Security Architect (Cloud)
from
As a leading financial services and healthcare technology company based on revenue, SS&C is headquartered in Windsor, Connecticut, and has 27,000+ employees in 35 countries. Some 20,000 financial services and healthcare organizations, from the world's largest companies to small and mid-market firms, rely on SS&C for expertise, scale, and technology.
Job Description
Cloud Security Architect
Get To Know Us:
SS&C is leading the way. We continue to look fortoday’s and tomorrow’s brightest talent, those that embody a spirit to improve not only their lives, but those around them. From college students to seasoned and experienced professionals, we encourage you to apply. SS&C prides itself on hiring diverse, honest, dynamic individuals, who value collaboration, accountability, and innovation to name a few.
TheCloud Security Architect is a strategic change agent and cybersecurity ambassador responsible for implementing,maintaining, and enhancing security controls across multi-cloud environments (Azure and AWS). This role focuses onidentifying and assessing security threats and risks, defining secure configurations, leading security automation initiatives, and ensuring compliance with industry frameworks (ISO 27001, SOC 2, NIST CSF, CIS Controls).
The Cloud Security Architect will collaborate with DevOps, Platform Engineering, and Product teams to embed security throughout the software development lifecycle.
Why You Will Love It Here!
Flexibility: Hybrid Work Model
Your Future: Professional Development Reimbursement including access to SS&C University
Work/Life Balance: Competitive holiday scheme
Your Wellbeing: Competitive benefits designed to support the wellbeing of our staff
Diversity & Inclusion: Committed to Welcoming, Celebrating and Thriving on Diversity
Training: Hands-On, Team-Customised throughout your career
What You Will GetTo Do:
Cloud Security Operations
Design, implement, andmaintain security controls acrossAzure and AWS cloud platforms.
Conduct continuous security control testing and monitoring of cloud security events and alerts through optimization and automation.
Triage,validate, and investigate security alerts; escalate incidents following incident response procedures.
Monitor andmaintainCloud Security Posture Management (CSPM) tools andSecurity Information and Event Management (SIEM) systems.
Respond to security incidents and conduct root cause analysis with remediation recommendations.
Security Engineering & Automation
Develop and implementInfrastructure as Code (IaC) security standards using tools such asTerraform, CloudFormation, and ARM templates.
Integrate security automation intoCI/CD pipelines using tools such asGitHub Actions, Azure DevOps, Jenkins, or GitLab CI.
Build andmaintain security tooling for vulnerability scanning, secrets management, and compliance monitoring.
Create andmaintain secure design patterns, reference architectures, and security guardrails.
Implementpolicy-as-code using tools such asOpen Policy Agent (OPA), Azure Policy, or AWS Config.
Collaboration & Security Enablement
Partner withDevOps, SRE, and Engineering teams to embed security best practices.
Provide security consultation during architecture reviews and design phases.
Reduce security vulnerabilities through security awareness training and knowledge sharing.
Document security procedures, runbooks, and standards.
Mentor junior security team members and promote security culture across the organization.
Risk Management & Compliance
Assess and manage cloud security risks using industry-standard frameworks includingNIST and CIS Benchmarks.
Develop and track security risk metrics to enable data-driven decision-making.
Support compliance activities forISO 27001, SOC 2, PCI-DSS, GDPR, and other relevant standards.
Conduct security assessments of cloud architecture and configurations.
Facilitate and coordinate internal and external penetration tests and vulnerability assessments.
Dimensions of the Role
Cross-functional collaboration with Engineering, DevOps, Compliance, and Product teams.
Internal and external stakeholder management across multiple geographic regions.
Problem-solving and troubleshooting during security incidents with distributed teams.
Ability tooperate under pressure while providing clear status updates to leadership.
Capability to work independently and as part of a global virtual team.
Participation in anon-call rotation for security incident response.
What You Will Bring:
Cloud Security Expertise – AWS
Strong understanding of AWS security services includingAWS Security Hub,GuardDuty, AWS Config, CloudTrail, and EKS.
Proficiency with AWS security features includingKMS, Secrets Manager, Security Groups, NACLs, WAF, Shield, and CloudFront.
Experience with AWS identity and access management includingIAM policies, roles, SCPs, AWS SSO, and Cognito.
Knowledge of AWS infrastructure includingVPC, Transit Gateway, Direct Connect, andPrivateLink.
