Overview In this role you lead the cloud security architecture and engineering function, guiding strategy while actively contributing technically. You'll shape a multi-cloud, hybrid security approach across AWS, Azure, SaaS, and OT environments. You work with cross-functional teams to embed security by design, drive cloud transformation, and deliver secure, scalable cloud systems. You'll influence leadership through architecture leadership and security workshops.
Compensation / Benefits- bonus program
- healthcare benefits
- life insurance
- time off benefits
- 401(k) plan
Responsibilities- Own and evolve the enterprise cloud security architecture across AWS, SaaS platforms, hybrid infrastructure, applications, networking, and operational technologies to align with business strategy and risk tolerance
- Define and implement AWS-native security architectures (identity, encryption, network segmentation, logging, detection, governance) for secure cloud adoption
- Support re-architecture and migration of Azure workloads to AWS, embedding security-by-design throughout the migration lifecycle
- Design, implement and enforce Zero Trust security models for cloud and hybrid environments
- Integrate AWS with enterprise security platforms (Zscaler, Splunk, BeyondTrust) for centralized visibility and response
- Collaborate with DevOps and cloud infrastructure teams to embed security into pipelines, using automation for vulnerability management, code scanning, configuration validation, and continuous compliance
- Support cloud identity and access management (IAM) strategies, including federation, least privilege, just-in-time access, identity governance, and Zero Trust principles; integrate with IdPs (Entra ID, SAP IAS)
- Establish governance, risk, and compliance (GRC) frameworks for cloud adoption, including policy-as-code and automated monitoring
- Develop templates, accelerators, and reusable security artifacts to accelerate delivery and ensure compliance across cloud initiatives for BBG
- Monitor emerging cloud services, regulatory changes, and threat trends to advise leadership on security posture and mitigations
- Lead and develop cloud security teams, set technical direction and delivery priorities; oversee cloud security tools, platforms, and services portfolio
- Oversee cloud incident response and forensics leveraging native cloud telemetry and SIEM integrations
- Deliver executive briefings, architecture reviews, and security workshops to influence stakeholders and drive secure cloud transformation
Key requirements- 12+ years IT Security experience, with 5+ years in AWS architecture
- AWS Solutions Architect - Associate Certification
- AWS Security Specialty
- CISSP Certification
- Deep expertise in AWS-native and third-party security tools
- Strong understanding of cloud governance, IaC, encryption, networking, and identity management
- Experience with Snowflake and S/4HANA
- Hands-on scripting and automation (Python, Terraform)
- Strong experience with Splunk
- Experience with multi-cloud environments (AWS, Azure)
- Strong writing and communication skills across technical and executive audiences
- Experience with leading and team management
- Ability to multi-task, work independently and/or within a team, meet deadlines
- Ability to work nights, weekends and holidays
- strong communication
- leadership
- cross-functional collaboration
- AWS, Azure
- Zscaler
- Splunk