Castillians logo
Castillians

The world's trusted engineering network

Cybersecurity Architect

Security EngineerSecurity EngineerContractRemoteSeniorTeam 51-200Since 2006H1B No SponsorCompany SiteLinkedIn

Location

Ireland

Posted

34 days ago

Salary

0

Seniority

Senior

Job Description

Cybersecurity Architect

Castillians

• Own the end-to-end security architecture for our AWS/Azure cloud environments, including networking, IAM, data encryption, and logging. • Embed security controls into CI/CD pipelines, including automated SAST/DAST scanning, software composition analysis (SCA), and container image scanning in Kubernetes. • Design and implement a Zero Trust architecture, including micro-segmentation, least-privilege access, and continuous device posture validation. • Conduct threat modeling for new product features and microservices using the STRIDE or OWASP threat modeling frameworks. • Build and maintain security-as-code using Terraform, CloudFormation, or Pulumi, ensuring all cloud resources are deployed with hardened baselines. • Select, deploy, and manage security tooling such as CSPM, CWPP, SIEM, and SOAR platforms, integrating them with existing DevOps workflows. • Lead the response to security incidents by performing forensic analysis on cloud workloads and recommending architectural fixes to prevent recurrence. • Partner with legal and compliance teams to map technical controls to requirements for SOC 2, HIPAA, PCI-DSS, and GDPR. • Design secrets management solutions using HashiCorp Vault or cloud-native key management services (KMS). • Create and maintain architecture diagrams, runbooks, and threat models for all critical systems. • Mentor software engineers on secure coding practices and conduct regular architecture review sessions. • Participate in an on-call rotation for security emergencies and critical patch deployments.

Job Requirements

  • Experience in cybersecurity roles, with at least 4 years specifically architecting security solutions in a cloud-native environment.
  • Strong programming or scripting experience in Python, Go, TypeScript, or Bash.
  • Hands-on experience with container orchestration (Kubernetes, EKS, AKS, or GKE) and service mesh technologies (Istio, Linkerd).
  • Deep expertise in at least one major cloud provider (AWS, Azure, or GCP), including native security services (Security Hub, GuardDuty, Sentinel, Policy as Code).
  • Infrastructure as Code: Terraform, CloudFormation, or ARM templates.
  • CI/CD Tools: GitHub Actions, GitLab CI, Jenkins, or ArgoCD.
  • Container Security: Docker, Kubernetes security contexts, admission controllers (OPA/Gatekeeper), and image scanning (Trivy, Clair).
  • Identity & Access: OIDC, OAuth 2.0, workload identity, and conditional access policies.
  • Monitoring & Logging: Prometheus, OpenTelemetry, ELK Stack, or Datadog.
  • Certifications (Nice to have, not required): Certified Kubernetes Security Specialist (CKS), AWS Certified Security – Specialty or Azure Security Engineer Associate, GIAC Cloud Security Essentials (GCLD), Certified DevSecOps Professional (CDP)

Benefits

  • Clear scope with no ambiguity over deliverables
  • Opportunity for repeat engagements based on performance

Related Categories

Related Job Pages

More Security Engineer Jobs

Sunshine Enterprise USA logo

Network Security Engineer

Sunshine Enterprise USA

Our commitment to creating American jobs

ContractRemoteTeam 51-200Since 2001H1B No Sponsor

• Analyze and document current and future business processes and workflows • Facilitate meetings with business and technical teams to gather requirements • Prepare BRDs, functional documents, use cases, and user stories • Identify system integration points and document data flows between applications • Support PMO activities including task tracking, documentation, and coordination • Collaborate with stakeholders to ensure clear understanding of project goals • Assist in User Acceptance Testing (UAT), test plans, and test cases • Identify process improvements, automation opportunities, and efficiency gaps • Maintain project documentation and ensure alignment with business needs • Support implementation and ensure solutions meet requirements

South Carolina
Full TimeRemoteTeam 51-200Since 2013H1B No Sponsor

• Operate at the intersection of Foresite’s cybersecurity expertise and Google’s security technology. • Partner closely with Google Cloud field sellers, Google Security specialists, and Foresite’s solution architects and delivery teams to identify opportunities, shape solutions, and close business. • Measured on new logo acquisition, annual recurring revenue (ARR), and the expansion of existing customer relationships. • Execute a strategic territory plan to achieve and exceed quarterly and annual bookings quotas for Foresite’s Google Security-aligned services. • Build and maintain a qualified pipeline through direct prospecting, account-based outreach, and co-selling with Google Cloud field teams and channel partners. • Lead negotiations and drive deals to completion, ensuring accurate forecasting and disciplined use of CRM (HubSpot/Salesforce) and deal-desk processes. • Collaborate with Google Cloud account teams on joint account planning, opportunity registration, and leveraging partner funding programs (MDF, POC funding) to accelerate cycles. • Partner with Foresite solution architects and Google specialists to design compelling, outcome-focused proposals and Statements of Work (SOWs). • Represent Foresite at industry events, Google Cloud partner forums, and customer briefings as a credible voice for our Google Security practice. • Develop deep relationships with CISOs, CIOs, and security leaders to understand their business drivers, compliance requirements, and SOC maturity. • Provide structured insights into Foresite’s product and marketing leadership regarding customer needs and competitive dynamics to enhance our service portfolio.

United States
Foresite Cybersecurity logo

Enterprise Account Executive, Cloud Security

Foresite Cybersecurity

Transform security from a barrier to a Catalyst

Full TimeRemoteTeam 51-200Since 2013H1B No Sponsor

• Operate at the intersection of Foresite’s cybersecurity expertise and Google’s security technology. • Partner closely with Google Cloud field sellers and Google Security specialists to identify opportunities, shape solutions, and close business. • Execute a strategic territory plan to achieve and exceed quarterly and annual bookings quotas. • Build and maintain a qualified pipeline through direct prospecting and co-selling with Google Cloud field teams. • Lead negotiations and drive deals to completion, ensuring accurate forecasting and CRM processes. • Collaborate with Google Cloud account teams on joint account planning and leverage partner funding programs. • Develop deep relationships with CISOs, CIOs, and security leaders to understand their business drivers and compliance requirements. • Provide structured insights into Foresite’s product and marketing leadership regarding customer needs.

District Of Columbia + 1 moreAll locations: District Of Columbia | Washington
Cisco logo

Senior Linux Security Engineer

Cisco

We securely connect everything to make anything possible.

Full TimeRemoteTeam 10,001+Since 1984H1B Sponsor

• Develop and maintain Tetragon runtime security policies to ensure customers have good visibility of suspicious activity on their infrastructure and are protected against the latest emerging threats • Help design frameworks and architectures that allow customers to easily consume policies and understand their overall security posture • Monitor vulnerability disclosures (CVEs) and the latest threat intelligence to develop Tetragon runtime security policies • Work with software engineers at Isovalent and Cisco to improve and enhance the capabilities of Tetragon security policies • Interact with solution architects and customers as necessary to support and deploy Tetragon security policies in production • Publish content and give talks based on your work

Switzerland