AWS Cloud Security Architect (Senior Specialist - Architecture)
- AWS Cloud
- AWS
- Terraform
- KMS
- CloudWatch
- DynamoDB
- EC2
- Kinesis
- SQS
- VPC
- IaC
- IAM
- NIST
Title: AWS Cloud Security Architect
Location: Remote
Cloud Security Engineer - SRC (Partner)
Description: Hands-on policy authoring and implementation resources responsible for designing and writing Service Control Policies (SCPs), Resource Control Policies (RCPs) and data perimeter policy rule sets. Work under the direction of the AWS Lead Security Consultant. Responsible for Terraform-compatible policy code delivery, testing in non-production environments, and blast radius analysis. Resources are required to cover the volume of work (47 SCPs + 11 RCPs + data perimeter) within the engagement timeline.
Activities:
·Author SCP policy rule sets for all 47 enabled AWS services, prioritized by SCI tier
·Author RCP policy rule sets for the 11 eligible services (S3, KMS, CloudWatch Logs, DynamoDB, EC2 Autoscaling, Inspector, Kinesis, SQS, CodeBuild, CodePipeline, Secrets Manager)
·Implement VPC endpoint policies and resource-based policies for critical assets (logging buckets, KMS keys)
·Deliver all policy artifacts as Terraform-compatible code for deployment via Control Tower AFT pipelines (new landing zone) and hybrid Terraform/manual deployment (legacy landing zone)
·Validate policy syntax and functionality in sandbox/non-production environments
·Conduct blast radius analysis documenting potential impact of each policy on existing workloads
·Develop phased rollout plans (Account/OU level to root) for each policy batch
·Identify and document Control Tower default SCP overlaps with custom policies
·Develop operational runbooks for ongoing policy management and exception handling
·Conduct knowledge transfer sessions with Customers Platform Engineering Team and Cloud Engineering teams
Skills Required:
·AWS Certified Security - Specialty (required)
·Hands-on experience authoring SCPs, RCPs, and data perimeter controls (VPC endpoint policies, resource-based policies)
·Strong Terraform/Infrastructure-as-Code skills, including experience with AWS Control Tower AFT
·Deep knowledge of IAM policy language, condition keys, and service-specific policy capabilities
·Experience with phased deployment of organizational policies in multi-account AWS environments
·Understanding of blast radius analysis and rollback methodologies for policy changes
·Familiarity with NIST and financial services compliance requirements
Experience working across both Control Tower and legacy (non-CT) AWS landing zones
AWS Cloud Security Architect (Senior Specialist - Architecture) · LTM