View all jobs
Multi-Cloud Security Architect
Position: Multi-Cloud Security Architect
Industry: Transportation
Location: Dallas, TX or San Antonio, TX — Onsite / Co-Located
Employment Type: Contract-to-Hire
Work Authorization: Must be a U.S. Citizen or U.S. Permanent Resident. No current or future sponsorship available.
Overview
The Multi-Cloud Security Architect will provide security architecture leadership across cloud environments spanning Google Cloud Platform (GCP), Amazon Web Services (AWS), and Microsoft Azure. The role will focus on developing secure architectural approaches for cloud services, identity and access management (IAM), APIs, authentication and authorization, and network connectivity across a multi-cloud technology environment.
This is an architecture role requiring the ability to translate security principles into practical technical designs. The architect will evaluate how applications, services, identities, APIs, and networks interact across cloud boundaries and develop security approaches that protect those interactions without unnecessarily limiting business or technology objectives.
Particular emphasis will be placed on IAM and API security, including practical application of OAuth, JSON Web Tokens (JWT), and mutual TLS (mTLS). The architect must also understand cloud and network security sufficiently to identify architectural weaknesses, recommend appropriate controls, and help technical teams implement secure solutions consistently across GCP, AWS, and Azure.
The successful candidate must demonstrate meaningful hands-on architecture experience across GCP, AWS, and Azure rather than experience limited to a single cloud platform. The candidate should be able to explain how security architectures and controls differ among the platforms while also demonstrating the ability to create consistent multi-cloud security principles.
Strong IAM and API-security expertise is essential. Candidates should demonstrate practical understanding of OAuth, JWT, and mTLS and be able to explain when and why each mechanism would be used, the security problems each address, and common architectural mistakes associated with their implementation.
Strong network-security architecture capability is also required. The candidate must be able to reason across cloud boundaries and evaluate how identities, applications, APIs, services, and networks interact to create—or reduce—security risk.
Objectives
1. Establish a Secure Multi-Cloud Architecture Across GCP, AWS, and Azure. During the initial 90–180 days, assess the relevant security architecture across GCP, AWS, and Azure and establish practical architectural patterns for protecting applications, services, identities, APIs, and network interactions across these environments. Identify material architectural weaknesses, inconsistent security approaches, and cross-cloud dependencies requiring remediation or standardization. Translate findings into actionable security designs and priorities that technical teams can use when implementing or modifying cloud solutions. Success will be measured by adoption of defined architectural patterns, resolution or mitigation of priority security gaps, and improved consistency of security design across the multi-cloud environment. AI-assisted architecture analysis may be used where appropriate, with recommendations independently evaluated by the architect before adoption.
2. Strengthen Identity and Access Management Across the Multi-Cloud Environment. During the first six months, evaluate IAM architecture across applicable GCP, AWS, and Azure environments and define secure approaches for authentication, authorization, identity relationships, and access to cloud resources. Identify excessive, inconsistent, or poorly designed access patterns and develop architectural recommendations that improve security while maintaining necessary business and technical functionality. Work with appropriate technical stakeholders to translate IAM security principles into implementable designs and reusable patterns. Success will be measured by implementation of improved IAM architecture, reduction of material identity-related security risks, and increased consistency in how access is designed and controlled across cloud environments.
3. Design and Implement Secure API Architecture. During the first six months and throughout the engagement, establish secure architectural approaches for APIs and service-to-service communications using appropriate authentication, authorization, encryption, and trust mechanisms. Apply practical knowledge of OAuth, JWT, mTLS, and related API-security concepts to determine how identities, tokens, certificates, and permissions should be managed across application and cloud boundaries. Review proposed or existing API architectures for material security weaknesses and provide technically actionable recommendations for remediation. Success will be measured by adoption of secure API patterns, resolution of significant API-security weaknesses, and demonstrated implementation of appropriate authentication and authorization controls.
4. Improve Network Security Architecture Across Cloud Boundaries. Throughout the engagement, evaluate network security requirements associated with applications, services, APIs, and data moving within and between GCP, AWS, and Azure environments. Develop architectural approaches that appropriately control connectivity, segmentation, trust boundaries, and secure communication while supporting required system functionality. Identify high-risk network design issues and work with technical teams to develop practical remediation approaches that align with the broader cloud security architecture. Success will be measured by implementation of secure network patterns, mitigation of material architectural risks, and improved consistency in network security across cloud environments.
Subtasks
1. Assess the Existing Multi-Cloud Security Environment. During the first 30–60 days, develop an understanding of the relevant GCP, AWS, and Azure environments, including applications, identities, APIs, network connections, trust relationships, and existing security architecture. Identify major architectural dependencies and areas where different cloud platforms or security approaches interact. Prioritize security concerns according to their potential impact and establish an initial architectural work plan. Success will be measured by completion of a usable multi-cloud security assessment and agreement on the highest-priority architectural issues requiring attention.
