Cloud Security Architect
Ekco Dublin, Dublin, Ireland
IT Services and IT Consulting · 501-1,000 employees
About the role
You will lead secure cloud transformation for enterprise clients by defining security strategies, architectures, and remediation roadmaps. Additionally, you will guide client engagements from discovery through delivery while mentoring colleagues and shaping reusable architecture patterns.
What they look for
Requirements
The role requires substantial experience in designing secure enterprise cloud architectures, particularly in Azure, with knowledge of AWS and hybrid environments. Candidates must possess strong consulting skills and experience applying regulatory frameworks like GDPR, ISO 27001, and NIST to cloud environments.
Benefits
Full description
About Ekco
🚀 Founded in 2016, Ekco has quickly become one of Europe’s fastest-growing cloud solution providers and your trusted security-first Managed Service Provider. IT leaders choose Ekco to drive operational efficiency, scale smarter and stay ahead of risk – powered by local expertise, delivered at European scale.
We specialise in helping organisations advance their cloud maturity guiding transformation, strengthening security, and maximising the value of their technology investments.
☁️ In simple terms: we help organisations modernise with confidence securing their systems, optimising their cloud, and keeping them resilient in a rapidly changing world.
🌍 Today, we’re a thriving team of 1,000+ talented and supportive colleagues across the UK, Ireland, Benelux, South Africa, and Malaysia—and we’re continuing to grow.
At Ekco, how we work matters as much as what we deliver. Our people live by four core values that shape everything we do:
- On It: We take ownership, follow through, and get things done.
- All In : We collaborate, support each other, and commit fully to shared goals.
- Connected: We build trusted relationships with colleagues, clients, and partners.
- Hungry to Grow: We stay curious, keep learning, and push ourselves to the next level.
🏠If these values resonate with you, you’ll feel right at home here.
The Role
Day-to-day at Ekco:
We are looking for an experienced Cloud Security Architect to lead secure cloud transformation for enterprise and regulated clients. You will assess complex environments, define security strategies and architectures, and guide the delivery of secure solutions across cloud, hybrid and on-premises platforms.
As a trusted advisor, you will translate risk, regulatory obligations and business objectives into practical security designs, assessments and improvement roadmaps. You will lead client engagements from discovery and pre-sales through design assurance and delivery, produce clear technical and executive artefacts, and help shape reusable Ekco architecture patterns and services. This hybrid role is based in Dublin and may include travel to client sites.
What you’ll be responsible for:
- Security strategy and assurance: Assess cloud, hybrid and on-premises environments; define security strategies, target architectures, policies, risk registers and prioritised remediation roadmaps aligned to regulatory and industry frameworks.
- Secure cloud architecture: Design Cloud Adoption Framework aligned landing zones and guardrails across Azure and AWS, using Zero Trust principles, network segmentation, encryption, key and secrets management, data protection, sovereignty and secure backup and recovery patterns.
- Identity security: Architect workforce, privileged and workload identity controls using Microsoft Entra ID and AWS IAM, including Conditional Access, identity governance and privileged access management.
- Cloud-native security: Design posture management, policy enforcement and organisation level controls using services such as Azure Policy, Microsoft Defender for Cloud, Microsoft Sentinel, AWS Control Tower, Security Hub and GuardDuty.
- Threat modelling and design assurance: Lead threat modelling, architecture reviews and security decision making for applications, platforms, data services and emerging AI use cases.
- DevSecOps and automation: Embed policy as code, security testing, secrets scanning, dependency, container and software supply chain controls into infrastructure-as-code and CI/CD workflows.
- Detection, resilience and response: Define logging, monitoring, detection and cloud incident response requirements; integrate cloud platforms with SIEM and SOC services; and improve ransomware and operational resilience.
- Client leadership: Lead workshops and technical workstreams, support pre-sales and statements of work, mentor colleagues, and communicate architecture decisions, risks and recommendations to technical and executive stakeholders.
Essential Experience
- Substantial experience designing and assuring secure enterprise cloud architectures, preferably in Microsoft Azure, with practical knowledge of AWS and hybrid environments.
- Strong knowledge of identity, network, platform, application, data, security operations and resilience controls, including Zero Trust and shared responsibility principles.
- Hands-on experience with cloud governance, landing zones, Infrastructure as Code and automated delivery using Terraform, Bicep or equivalent tooling and Azure DevOps or GitHub Actions.
- Experience applying regulatory and security requirements such as GDPR, NIS2, DORA, ISO 27001, NIST, CIS, CSA and OWASP to cloud environments.
- Ability to conduct security assessments and threat modelling, evaluate technical risk, and produce architecture diagrams, security designs, risk registers, remediation roadmaps and executive reports.
- Strong consulting, leadership and stakeholder-management skills, including workshop facilitation, pre-sales support and the ability to explain complex risk in clear business language.
- A degree in a relevant discipline or equivalent professional experience.
Desirable Experience
- Experience securing AWS or Google Cloud alongside Azure, including multi-account or multi-subscription governance.
- Experience with Kubernetes, container security, software supply chain controls, AI security, data protection or regulated industry environments.
- Relevant certifications such as Microsoft Certified: Cybersecurity Architect Expert, Azure Security Engineer Associate, AWS Certified Security – Specialty, HashiCorp Certified: Terraform Associate, CISSP, CCSP or CISM; equivalent practical experience is equally valued.
- Professional membership or accreditation with ISC2, ISACA, CIISec or BCS.
Benefits / Perks
- ☀️ Time Off: 25 days annual leave + public holidays
- 🎂 Birthday Leave: One extra day off to celebrate
- 💰 Company Pension Scheme
- 📞 Employee Assistance Programme (EAP) for wellbeing support
- 🏃♀️ EkcOlympics: Global team activity challenges
- 📚 Unlimited access to Pluralsight for continuous development
- 🌱 Real opportunities to grow, including international progression
Why Ekco
- 🏅 Company of the year 2026 Tech Excellence Awards
- ⭐️ Microsoft 2023 Rising Star Security Partner of the Year
- 🚀 First Irish Microsoft MSP to achieve all four Microsoft Security Specialisations
- 🌈 A culture rooted in diversity, equity, inclusion, and belonging
- 🎉 Strong commitment to internal mobility and career progression
- ✨ Flexible, family‑friendly working at the heart of our culture
- 🔐 A trusted, security‑first MSP helping organisations scale smarter and stay ahead of risk