Cloud Architect / Security & Guardrails (AWS & Azure)
Job description
We are DIGIPAL , a software delivery agency specialising in building high-performing product design and software development teams for clients across Europe and North America. We work with a wide range of organisations from ambitious startups to multinational corporations. We have a unique career opportunity for you to work on building exciting digital products for international clients. Yet, remaining flexible in a remote-only environment and getting a top-tier compensation package. About the Role: We are looking for a Cloud Architect – Security & Guardrails with deep expertise in AWS and Azure security architecture to help secure and govern enterprise-scale multi-cloud environments. In this role, you will design and implement security guardrails, cloud governance frameworks, and automated compliance controls while integrating enterprise security platforms across cloud infrastructure. You will work closely with Cloud Engineering, Security Operations, and Compliance teams to build resilient, secure, and compliant cloud platforms that support enterprise-scale applications. Responsibilities: Design and implement cloud security architecture across AWS and Azure. Develop and enforce automated security guardrails and governance policies. Build and optimize centralized logging and SIEM integrations. Design cloud-native monitoring and threat detection solutions. Oversee EDR, XDR, and workload protection across cloud environments. Implement Cloud Security Posture Management (CSPM) and vulnerability management processes. Architect secure IAM, Zero Trust, JIT, and Privileged Access Management solutions. Integrate third-party cloud security platforms into enterprise environments. Build secure Infrastructure as Code solutions using Terraform. Collaborate with Cloud, Security Operations, and Compliance teams to improve cloud Requirements: 7+ years of experience in Cloud Architecture, Cloud Security, or Security Engineering. Strong architectural expertise across AWS and Azure. Experience designing enterprise cloud governance and security frameworks. Hands-on experience with AWS Organizations, Service Control Policies (SCPs), Azure Policy, and Landing Zones. Strong knowledge of SIEM platforms such as Microsoft Sentinel or Splunk. Experience with EDR/XDR, CSPM, and enterprise vulnerability management. Advanced knowledge of Terraform and Infrastructure as Code. Strong understanding of IAM, Zero Trust, PAM, and cloud identity security. Experience with enterprise security platforms such as CyberArk, Wiz, Prisma Cloud, or CrowdStrike. Solid understanding of cloud threats, MITRE ATT&CK, and security best practices. Excellent communication and stakeholder management skills. Professional, proactive, and security-first mindset. security and governance. Nice to Have: Experience working in large-scale enterprise or regulated cloud environments. Knowledge of SOC 2, ISO 27001, CIS Benchmarks, or NIST frameworks. Experience supporting Security Operations Centers (SOC) and incident response. Familiarity with cloud compliance, audit, and risk management. Experience designing multi-cloud landing zones and governance frameworks. Preferred Certifications AWS Certified Security – Specialty. AWS Certified Solutions Architect – Professional. Microsoft Certified: Azure Security Engineer Associate (AZ-500). Microsoft Certified: Cybersecurity Architect Expert. CISSP (Certified Information Systems Security Professional). CCSP (Certified Cloud Security Professional). Our offer: 100% remote position. Attractive compensation package. Long-term B2B contract. Opportunities for professional growth and continuous learning. Collaboration with top engineering talent from around the globe. The chance to build world-class digital products for European and US markets.