Cloud Security Architect
Camlin Group Belgrade, Central Serbia, Serbia
Energy Technology · 501-1,000 employees
About the role
The Cloud Security Architect will design secure, scalable cloud infrastructures and embed security by design across product and engineering teams. They are responsible for establishing security standards, conducting threat modelling, and overseeing automated incident response and monitoring.
What they look for
Requirements
Candidates must have at least 5 years of experience in cloud security with deep expertise in AWS and secure DevOps practices. Proficiency in network security, containerization, and relevant security certifications like CISSP or CCSP is required.
Full description
Position Overview
The Cloud Security Architect will play a critical role in designing secure, scalable and resilient cloud infrastructures.
This role partners closely with Product, Engineering, QA, Compliance and ISMS teams to embed security by design, deliver secure guidance, and ensure that cloud and SaaS environments are resilient against evolving threats. The ideal candidate brings a strong technical foundation, a proactive security mindset, and the ability to translate complex security concepts into actionable engineering practices.
This position requires a strong focus on Cloud Security toolchains (e.g. AWS, Azure, Platform independent). This position requires a hands–on architect with a deep understanding of cloud security architectures and secure DevOps practices.
Responsibilities
General Work
- Architecture Design: Create high-level (HLD) and low-level (LLD) design blueprints for secure public/private cloud environments.
- Cloud Security Strategy: Establish security standards, policies, and roadmaps aligned with business goals.
- Control Design: Design security tools such as firewalls, SIEM, intrusion detection/prevention, and encryption.
- Risk Management: Conduct threat modelling, vulnerability assessments, and penetration testing to identify and remediate risks.
- Compliance: Ensure cloud infrastructure adheres to industry standards (ISO27001 ISO27017, NIST CSF).
- Governance & Collaboration: Work with DevOps, ISMS, and engineering teams to embed security into the development lifecycle (DevSecOps).
- Identity Management: Define IAM roles, policies, and access controls
Threat Modelling, Secure Design and Risk Analysis
- Conduct structured threat modelling exercises using e.g. PASTA methodologies during design and cloud infrastructure planning.
- Identify potential attack vectors, assess risk impact, and recommend mitigation strategies.
- Support ongoing risk management activities and contribute to risk registers.
- Be an integral part for the Secure Design phase in the SDLC
- Designing secure VPCs, subnets, and network segmentation to manage traffic. Proficiency in micro segmentation and securing API gateways.
Cloud Application Security Testing and Monitoring
- Oversee application security assessments, including manual and automated penetration testing and remediations to meet SLAs.
- Be responsible for the security of our platforms in the cloud, monitoring, investigation and IR.
- Design securely configured monitoring tool chains, setting alert threshold levels and notifications
- Monitor application and cloud environments for security anomalies and vulnerabilities.
- Support Tier 3 response activities
- Automate Incident Response and Triage to meet customer SLAs
Security Automation
- Work with DevOps teams to embed security tooling and automation into CI/CD pipelines.
- Support continuous integration, testing, and delivery practices with a security-first approach.
- Evaluate and design new security tools, technologies, and best practices.
Documentation & Reporting
- Create, update, and maintain tickets related to security findings and testing outcomes.
- Produce clear technical documentation, including assessment reports, remediation guidance, and architectural security recommendations.
Essential Criteria
- 5+ years in Cloud security, with significant experience in cloud architecture and design.
- Cloud Expertise: Deep knowledge of public cloud providers, specifically AWS.
- Technical Knowledge: Proficiency in network security, virtualization, containers (Docker, Kubernetes), and API security.
- Certifications such as CISSP, CCSP, or platform-specific certifications (AWS Certified Security, Azure Security Engineer).
- Cryptography: deep understanding of cryptographic protocols, techniques and configurations, able to offer best selection for various applications and needs.
Personal Attributes
- A collaborative team player who thrives under pressure and meets tight deadlines.
- Clear and confident communicator with strong interpersonal skills.
- Highly organised, detail-oriented, and quality-focused.
- Demonstrates initiative, ownership, and a proactive approach to solving technical challenges.
- Positive, enthusiastic, and committed to continuous improvement and learning.
- Excellent communication skills, capable of translating complex technical risk into business-relevant language.
- Strong problem‑solving abilities and a proactive, ownership-driven mindset.
- Ability to work within cross‑functional teams.
Our Values
- We work together
- We believe in people
- We won’t accept the ‘way it has always been done’
- We listen to learn
- We’re trying to do the right thing
Equal Employment Opportunity Statement
Individuals seeking employment at Camlin are considered without regards to race, colour, religion, national origin, age, sex, marital states, ancestry, physical or mental disability, gender identity or sexual orientation.