Cloud Architect – Security & Guardrails (AWS/Azure)
Brak informacji o wynagrodzeniu
SeniorFull-time·B2B
#434883·Dodano dwa miesiące temu·1
Źródło: CapcoTech Stack / Keywords
AWSAzureTerraformSIEMEDRXDRCSPMIAMKubernetesMITRE ATT&CK
Firma i stanowisko
At Capco, we specialize in management consulting and technology transformation for the financial services industry, focusing on helping clients navigate complex change and build future-ready organizations.
Wymagania
- Extensive experience designing and securing enterprise-scale AWS and Azure environments.
- Deep knowledge of cloud-native security services, controls, and governance frameworks.
- Hands-on expertise with SIEM platforms, EDR/XDR technologies, vulnerability management solutions, and CSPM tools.
- Strong experience implementing Azure Policy, AWS Control Tower, Service Control Policies (SCPs), and cloud governance frameworks.
- Advanced Infrastructure as Code (IaC) skills, particularly with Terraform.
- Experience embedding security controls into CI/CD and cloud deployment pipelines.
- Strong understanding of modern cyber threats, MITRE ATT&CK framework, cloud attack vectors, security monitoring, and incident response processes.
- Proven ability to collaborate effectively with Cloud Engineering teams, Security Operations Centers (SOC), and Risk, Compliance, and Audit functions.
- Excellent stakeholder management and communication skills.
Obowiązki
Cloud Security Governance & Guardrails:
- Design, implement, and enforce security baselines and preventative guardrails across AWS and Azure environments.
- Develop governance frameworks leveraging AWS Organizations, Service Control Policies (SCPs), AWS Control Tower, Azure Policy, and Azure Landing Zones.
- Ensure alignment with internal security standards, regulatory requirements, and industry best practices.
SIEM, Monitoring & Logging Architecture:
- Design and optimize multi-cloud logging and monitoring strategies.
- Build scalable telemetry pipelines integrating AWS CloudTrail, Amazon GuardDuty, Azure Activity Logs, and Microsoft Defender for Cloud.
- Enable centralized visibility through enterprise SIEM platforms such as Microsoft Sentinel and Splunk.
- Support real-time threat detection, correlation, investigation, and alerting capabilities.
Endpoint & Workload Protection:
- Define architecture and deployment strategies for EDR/XDR solutions and Cloud Workload Protection Platforms (CWPP).
- Secure virtual machines, containers, Kubernetes environments, and serverless workloads across cloud platforms.
- Collaborate with Security Operations teams to enhance threat detection and response.
Vulnerability & Security Posture Management:
- Implement and optimize Cloud Security Posture Management (CSPM) capabilities.
- Establish enterprise vulnerability management processes across cloud assets.
- Enable continuous security scanning for cloud misconfigurations, infrastructure vulnerabilities, container images, and operating systems.
- Develop automated remediation workflows and security playbooks.
Identity & Access Security:
- Design and enforce Zero-Trust security principles.
- Strengthen Identity and Access Management (IAM) governance across cloud platforms.
- Implement Just-In-Time (JIT) access, Privileged Access Management (PAM), Role-Based Access Control (RBAC), and federated identity solutions.
- Partner with security stakeholders to reduce privileged access risks.
Security Technology Integration:
- Evaluate, deploy, and govern best-in-class cloud security technologies.
- Integrate third-party security platforms including CyberArk, Wiz, Palo Alto Prisma Cloud, CrowdStrike, and other strategic security tooling.
- Drive consistent security controls and operational excellence across the cloud ecosystem.
Benefity
- Flexible collaboration model based on a B2B contract.
- Opportunity to work on diverse projects.
Inne informacje
Candidate must be based in Poland as explicitly stated in the job offer.
Capco
51 aktywnych ofert