Back to jobs

Cloud Security Architect

Arlington, VA

Are you a cloud security expert with deep experience across AppSec, InfoSec, infrastructure, and DLP? Do you want to help shape, design, and execute secure architectures across Azure and AWS while managing complex enterprise security initiatives? If so, then you might be Fivesky’s next Cloud Security Architect!

Who you are:

  • Bachelor’s degree is required in Computer Science or Computer Engineering, or Computer Information Systems.
  • Experienced in Cloud Security Architecture or as an Information Security Engineer, specifically with enterprise-grade systems.
  • Deeply familiar with cloud platforms like Azure and AWS, including services across IaaS and PaaS environments.
  • Comfortable working in regulated, enterprise environments with complex security and compliance requirements.
  • Able to create processes, develop and design plans, and manage security team execution.
  • Experienced in stakeholder collaboration, documentation, and the delivery of security solutions at scale.

It would be awesome if you had:

  • Experience onboarding complex applications and leading cloud migration efforts from on-prem to cloud.
  • Proven ability to design and implement security solutions aligned to industry best practices and regulatory standards.
  • A history of writing and maintaining cloud security documentation, standards, and Security Reference Architectures.
  • Hands-on experience acting as an SME for AppSec, InfoSec, or infrastructure security across cloud environments.
  • Conduct collaborations across architecture and engineering teams in large organizations.

What you will do:

  • Create processes, develop and design plans and manage security team execution.
  • Work closely with stakeholders and present documentation and security solutions
  • Act as an SME when it involves AppSec, InfoSec, or Infrastructure security around Cloud, designing and architecting solutions for your organization.
  • Collaborate with other teams involved in architecture design.
  • Identify potential risks of projects, document and address those risks and work with other teams to resolve the issue.
  • Work with design, testing, and integration of security controls within an Enterprise environment.
  • Provide hands-on direction with application, technology risk management, and/or infrastructure security assignments.
  • Assess current security processes and offer recommendations to all levels within the organization up to the C Suite.
  • Perform thorough documentation of the development and implementation of processes.
  • Define strategy for the secure use of cloud services. Develop security requirements governing the use of individual cloud services and collections of cloud services in a design pattern.
  • Document security controls, requirements, designs, and configurations.
  • Engage proactively with customers to better understand their needs and risks.
  • Assess current risk associated with cloud services, and the change in risk posture over time as cloud security controls are implemented.
  • Advise Data Loss Policy development as per company’s evolving business needs and configure DLP policies to prevent data loss in email and web traffic.
  • Perform DLP three-tier installations and version upgrades for production, along with conducting periodic health checks and performance assessments.
  • Create procedures and workflows for production deployment and publish fixes in knowledge base.
  • Configure Network scans on appropriate DLP detection servers to identify stored sensitive information at-rest and quarantine data classified as Restricted.
  • Generate data indexes/fingerprints remotely to be later used in detection rules within DLP policies for exact data match (EDM) detection.
  • Integrate/Extend DLP capabilities to cloud applications for monitoring protected data-in-motion and data-at-rest using Cloud Access Security (MCAS/CASB).
  • Automate various aspects of security procedures using scripting languages based on Operating system in use.
  • Configure detection server settings to route network traffic through specific TCP ports for different network protocols.
  • Build DLP detection rules to monitor information being stored and transferred over different TCP ports from endpoint devices.
  • Configure prevent actions for protocols like HTTP/S, FTP, SMTP, SMB, SFTP, etc., including web block, email encryption and quarantine response rules for outgoing traffic.
  • Troublehoot Network issues relating to Firewall, traffic routing, network proxy, gateway — involving application and transport layer network protocols.
  • Develop Proxy auto config (PAC) files to route network traffic through defined proxy servers and configure IP addresses of specific ‘Network Prevent’ DLP detection servers to use ICAP protocol.
  • Understand network diagrams and network technologies like VPN tunneling, Network Address Translation (NAT), OSI model, LAN/WAN, SSL, packet trace analysis, etc., for structuring the DLP network architecture and network traffic routing.
  • Collaborate with Operations team to support troubleshooting of production issues and perform root cause analysis on data loss due to detection fails on network or email traffic from the DLP system.

Who we are: 

  • Fivesky is a fast-growing, global technology solution provider. We partner with the world’s largest financial service firms to deliver networking/infrastructure, cybersecurity, and cloud-based solutions for complex, global projects. 
  • At Fivesky, our employees are our greatest asset, and we strive to build a strong team culture centered on highly competitive compensation, professional development, career advancement, and fun.
  • This is an FTE position in Arlington, VA or unanticipated client sites within the US. The compensation package is based on experience and qualifications. The base salary range for this role is $ 173,056 - $180,000 per year. Benefits include: PTO/ paid sick leave, holidays, Health, Dental and Vision insurance, Retirement.
  • Fivesky is an equal-opportunity employer. Fivesky prohibits discrimination and harassment of any type and affords equal employment opportunities to employees and applicants without regard to race, sex, age, color, religion, national origin, sexual orientation, disability status, genetic information, protected veteran status (United States positions), or any other characteristic protected by law. 
  • Mail Resumes to:Fivesky, LLC, 1 Pennsylvania Plaza, Suite #2222, New York, NY 10119

(FS-RID-0467)

Apply for this job

*

indicates a required field

Resume/CV

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf



U.S. Standard Demographic Questions

We invite applicants to share their demographic background. If you choose to complete this survey, your responses may be used to identify areas of improvement in our hiring process.
Select...
Select...
Select...
Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Fivesky’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.