Job Summary
Role Summary
The Principal AWS Infrastructure & Security Architect will be responsible for designing, implementing, and governing secure, scalable, and resilient AWS cloud solutions for enterprise workloads. The role requires strong architecture ownership, hands-on cloud security expertise, automation capability, and the ability to work with cross-functional teams to support cloud migration, modernization, compliance, and operational resilience objectives.
Key Responsibilities
Key Responsibilities
Cloud Infrastructure & Architecture
• Design highly available, scalable, secure, and fault-tolerant enterprise architectures on AWS.
• Architect and implement AWS Landing Zone solutions using AWS Control Tower and AWS Organizations for multi-account governance.
• Define, maintain, and govern Infrastructure as Code templates using Terraform and AWS CloudFormation.
• Support large-scale cloud migration, application modernization, and disaster recovery strategy definition.
• Recommend and configure appropriate AWS compute, storage, database, and networking services including EC2, S3, RDS, VPC, Transit Gateway, and related services.
Cloud Security & Compliance
• Act as a cloud security SME and define security policies, standards, controls, and implementation patterns for AWS environments.
• Design secure network segmentation using AWS WAF, AWS Network Firewall, Firewall Manager, security groups, route tables, and network access controls.
• Implement identity and access management controls using AWS IAM, AWS IAM Identity Center, Active Directory integration, and least-privilege access models.
• Establish encryption controls for data at rest and in transit using AWS KMS, CloudHSM, and certificate management practices.
• Ensure alignment with regulatory and security frameworks such as ISO 27001, SOC 2, GDPR, and internal governance requirements.
• Implement and govern AWS security monitoring services including Security Hub, GuardDuty, Config, CloudTrail, and related detective controls.
• Support vulnerability management, threat modelling, risk assessments, and cloud incident response processes.
DevSecOps, Automation & Operations
• Design and embed DevSecOps controls across CI/CD pipelines, including SAST, DAST, container scanning, and IaC security validation.
• Develop automation and remediation scripts using Python, Bash, or similar scripting languages.
• Implement centralized logging, monitoring, alerting, and observability using Amazon CloudWatch, CloudTrail, OpenSearch, SIEM integrations, and related tooling.
• Drive cloud cost governance and optimization using AWS Cost Explorer, Trusted Advisor, tagging strategy, and usage analysis.
• Work with applications, infrastructure, security, compliance, and operations teams to ensure production readiness and operational stability.
Skill Requirements
Required Skills & Experience
• Strong hands-on experience in AWS architecture, cloud infrastructure design, cloud security, and enterprise-scale implementation.
• Deep understanding of the AWS Well-Architected Framework, including security, reliability, performance efficiency, operational excellence, and cost optimization pillars.
• Experience with AWS networking concepts including VPC, subnetting, DNS, VPN, Direct Connect, Transit Gateway, VPC peering, routing, and firewall integration.
• Experience with CI/CD platforms, container platforms such as Kubernetes or Amazon EKS, and serverless architecture patterns.
• Strong understanding of security controls, access governance, encryption, vulnerability management, compliance monitoring, and audit readiness.
• Ability to create architecture documentation, solution designs, operational runbooks, standards, and technical governance artefacts.
Other Requirements
Qualifications & Certifications
• Bachelor’s degree in Computer Science, Information Technology, Engineering, or a related discipline.
• AWS Certified Solutions Architect – Professional is strongly preferred.
• AWS Certified Security – Specialty is strongly preferred.
• Additional certifications in cloud security, DevSecOps, networking, or enterprise architecture will be an advantage.
Preferred Competencies
• Strong stakeholder management and communication skills with the ability to present architecture decisions to technical and management audiences.
• Ability to work in a global delivery model and collaborate with infrastructure, application, security, audit, and compliance stakeholders.
• Strong analytical and problem-solving capability with a focus on risk reduction, resilience, automation, and continuous improvement.
• Experience working in regulated environments and supporting internal and external audit requirements.
Expected Outcomes
• Secure, compliant, and well-governed AWS cloud architecture aligned with enterprise standards.
• Improved cloud resilience, availability, disaster recovery readiness, and operational stability.
• Consistent use of automation, IaC, monitoring, and DevSecOps practices across AWS workloads.
• Clear architecture documentation, standards, and governance artefacts to support delivery and operations teams.