Cloud Security Architect Lead

Job purpose

Design secure and reliable cloud solutions to protect the organization's digital assets from internal and external cyber threats. This position involves developing and implementing a comprehensive cloud security strategy, conducting thorough analyses of current infrastructure and applications, and collaborating with stakeholders to align cloud security architecture with business goals. The role also includes creating and maintaining robust cloud security architecture, performing regular security assessments, ensuring compliance with industry standards, and managing risks associated with cloud-based projects.

Key activities, responsibility & accountability

Cloud strategy and planning

  • Develop and implement the organization's cloud security strategy.
  • Conduct comprehensive analysis of current infrastructure and applications to determine optimal cloud security solutions.
  • Collaborate with stakeholders to align cloud security architecture with business goals.

Design and develop cloud security architecture

  • Create and maintain a comprehensive cloud security architecture that ensures the security of cloud-based systems.
  • Identify the specific security needs of your organization, including compliance requirements, data sensitivity, and business objectives.
  • Develop and validate security controls to protect cloud infrastructure and applications.
  • Review solution designs for cloud-based projects and ensure those align with information security and compliance requirements.
  • Provide security recommendations for new cloud projects.
  • Maintain and update the cloud security decision tool to ensure easy decision making for cloud projects.

Security assessments and compliance

  • Perform regular security assessments to ensure security of the cloud platforms.
  • Perform scheduled security assessments for cloud-based solutions.
  • Support audit teams during cloud audits.
  • Perform continuous evaluation and ensure compliance with security standards.
  • Ensure compliance with industry security standards and regulations.

Incident response

  • Work with incident response team to support investigation of cloud-related incidents.

Risk management

  • Conduct risk assessments and develop mitigation strategies.
  • Review risks raised for cloud-related projects and perform risk evaluation.
  • Update the risk tracker and maintain the same.
  • Track risks from risk tracker on a regular basis.
  • Evaluate third-party vendor security posture and ensure that their practices comply with company standards and regulatory requirements.
  • Lead efforts to manage security risks in the supply chain.

Reporting & documentation

  • Prepare detailed reports on risk assessments, security audits, and compliance activities.
  • Track and report on the departmental KPI on a periodic basis.
  • Create and maintain security baselines for cloud technologies.
  • Establish clear cloud security decision matrix that governs access control, data protection, incident response, and compliance.
  • Adopt industry standards and frameworks such as NIST, ISO/IEC 27001, and the Cloud Security Alliance (CSA) guidelines.
  • Provide training and guidance on cloud security best practices for team members.
  • Maintain up-to-date knowledge of cloud security trends, threats, and countermeasures.
  • Stay up to date on the latest security threats, tools, and trends.
  • Mentor junior resources on cloud-related projects.
  • Communicate findings and recommendations to both technical and non-technical stakeholders at various levels of the organization.

Health and safety, security, and business continuity

  • All individuals take personal responsibility for safety; follow company HSE policies, procedures and instructions; avoid complacency and continuously challenge existing conditions and activities in order to identify discrepancies that might result in error or inappropriate action; report any situation that could present a hazard; not intentionally or recklessly interfere with or misuse anything provided at the workplace in the interest of health, safety, welfare or protection or management of the environment.
  • Follow all relevant security policies, processes, procedures, and instructions to ensure security compliance in all aspects of work, by applying them on self, others, and corporate assets.
  • Follow all relevant business continuity and resilience requirements for compliance with, and adherence to, policies, procedures and instructions related to the effective planning for, and response to, incidents and/or business disruptions to continue critical business processes and activities with minimal adverse impact.

Professional certifications

CISSP, SC-100, CEH, AWS Certified, multiple Azure certifications, TOGAF/ COBIT certified

Qualifications

Bachelor’s degree in Computer Science, Information Technology, Cyber Security, or relevant field.

Experience

Bachelor’s degree with 7 years’ experience, diploma, military or police academy graduate with 10 years’ experience, or high school with 12 years’ experience.

Back to blog

Other Jobs To Apply

No other job posts for this day.

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...