Senior AWS Cloud & Security Architect
IT
United States
Senior AWS Cloud & Security Architect
*EST or CST time zone location required
About Skopenow
Skopenow helps organizations efficiently collect and analyze open-source intelligence to uncover threats and detect fraud.
Founded in 2016 and headquartered in New York City, Skopenow is a high-growth, venture-backed technology company serving more than 1,500 customers worldwide. Our customers include Fortune 500 companies, government and law enforcement agencies, leading insurance carriers, media organizations, and more.
Our OSINT platform includes five products: Grid, Pre-Check, Workbench, Link Analysis, and Rabbit. Together, they help organizations automate threat detection and investigation workflows.
The Role
We’re looking for a Senior AWS Cloud & Security Architect to own the architecture, security, and ongoing management of the AWS environment supporting our SaaS platform.
This is a hands-on, security-first role for someone who combines deep AWS infrastructure and networking expertise with cloud security, DevSecOps, and security operations.
You’ll be responsible for ensuring our AWS environment is architected securely, implementing the tools and controls needed to detect vulnerabilities and threats, and proactively identifying and remediating security gaps.
We’re looking for someone who can do more than recommend solutions. You should be comfortable designing, building, automating, and implementing them.
What You’ll Own
You’ll take ownership of key areas across our AWS infrastructure and security environment, including:
- AWS Landing Zone design and implementation
- AWS Control Tower and multi-account architecture
- VPCs, network segmentation, public and private access, load balancers, security groups, and open-port management
- IAM and IAM Identity Center, including roles, permissions, account access, and least-privilege controls
- Access controls across S3, DynamoDB, and other AWS services
- AWS WAF, Network Firewall, GuardDuty, Security Hub, and CloudWatch
- Firewall rules, IP allowlisting, and network security boundaries
- Security monitoring, logging, alerting, and threat hunting
- SIEM integrations and security alert logic
- Identification and remediation of AWS security gaps, including findings surfaced through Vanta
- Golden container and image management, CVE remediation, and vulnerability management against established SLAs
- SBOM generation and scanning
- Automated vulnerability and application security scanning using Trivy, OWASP ZAP, SonarQube, and related tools
- Bitbucket pipeline design and DevSecOps security practices
- AWS backup strategy, retention, storage locations, and security
- Network diagrams, data-flow diagrams, security boundary mapping, and SSP management
- Secure implementation and management of Amazon Bedrock
- Building and automating new AWS infrastructure and security capabilities as our environment evolves
What We’re Looking For
You’re an experienced AWS architect with a security-first mindset who is equally comfortable designing cloud environments and getting hands-on to secure them.
You understand how AWS environments should be structured, how traffic and data should flow, where security boundaries belong, and which controls and tools should be in place to identify risk.
Ideally, you bring:
- Senior-level experience architecting, building, and securing production AWS environments
- Hands-on experience designing and implementing AWS Landing Zones
- Strong experience with AWS Control Tower and AWS-native security services
- Deep knowledge of AWS networking, network security, IAM, and access controls
- A strong background in cloud security and security operations
- Experience with GuardDuty, Security Hub, WAF, Network Firewall, and CloudWatch
- Experience with vulnerability management, CVE remediation, container and image security, and threat detection
- Experience implementing DevSecOps practices within CI/CD pipelines
- Familiarity with tools such as Trivy, OWASP ZAP, SonarQube, SBOM scanning, and SIEM platforms
- Experience securing infrastructure that supports a SaaS application
- The ability to create and maintain clear architecture, network, data-flow, and security documentation
Most importantly, you’re someone who can identify a security or infrastructure gap, determine the right solution, and take ownership of implementing