Principal AWS Infrastructure & Security Architect
Indexed description
Role Summary
The Principal AWS Infrastructure & Security Architect will be responsible for designing, implementing, and governing secure, scalable, and resilient AWS cloud solutions for enterprise workloads. The role requires strong architecture ownership, hands-on cloud security expertise, automation capability, and the ability to work with cross-functional teams to support cloud migration, modernization, compliance, and operational resilience objectives.
Key Responsibilities
Cloud Infrastructure & Architecture
- Design highly available, scalable, secure, and fault-tolerant enterprise architectures on AWS.
- Architect and implement AWS Landing Zone solutions using AWS Control Tower and AWS Organizations for multi-account governance.
- Define, maintain, and govern Infrastructure as Code templates using Terraform and AWS CloudFormation.
- Support large-scale cloud migration, application modernization, and disaster recovery strategy definition.
- Recommend and configure appropriate AWS compute, storage, database, and networking services including EC2, S3, RDS, VPC, Transit Gateway, and related services.
Cloud Security & Compliance
- Act as a cloud security SME and define security policies, standards, controls, and implementation patterns for AWS environments.
- Design secure network segmentation using AWS WAF, AWS Network Firewall, Firewall Manager, security groups, route tables, and network access controls.
- Implement identity and access management controls using AWS IAM, AWS IAM Identity Center, Active Directory integration, and least-privilege access models.
- Establish encryption controls for data at rest and in transit using AWS KMS, CloudHSM, and certificate management practices.
- Ensure alignment with regulatory and security frameworks such as ISO 27001, SOC 2, GDPR, and internal governance requirements.
- Implement and govern AWS security monitoring services including Security Hub, GuardDuty, Config, CloudTrail, and related detective controls.
- Support vulnerability management, threat modelling, risk assessments, and cloud incident response processes.
DevSecOps, Automation & Operations
- Design and embed DevSecOps controls across CI/CD pipelines, including SAST, DAST, container scanning, and IaC security validation.
- Develop automation and remediation scripts using Python, Bash, or similar scripting languages.
- Implement centralized logging, monitoring, alerting, and observability using Amazon CloudWatch, CloudTrail, OpenSearch, SIEM integrations, and related tooling.
- Drive cloud cost governance and optimization using AWS Cost Explorer, Trusted Advisor, tagging strategy, and usage analysis.
- Work with applications, infrastructure, security, compliance, and operations teams to ensure production readiness and operational stability.
Required Skills & Experience
- Strong hands-on experience in AWS architecture, cloud infrastructure design, cloud security, and enterprise-scale implementation.
- Deep understanding of the AWS Well-Architected Framework, including security, reliability, performance efficiency, operational excellence, and cost optimization pillars.
- Experience with AWS networking concepts including VPC, subnetting, DNS, VPN, Direct Connect, Transit Gateway, VPC peering, routing, and firewall integration.
- Experience with CI/CD platforms, container platforms such as Kubernetes or Amazon EKS, and serverless architecture patterns.
- Strong understanding of security controls, access governance, encryption, vulnerability management, compliance monitoring, and audit readiness.
- Ability to create architecture documentation, solution designs, operational runbooks, standards, and technical governance artefacts.
Qualifications & Certifications
- Bachelor’s degree in computer science, Information Technology, Engineering, or a related discipline.
- AWS Certified Solutions Architect – Professional is strongly preferred.
- AWS Certified Security – Specialty is strongly preferred.
- Additional certifications in cloud security, DevSecOps, networking, or enterprise architecture will be an advantage.
Preferred Competencies
- Strong stakeholder management and communication skills with the ability to present architecture decisions to technical and management audiences.
- Ability to work in a global delivery model and collaborate with infrastructure, application, security, audit, and compliance stakeholders.
- Strong analytical and problem-solving capability with a focus on risk reduction, resilience, automation, and continuous improvement.
- Experience working in regulated environments and supporting internal and external audit requirements.
Expected Outcomes
- Secure, compliant, and well-governed AWS cloud architecture aligned with enterprise standards.
- Improved cloud resilience, availability, disaster recovery readiness, and operational stability.
- Consistent use of automation, IaC, monitoring, and DevSecOps practices across AWS workloads.
- Clear architecture documentation, standards, and governance artefacts to support delivery and operations teams.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search