More jobs:
Security Architect; Cloud Security & Compliance
Job in
New Britain, Hartford County, Connecticut, 06051, USA
Listed on 2026-01-16
Listing for:
Stanley Black & Decker
Full Time
position Listed on 2026-01-16
Job specializations:
-
IT/Tech
Cybersecurity, Systems Engineer
Job Description & How to Apply Below
( Optional Analytics - see below for details). (
** Optional Analytics*** +
** Google Analytics
** to gather external career site traffic metrics. +
** Tracking Pixels
** to track the source of traffic to your external career site.
** Security Architect (Cloud Security & Compliance) - Hybrid
**** New Britain, CT, United States
**** Towson, MD, United States
**** Come build something that matters.
**** The Job:
** As a Security Architect (Cloud Security & Compliance), you’ll be part of our Information Technology team working as a hybrid employee.
You’ll get to:
** Cloud Security Architecture & Strategy:
*** Design, develop, and oversee the implementation of comprehensive security architectures for AWS cloud environments and connected products, ensuring confidentiality, integrity, and availability of systems and data.
** Security Solution Design & Integration:
*** Architect and integrate AWS native security tools (e.g., Guard Duty, Security Hub, IAM, KMS, Cloud Trail, Config) and external solutions (e.g., CSPM, Secure SDLC, SIEM) for holistic security coverage.
** AST - Application security testing:
*** Knowledge and understanding of static analysis, software composition analysis, dynamic analysis, secret scanner etc.
** Compliance & Certification:
*** Lead the security strategy for SOC2, NIST, ISO
27001, and other regulatory certifications. Define and maintain documentation, evidence, and processes required for compliance readiness.
** Governance, Risk, and Compliance (GRC):
*** Architect and oversee GRC processes, including risk assessments, policy development, control mapping, and remediation tracking for cloud environments.
** Security Automation &
Infrastructure:
*** Design and implement automated security controls and monitoring solutions using infrastructure-as-code (Terraform, Cloud Formation), CI/CD pipelines, and scripting (Python, Shell).
** Incident Response Strategy:
*** Develop and guide incident response plans, lead detection and investigation efforts, and coordinate with internal teams for timely resolution and root cause analysis.
** Vulnerability Management Oversight:
*** Architect vulnerability management programs, including regular assessments, penetration testing, and remediation for cloud infrastructure and applications.
** Security Awareness & Enablement:
*** Lead organization-wide security awareness initiatives, provide training, and foster a culture of security through strategic communication and enablement.
** Documentation & Reporting:
*** Define and maintain security architecture documentation, controls, incident records, and compliance activities. Prepare executive-level reports for stakeholders and leadership.
** The Person:
*** 10+ years of experience in security architecture, cloud security, or related roles.
* Proven track record designing and managing security architectures in AWS cloud environments.
* Experience leading organizations through SOC2, NIST, ISO
27001, or similar compliance frameworks.
* Undergraduate degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field, or equivalent work experience in cloud security and architecture.
* Preferred certifications: AWS Certified Security – Specialty, Certified Information Systems Security Professional (CISSP), Certified Cloud Security Professional (CCSP).
** Core Technologies and Skills**
* ** AWS Security Tools:
** Guard Duty, Security Hub, IAM, KMS, Cloud Trail, Config, Macie, Inspector.
* ** External Security Solutions:
*** WIZ.io, Mend.io, Sonar Qube, Cortex, Akamai, Cognito, Balbix, Splunk, Git Leaks or similar
* ** GRC Platforms:
** Service Now GRC, Archer, One Trust, and related processes.
* ** Infrastructure as Code:
** Terraform, Cloud Formation for security automation and compliance.
* ** CI/CD Security:
** Security integration in CI/CD pipelines (Bitbucket, Jenkins, Git Hub Actions).
* ** Scripting:
** Python and Shell for automation and security tasks.
* ** Vulnerability Management:
** Vulnerability scans, penetration testing, and remediation.
* ** Regulatory Knowledge:
** SOC2, NIST, ISO
27001, GDPR, and other relevant regulations.
* ** Monitoring & Logging:
** Security monitoring, SIEM solutions, and log…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×