Senior Cloud Security Architect – Terraform

Job not on LinkedIn

🔥 7 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Dayforce

Dayforce

5001 - 10000 employees

👥 HR Tech

☁️ SaaS

🤝 B2B

💰 $1G Post-IPO Debt - Dayforce on 2024-03

HR Tech • SaaS • B2B

Dayforce is a cloud-based human capital management (HCM) platform that provides payroll, HR, workforce management, time and attendance, benefits administration, talent management, and analytics for employers. Delivered as a software-as-a-service solution and used by organizations to centralize HR and payroll processes, Dayforce targets business customers and enterprises seeking integrated workforce and payroll systems. The provided page content contained only a browser loading message and no detailed information, so established public knowledge about Dayforce was used to produce this description.

📋 Description

• Designs, implements, and continuously improves AWS security architecture. • Partners with cloud engineering, platform engineering, DevOps, Risk & Compliance, and product teams to build secure-by-default patterns, guardrails, and automation that enable delivery velocity without compromising security. • Influences cloud security strategy while providing hands-on architectural and engineering support. • Designs secure reference architectures and reusable security patterns for AWS workloads, including identity, networking, encryption, logging, monitoring, and secrets management. • Implements and operates enterprise AWS guardrails using Organizations, Control Tower, SCPs, AWS Config (managed and custom rules), Security Hub, GuardDuty, Detective, Macie, WAF/Shield, and AWS Network Firewall. • Applies least-privilege IAM using roles, permission boundaries, session policies, IAM Identity Center, SAML/OIDC federation, and ABAC/RBAC where appropriate. • Uses IAM Access Analyzer and automated validation to identify and reduce risk. • Designs secure VPC architectures, including subnet strategy, private endpoints, NAT and egress controls, Transit Gateway, Route 53, DNS Firewall, centralized ingress/egress, and service-to-service authentication. • Establishes detection-as-code and telemetry standards using CloudTrail, VPC Flow Logs, Route 53, RDS, ALB/NLB, and S3 access logs; integrates detections with SIEM/SOAR platforms. • Supports incident response through detections, playbooks, and tabletop exercises. • Embeds security into CI/CD pipelines using policy-as-code, Terraform checks, container and image scanning, SBOMs, and pre-commit hooks. • Automates remediation and drift detection using Lambda, Step Functions, and Terraform. • Maps technical controls to security frameworks including CIS AWS Foundations, NIST, ISO 27001, SOC 2, PCI DSS, and HIPAA (as applicable). • Conducts threat modeling (e.g., STRIDE) and risk assessments and drives remediation to closure. • Reviews designs, provides architectural guidance, and produces clear documentation and runbooks.

🎯 Requirements

• 7+ years of experience in cloud architecture and security, including leading cloud security programs or large-scale AWS transformations. • Hands-on expertise with AWS security services and controls, including Organizations, Control Tower, IAM/IAM Identity Center, KMS, Security Hub, GuardDuty, Detective, Macie, WAF/Shield, AWS Network Firewall, CloudTrail, Config, CloudWatch, VPC, Route 53, ECS, and Secrets Manager/Parameter Store. • Strong background in cloud identity and Zero Trust patterns, including workload identity, JIT access, break-glass design, and ABAC where appropriate. • Experience securing data at scale, including classification, DLP, tokenization, and access governance. • Deep understanding of networking and isolation patterns, including multi-region architectures, hybrid connectivity, egress controls, private endpoints, and service-to-service authentication. • Proficiency with infrastructure-as-code and automation tools (Terraform, Python/Bash, policy-as-code). • Experience with container and serverless security, including ECS hardening, image attestations, runtime controls, and least-privilege Lambda patterns. • Detection engineering experience, including logging strategies, detections-as-code, and SIEM/SOAR integration. • Familiarity with incident response and security investigations. • Strong governance, risk, and compliance knowledge with the ability to map controls to CIS, NIST, ISO, PCI, and HIPAA frameworks (as applicable). • Clear written and verbal communication skills, with the ability to produce concise design documentation and provide actionable guidance to engineering teams. • Ability to manage priorities effectively in a fast-changing environment. • Comfortable working in a remote or hybrid environment with limited in-person interaction.

🏖️ Benefits

• Full benefits starting Day 1: Medical, Dental, and Vision • 401(k) with company match • Unlimited Flex Time Off plus 10 company-paid holidays • Remote-first role with monthly communication stipend • Professional development programs, tuition assistance, and quarterly book program • Free wellness coaching and pet insurance • Home office equipment stipend • Employee resource groups and exclusive employee discounts

Apply Now

Similar Jobs

🔥 23 minutes ago

Allstate

10,000+ employees

💼 Consulting

📦 Logistics

🛡️ Insurance

Cloud Product Engineer developing and operating Allstate’s Cloud platforms. Leading engineering practices and mentoring teams while ensuring platform efficiency and operational excellence.

Azure

Cloud

Google Cloud Platform

🔥 1 hour ago

General Dynamics Information Technology

10,000+ employees

💼 Consulting

🏥 Healthcare

📦 Logistics

Lead Cloud Software Developer at GDIT managing Agile software development teams for federal projects. Responsible for cloud solutions design, architecture, and deployment while ensuring system integrity.

AWS

Cloud

JavaScript

Linux

Node.js

Python

React

🔥 2 hours ago

Koniag Government Services

1001 - 5000

🏛️ Government

🎖️ Defense

💼 Consulting

AWS FinOps Engineer at Koniag IT Solutions leveraging advanced analytics for cloud cost optimization. Collaborating on mission-critical projects while solving analytical problems.

AWS

Cloud

Tableau

Terraform

🔥 2 hours ago

Koniag Government Services

1001 - 5000

🏛️ Government

🎖️ Defense

💼 Consulting

Cloud Architect responsible for advanced AWS networking solutions for government clients. Collaborating with security teams and ensuring compliance with federal standards.

AWS

Cloud

Cyber Security

DNS

Switching

TCP/IP

Terraform

🔥 2 hours ago

Koniag Government Services

1001 - 5000

🏛️ Government

🎖️ Defense

💼 Consulting

Cloud Architect supporting scalable cloud service design for U.S. Department of Health. Collaborating with teams to develop cloud architecture and enforce standards.

AWS

Azure

Cloud

DNS

Docker

Google Cloud Platform

Kubernetes

Splunk

Terraform