2. Define Multi-Cloud Security Architecture and Design Patterns. Within the first 90 days, translate assessment findings into practical security architecture principles and reusable design patterns that can be applied across GCP, AWS, and Azure. Address how applications, services, identities, APIs, and networks should be secured while recognizing legitimate differences among the three cloud platforms. Success will be measured by stakeholder acceptance, technical usability, and application of the patterns to cloud solutions.
3. Establish Secure IAM Architecture. Within the first 90–180 days, evaluate identity and access patterns affecting cloud resources and develop appropriate IAM architecture for applicable GCP, AWS, and Azure services. Define approaches to authentication, authorization, permissions, and identity relationships that reduce unnecessary access while preserving required functionality. Review implementations for significant deviations or weaknesses and provide actionable remediation guidance to technical teams. Success will be measured by improved IAM consistency, implementation of recommended patterns, and remediation of priority identity-related risks.
4. Secure APIs and Service-to-Service Communications. Throughout the engagement, evaluate API and service communications and determine appropriate security controls based on the architecture and risk of each interaction. Apply OAuth, JWT, mTLS, and other appropriate mechanisms to establish secure authentication, authorization, token handling, encrypted communication, and trust between services. Troubleshoot architectural weaknesses involving identity, tokens, certificates, permissions, or service trust and provide implementable solutions. Success will be measured by secure API implementations, resolution of material security issues, and consistent application of approved API-security patterns.
5. Strengthen Multi-Cloud Network Security. During the first six months, review network connectivity and trust boundaries associated with relevant workloads across GCP, AWS, and Azure. Identify architectural risks involving network access, segmentation, cross-cloud connectivity, or service exposure and develop appropriate technical recommendations. Success will be measured by remediation of priority network-security issues and adoption of more consistent network-security architecture.
6. Review Implementations and Drive Architectural Adoption. Throughout the engagement, work with technical stakeholders to review proposed and existing cloud solutions against established security architecture and identify deviations requiring attention. Translate security findings into practical recommendations and help engineering teams understand the technical reasoning behind required IAM, API, cloud, and network controls.
Definition of Success
Within the first six months, the Multi-Cloud Security Architect has developed a credible understanding of the GCP, AWS, and Azure environment, identified significant security architecture risks, and established practical approaches for IAM, API security, service-to-service communication, and network security.
More importantly, the architect's work results in implemented security improvements rather than architecture documents alone. Engineering teams are using the recommended patterns, priority architectural weaknesses are moving toward remediation, and the organization has a clearer and more consistent approach for securing applications, identities, APIs, and networks across its multi-cloud environment.
The architect is ultimately viewed as someone who can take a complex multi-cloud security problem, understand the technical and security implications, design a practical solution, and influence technical teams to implement it successfully.
Industry: Transportation
Location: Dallas, TX or San Antonio, TX — Onsite / Co-Located
Employment Type: Contract-to-Hire
Work Authorization: Must be a U.S. Citizen or U.S. Permanent Resident. No current or future sponsorship available.
Overview
The Multi-Cloud Security Architect will provide security architecture leadership across cloud environments spanning Google Cloud Platform (GCP), Amazon Web Services (AWS), and Microsoft Azure. The role will focus on developing secure architectural approaches for cloud services, identity and access management (IAM), APIs, authentication and authorization, and network connectivity across a multi-cloud technology environment.
This is an architecture role requiring the ability to translate security principles into practical technical designs. The architect will evaluate how applications, services, identities, APIs, and networks interact across cloud boundaries and develop security approaches that protect those interactions without unnecessarily limiting business or technology objectives.
Particular emphasis will be placed on IAM and API security, including practical application of OAuth, JSON Web Tokens (JWT), and mutual TLS (mTLS). The architect must also understand cloud and network security sufficiently to identify architectural weaknesses, recommend appropriate controls, and help technical teams implement secure solutions consistently across GCP, AWS, and Azure.
The successful candidate must demonstrate meaningful hands-on architecture experience across GCP, AWS, and Azure rather than experience limited to a single cloud platform. The candidate should be able to explain how security architectures and controls differ among the platforms while also demonstrating the ability to create consistent multi-cloud security principles.
Strong IAM and API-security expertise is essential. Candidates should demonstrate practical understanding of OAuth, JWT, and mTLS and be able to explain when and why each mechanism would be used, the security problems each address, and common architectural mistakes associated with their implementation.
Strong network-security architecture capability is also required. The candidate must be able to reason across cloud boundaries and evaluate how identities, applications, APIs, services, and networks interact to create—or reduce—security risk.
Objectives
1. Establish a Secure Multi-Cloud Architecture Across GCP, AWS, and Azure. During the initial 90–180 days, assess the relevant security architecture across GCP, AWS, and Azure and establish practical architectural patterns for protecting applications, services, identities, APIs, and network interactions across these environments. Identify material architectural weaknesses, inconsistent security approaches, and cross-cloud dependencies requiring remediation or standardization. Translate findings into actionable security designs and priorities that technical teams can use when implementing or modifying cloud solutions. Success will be measured by adoption of defined architectural patterns, resolution or mitigation of priority security gaps, and improved consistency of security design across the multi-cloud environment. AI-assisted architecture analysis may be used where appropriate, with recommendations independently evaluated by the architect before adoption.
