Senior Cloud Security Architect
Lead cloud architecture and customer-facing security engagements, from discovery and assessment through implementation and production handover. Design secure, scalable cloud environments and translate security and compliance requirements into actionable controls and delivery plans.
Responsibilities
- Design secure, scalable, resilient cloud architectures across AWS, GCP, and Azure environments.
- Set cloud architecture principles and lead technical reviews focused on security, reliability, and cost efficiency.
- Modernize legacy applications and guide adoption of microservices and distributed architectures.
- Drive infrastructure-as-code practices and optimize cloud environments for cost, performance, and scale.
- Lead customer discovery and security posture assessments across cloud and hybrid environments.
- Design target-state security architectures, remediation roadmaps, and controls aligned with regulatory and customer requirements.
- Scope security engagements and author delivery-ready statements of work, including deliverables, estimates, dependencies, and acceptance criteria.
- Architect and implement operational security capabilities, including centralized logging, SIEM integrations, detection use cases, and response automation.
- Lead implementation planning, resolve architectural issues, validate controls, and deliver documentation, runbooks, and knowledge transfer.
- Mentor security engineers and delivery teams and maintain architecture documentation and decision records.
Requirements
- At least 6 years of systems, infrastructure, or security engineering experience in R&D or delivery environments, including at least 3 years in a cloud architecture or technical leadership role.
- At least 3 years architecting and personally implementing security projects in customer-facing professional services or consulting engagements.
- Production-proven AWS expertise and hands-on GCP experience; Azure familiarity is a plus.
- Strong Terraform and infrastructure-as-code skills; experience with Docker, Kubernetes, and container hardening.
- Familiarity with microservices, REST APIs, event-driven patterns, message brokers, CI/CD, databases, caching, and cloud storage.
- Applied knowledge of ISO/IEC 27001, SOC 2, GDPR, and HIPAA, including risk assessment, control mapping, remediation, and evidence collection.
- Hands-on security engineering experience across identity and privileged access, network segmentation, encryption, secrets management, cloud and Kubernetes hardening, vulnerability management, logging, and detection.
- Ability to lead customer workshops, assess unfamiliar environments, scope and estimate work, and author implementation-ready statements of work.
- Strong communication and presentation skills in Hebrew and English.
Nice to have
- Security certifications such as CISSP, CCSP, or AWS Certified Security Specialty.
- Professional cloud architecture certifications.
- Familiarity with Azure, serverless architectures, API gateways, FinOps, and observability tools.
- Experience in high-growth B2B SaaS or global enterprise environments.