Cloud Architect – Security & Guardrails (AWS/Azure)
Capco
Make my CV for this job, freeView job and applyYour CV, rewritten for this role using only your real experience. Sign in with Google and upload your CV. Nothing to install.
Skills named in this job
Read from the description itself, not inferred.
This role on the market
4 open guardrails roles across 2 companies are on ApplySarthi right now.
What guardrails roles keep asking for: AWS (25%), Azure (25%), B2B (25%), CI/CD (25%), IAM (25%), Kubernetes (25%), SIEM (25%), Serverless (25%) — counted across their open postings here.
AWS jobs · Azure jobs · CI/CD jobs · IAM jobs
Capco has 726 open roles listed here.
- Automation Tester - Salesforce-bengaluru
- Business Analyst - Procurement
- Business Analyst - Procurement
- Business Analyst - Procurement
- Business Analyst - Procurement
Counted across 14 company job boards, updated as roles open and close.
Preparing for this interview
Interviews for guardrails roles keep coming back to AWS, Azure, B2B, CI/CD. Practise those questions before you sit with Capco.
Questions you are likely to be asked
- Why do you want to join Capco?
- What is your experience with AWS? Tell me one thing you learned the hard way.
- How would you cut the cloud bill of a system without hurting it?
- How do you keep secrets and access safe in your infrastructure?
- Walk me through how code gets from a commit to production where you work.
Prep Sarthi gives you a free mock interview: an AI interviewer asks you questions like these out loud, from your own CV and this job, and shows your score and your weakest answer.
Practise the Cloud Architect – Security & Guardrails (AWS/Azure) at Capco interview free →CAPCO POLAND
*We are looking for Poland based candidate.
At Capco, we specialize in management consulting and technology transformation for the financial services industry. We combine innovative thinking with deep industry expertise to help our clients navigate complex change, deliver meaningful outcomes, and build future-ready organizations.
Our culture is entrepreneurial, collaborative, and inclusive. We empower our people to challenge the status quo, take ownership, and make an impact from day one.
As we continue to expand our Cloud and Cybersecurity capabilities, we are looking for an experienced Cloud Architect – Security & Guardrails (AWS/Azure) to help shape and secure enterprise-scale cloud environments.
ROLE OVERVIEW:
We are looking for a highly skilled Cloud Architect to provide cloud security architecture services across enterprise AWS and Azure environments.
This role goes beyond traditional cloud architecture. You will design and implement robust defense-in-depth security frameworks, establish automated compliance guardrails, integrate advanced security platforms, and drive cloud security governance across complex environments.
Working at the intersection of Cloud Engineering, Cybersecurity, Risk, and Security Operations, you will contribute to ensuring cloud platforms remain secure, compliant, resilient, and continuously monitored.
KEY RESPONSIBILITIES:
-
Cloud Security Governance & Guardrails
- Design, implement, and enforce security baselines and preventative guardrails across AWS and Azure environments.
- Develop governance frameworks leveraging:
- AWS Organizations
- Service Control Policies (SCPs)
- AWS Control Tower
- Azure Policy
- Azure Landing Zones
- Ensure alignment with internal security standards, regulatory requirements, and industry best practices.
SIEM, Monitoring & Logging Architecture
- Design and optimize multi-cloud logging and monitoring strategies.
- Build scalable telemetry pipelines integrating:
- AWS CloudTrail
- Amazon GuardDuty
- Azure Activity Logs
- Microsoft Defender for Cloud
- Enable centralized visibility through enterprise SIEM platforms such as:
- Microsoft Sentinel
- Splunk
- Support real-time threat detection, correlation, investigation, and alerting capabilities.
Endpoint & Workload Protection
- Define architecture and deployment strategies for:
- EDR/XDR solutions
- Cloud Workload Protection Platforms (CWPP)
- Secure virtual machines, containers, Kubernetes environments, and serverless workloads across cloud platforms.
- Collaborate with Security Operations teams to enhance threat detection and response.
Vulnerability & Security Posture Management
- Implement and optimize Cloud Security Posture Management (CSPM) capabilities.
- Establish enterprise vulnerability management processes across cloud assets.
- Enable continuous security scanning for:
- Cloud misconfigurations
- Infrastructure vulnerabilities
- Container images
- