
Cloud Security Architect - St. Louis, MO
Hubbell Incorporated1 hour ago
St. Louis, MO, USASenior
Responsibilities
- Define and champion security best practices, standards, guidelines, and reference architectures for software solutions and development practices.
- Review Terraform and infrastructure-as-code changes for security misconfigurations, policy alignment, and compliance requirements.
- Establish and maintain security controls for AKS and EKS, including RBAC, network segmentation, network policies, secrets management, and container security.
- Review architecture and design decisions to identify and mitigate security risks.
- Advise engineers and stakeholders on threat modeling, risk assessment, security trade-offs, tools, vendors, and integrations.
- Own compliance activities aligned with external cybersecurity standards, including SOC 2 control execution, evidence collection, auditor engagement, gap identification, and remediation.
- Serve as the liaison between the software engineering team and the external cybersecurity organization.
- Lead security questionnaire responses for RFPs and sales processes and maintain security posture documentation.
Requirements
- At least 8 years of experience in DevOps, platform engineering, or cloud infrastructure with meaningful security ownership, or an equivalent blend of engineering and security experience.
- Hands-on experience securing Azure environments, including Azure AD/Entra ID, IAM, and network security controls.
- Experience reviewing and hardening Terraform and other infrastructure-as-code for security misconfigurations and policy compliance.
- Working knowledge of Kubernetes security in managed environments such as AKS and/or EKS, including RBAC, network policies, secrets management, and container image scanning.
- Participation in at least one SOC 2 audit cycle, including familiarity with control mapping, evidence collection, and auditor engagement.
- Ability to translate technical security posture into RFP questionnaire responses and compliance documentation.
- Ability to communicate effectively with engineers and non-technical stakeholders.
- Bachelor’s degree in computer science, engineering, or a related field.
- Preferred experience with DevSecOps and integrating Checkov, Mend, Checkmarx, or other SCA, SAST, and DAST tooling into CI/CD pipelines.
- Preferred familiarity with Azure Policy for Kubernetes, Defender for Containers, ACR container image scanning, AWS security controls, threat modeling, and secure design reviews.
- AZ-500 or a similar cloud-focused certification is preferred.