Familiarity with AWS PaaS security includingLambda, ECS/EKS security, API Gateway, andEventBridge.
Cloud Security Expertise – Azure
Strong understanding of Azure security services includingMicrosoft Defender for Cloud, Azure SecurityCenter, Secure Score, and Microsoft Sentinel.
Proficiency with Azure security features includingKey Vault, Network Security Groups (NSGs), Application Security Groups (ASGs), Azure Firewall, Azure DDoS Protection, Azure Front Door, and Web Application Firewall (WAF).
Experience with Azure identity and access management includingAzure AD, Conditional Access, Privileged Identity Management (PIM), and RBAC.
Knowledge of Azure infrastructure includingVirtual Networks, VPN Gateway, ExpressRoute, and Private Link/Endpoints.
Familiarity with Azure PaaS security includingApp Services, Azure Functions, Container Instances, and AKS security.
Technical Skills
Hands-on experience withInfrastructure as Code (Terraform, CloudFormation, ARM templates).
Proficiency in scripting and automation usingPython, PowerShell, Bash, or Go.
Experience withcontainer security, including Docker, Kubernetes, and container image scanning.
Knowledge ofSIEM/SOAR platforms such as Splunk, Sentinel, Datadog, and Sumo Logic.
Understanding ofDevSecOps practices and shift-left security principles.
Understanding ofArtificial Intelligence fundamentals.
Experience with vulnerability management tools such asQualys, Tenable, Rapid7, Wiz, and Prisma Cloud.
Knowledge of secrets management solutions includingHashiCorp Vault, AWS Secrets Manager, and Azure Key Vault.
Understanding ofzero-trust architecture principles.
Familiarity withAPI security, OAuth 2.0, OIDC, and SAML.
Soft Skills
Excellent written and verbal communication skills with the ability to explain complex security concepts to non-technical stakeholders.
Strong analytical and problem-solving abilities.
Collaborative mindset with experience working in agile environments.
Proactive approach toidentifying and mitigating security risks.
Qualifications & Experience
Required:
Bachelor’s degree inComputer Science, Information Security, or a related field, or equivalent experience.
3–5+ years of experience in cloud security or security engineering roles.
Demonstrable experience securingboth Azure and AWS environments.
Experience implementing security controls in production cloud environments.
Track record of security automation and tooling development.
Understanding of compliance frameworks includingISO 27001, SOC 2, NIST CSF, and CIS Controls.
Experience with incident response and forensics in cloud environments.
Preferred Certifications
One or more of the following certifications would be beneficial:
Cloud Platform: Azure Security Engineer Associate (AZ-500), AWS Certified Security – Specialty, Google Professional Cloud Security Engineer.
Security: CISSP, CCSP, CEH, GIAC (GCSA, GCED, GSEC), CompTIA Security+.
Cloud Architecture: Azure Solutions Architect Expert, AWS Solutions Architect – Professional.
DevSecOps: CertifiedDevSecOps Professional (CDP), Certified Kubernetes Security Specialist (CKS).
Additional Desirable Skills & Experience
Experience withmulti-cloud and hybrid cloud architectures.
Knowledge ofthreatmodeling and security architecture review processes.
Familiarity with theMITRE ATT&CK framework.
Experience withCloud-Native Application Protection Platforms (CNAPP).
Understanding ofsoftware supply chain security.
Contributions toopen-source security projects.
Experience withsecurity research or threat intelligence.
Knowledge of data privacy regulations includingGDPR, CCPA, and HIPAA.
We encourage applications from people of all backgrounds to enable us to bring diverse perspectives to our thinking and conversation.It's important to us that we strive to have a workforce that is diverse in the widest sense.
Thank you for your interest in SS&C! If applicable, to further explore this opportunity, please apply directly with us through our Careers page on our corporate website.
Unless explicitly requested or approached by SS&C Technologies, Inc. or any of its affiliated companies, the company will not accept unsolicited resumes from headhunters, recruitment agencies, or fee-based recruitment services.
Applications will be accepted on an ongoing basis until the position is filled.
SS&C Technologies is an Equal Employment Opportunity employer and does not discriminate against any applicant for employment or employee on the basis of race, color, religious creed, gender, age, marital status, sexual orientation, national origin, disability, veteran status or any other classification protected by applicable discrimination laws.