Summary
✨ AI‑Generated
A financial technology consulting environment is seeking an experienced cloud architect to design and implement security architecture across enterprise AWS and Azure estates. The role focuses on defense-in-depth, security guardrails, cloud governance, and protecting large-scale cloud environments. Candidates must be based in Poland.
Highlights
Senior cloud architecture opportunity focused on securing enterprise-scale AWS and Azure environments, with substantial influence over cloud security architecture, governance, and defense-in-depth controls.
Description
CAPCO POLAND
We are looking for Poland based candidate.
At Capco, we specialize in management consulting and technology transformation for the financial services industry.
We combine innovative thinking with deep industry expertise to help our clients navigate complex change, deliver meaningful outcomes, and build future-ready organizations.
Our culture is entrepreneurial, collaborative, and inclusive.
We empower our people to challenge the status quo, take ownership, and make an impact from day one.
As we continue to expand our Cloud and Cybersecurity capabilities, we are looking for an experienced Cloud Architect – Security & Guardrails (AWS/Azure) to help shape and secure enterprise-scale cloud environments.
Role Overview
We are looking for a highly skilled Cloud Architect to provide cloud security architecture services across enterprise AWS and Azure environments.
This role goes beyond traditional cloud architecture.
You will design and implement robust defense-in-depth security frameworks, establish automated compliance guardrails, integrate advanced security platforms, and drive cloud security governance across complex environments.
Working at the intersection of Cloud Engineering, Cybersecurity, Risk, and Security Operations, you will contribute to ensuring cloud platforms remain secure, compliant, resilient, and continuously monitored.
Key Responsibilities
Cloud Security Governance & GuardrailsDesign, implement, and enforce security baselines and preventative guardrails across AWS and Azure environments.Develop governance frameworks leveraging:AWS OrganizationsService Control Policies (SCPs)AWS Control TowerAzure PolicyAzure Landing ZonesEnsure alignment with internal security standards, regulatory requirements, and industry best practices.
SIEM, Monitoring & Logging Architecture
Design and optimize multi-cloud logging and monitoring strategies.Build scalable telemetry pipelines integrating:AWS CloudTrailAmazon GuardDutyAzure Activity LogsMicrosoft Defender for CloudEnable centralized visibility through enterprise SIEM platforms such as:Microsoft SentinelSplunkSupport real-time threat detection, correlation, investigation, and alerting capabilities.
Endpoint & Workload Protection
Define architecture and deployment strategies for:EDR/XDR solutionsCloud Workload Protection Platforms (CWPP)Secure virtual machines, containers, Kubernetes environments, and serverless workloads across cloud platforms.Collaborate with Security Operations teams to enhance threat detection and response.
Vulnerability & Security Posture Management
Implement and optimize Cloud Security Posture Management (CSPM) capabilities.Establish enterprise vulnerability management processes across cloud assets.Enable continuous security scanning for:Cloud misconfigurationsInfrastructure vulnerabilitiesContainer imagesOperating systemsDevelop automated remediation workflows and security playbooks.
Identity & Access Security
Design and enforce Zero-Trust security principles.Strengthen Identity and Access Management (IAM) governance across cloud platforms.Implement:Just-In-Time (JIT) accessPrivileged Access Management (PAM)Role-Based Access Control (RBAC)Federated identity solutionsPartner with security stakeholders to reduce privileged access risks.
Security Technology Integration
Evaluate, deploy, and govern best-in-class cloud security technologies.Integrate third-party security platforms including:CyberArkWizPalo Alto Prisma CloudCrowdStrikeOther strategic security toolingDrive consistent security controls and operational excellence across the cloud ecosystem.
Required Qualifications
Extensive experience designing and securing enterprise-scale AWS and Azure environments.Deep knowledge of cloud-native security services, controls, and governance frameworks.Hands-on expertise with:SIEM platformsEDR/XDR technologiesVulnerability management solutionsCSPM tools
Strong Experience Implementing
Azure PolicyAWS Control TowerService Control Policies (SCPs)Cloud governance frameworks
Advanced Infrastructure as Code (IaC) skills, particularly with Terraform.Experience embedding security controls into CI/CD and cloud deployment pipelines.Strong understanding of:
Modern cyber threatsMITRE ATT&CK frameworkCloud attack vectorsSecurity monitoring and incident response processes
Proven Ability To Collaborate Effectively With
Cloud Engineering teamsSecurity Operations Centers (SOC)Risk, Compliance, and Audit functions
Excellent stakeholder management and communication skills.
We offer a flexible collaboration model based on a B2B contract, with the opportunity to work on diverse projects.
Recruitment Process
HR Interview with the recruiterTechnical InterviewClient Interview Feedback and offer