per week in the Toronto office.Only candidates whose experience closely matches the requirements will be contacted. Based in Toronto and embedded in Canada's thriving AI ...Show more
    Last updated: 30+ days ago • Promoted
    Senior Solutions Architect : Cloud, Security & Data Strategy

    Senior Solutions Architect : Cloud, Security & Data Strategy

    Manulife • Toronto C6A, ON, Canada
    Remote
    Full-time
    A leading financial services provider is seeking a Senior Solution Architect in Toronto, Ontario.In this role, you will partner with IT professionals to craft solutions, take ownership of technical...Show more
    Last updated: 15 days ago • Promoted
    Senior Security Consultant (Cloud Penetration Testing - AWS)

    Senior Security Consultant (Cloud Penetration Testing - AWS)

    NetSPI Inc. • Toronto C6A, ON, Canada
    Remote
    Full-time
    Senior Security Consultant (Cloud Penetration Testing - AWS).NetSPI® pioneered Penetration Testing as a Service (PTaaS) and leads the industry in modern pentesting. Combining world-class security pr...Show more
    Last updated: 10 days ago • Promoted
    Hybrid Splunk Security Architect - Cloud SIEM Lead

    Hybrid Splunk Security Architect - Cloud SIEM Lead

    Foilcon • Toronto
    Full-time
    Foilcon is seeking a Technology Architect specializing in Splunk Security to join their team.This hybrid contract role involves developing and managing technical architectural solutions for Splunk ...Show more
    Last updated: 16 days ago • Promoted