2. Strengthen Identity and Access Management Across the Multi-Cloud Environment. During the first six months, evaluate IAM architecture across applicable GCP, AWS, and Azure environments and define secure approaches for authentication, authorization, identity relationships, and access to cloud resources. Identify excessive, inconsistent, or poorly designed access patterns and develop architectural recommendations that improve security while maintaining necessary business and technical functionality. Work with appropriate technical stakeholders to translate IAM security principles into implementable designs and reusable patterns. Success will be measured by implementation of improved IAM architecture, reduction of material identity-related security risks, and increased consistency in how access is designed and controlled across cloud environments.
3. Design and Implement Secure API Architecture. During the first six months and throughout the engagement, establish secure architectural approaches for APIs and service-to-service communications using appropriate authentication, authorization, encryption, and trust mechanisms. Apply practical knowledge of OAuth, JWT, mTLS, and related API-security concepts to determine how identities, tokens, certificates, and permissions should be managed across application and cloud boundaries. Review proposed or existing API architectures for material security weaknesses and provide technically actionable recommendations for remediation. Success will be measured by adoption of secure API patterns, resolution of significant API-security weaknesses, and demonstrated implementation of appropriate authentication and authorization controls.
4. Improve Network Security Architecture Across Cloud Boundaries. Throughout the engagement, evaluate network security requirements associated with applications, services, APIs, and data moving within and between GCP, AWS, and Azure environments. Develop architectural approaches that appropriately control connectivity, segmentation, trust boundaries, and secure communication while supporting required system functionality. Identify high-risk network design issues and work with technical teams to develop practical remediation approaches that align with the broader cloud security architecture. Success will be measured by implementation of secure network patterns, mitigation of material architectural risks, and improved consistency in network security across cloud environments.
Subtasks
1. Assess the Existing Multi-Cloud Security Environment. During the first 30–60 days, develop an understanding of the relevant GCP, AWS, and Azure environments, including applications, identities, APIs, network connections, trust relationships, and existing security architecture. Identify major architectural dependencies and areas where different cloud platforms or security approaches interact. Prioritize security concerns according to their potential impact and establish an initial architectural work plan. Success will be measured by completion of a usable multi-cloud security assessment and agreement on the highest-priority architectural issues requiring attention.
2. Define Multi-Cloud Security Architecture and Design Patterns. Within the first 90 days, translate assessment findings into practical security architecture principles and reusable design patterns that can be applied across GCP, AWS, and Azure. Address how applications, services, identities, APIs, and networks should be secured while recognizing legitimate differences among the three cloud platforms. Success will be measured by stakeholder acceptance, technical usability, and application of the patterns to cloud solutions.
3. Establish Secure IAM Architecture. Within the first 90–180 days, evaluate identity and access patterns affecting cloud resources and develop appropriate IAM architecture for applicable GCP, AWS, and Azure services. Define approaches to authentication, authorization, permissions, and identity relationships that reduce unnecessary access while preserving required functionality. Review implementations for significant deviations or weaknesses and provide actionable remediation guidance to technical teams. Success will be measured by improved IAM consistency, implementation of recommended patterns, and remediation of priority identity-related risks.
4. Secure APIs and Service-to-Service Communications. Throughout the engagement, evaluate API and service communications and determine appropriate security controls based on the architecture and risk of each interaction. Apply OAuth, JWT, mTLS, and other appropriate mechanisms to establish secure authentication, authorization, token handling, encrypted communication, and trust between services. Troubleshoot architectural weaknesses involving identity, tokens, certificates, permissions, or service trust and provide implementable solutions. Success will be measured by secure API implementations, resolution of material security issues, and consistent application of approved API-security patterns.
5. Strengthen Multi-Cloud Network Security. During the first six months, review network connectivity and trust boundaries associated with relevant workloads across GCP, AWS, and Azure. Identify architectural risks involving network access, segmentation, cross-cloud connectivity, or service exposure and develop appropriate technical recommendations. Success will be measured by remediation of priority network-security issues and adoption of more consistent network-security architecture.
6. Review Implementations and Drive Architectural Adoption. Throughout the engagement, work with technical stakeholders to review proposed and existing cloud solutions against established security architecture and identify deviations requiring attention. Translate security findings into practical recommendations and help engineering teams understand the technical reasoning behind required IAM, API, cloud, and network controls.
Definition of Success
Within the first six months, the Multi-Cloud Security Architect has developed a credible understanding of the GCP, AWS, and Azure environment, identified significant security architecture risks, and established practical approaches for IAM, API security, service-to-service communication, and network security.
More importantly, the architect's work results in implemented security improvements rather than architecture documents alone. Engineering teams are using the recommended patterns, priority architectural weaknesses are moving toward remediation, and the organization has a clearer and more consistent approach for securing applications, identities, APIs, and networks across its multi-cloud environment.
The architect is ultimately viewed as someone who can take a complex multi-cloud security problem, understand the technical and security implications, design a practical solution, and influence technical teams to implement it successfully.
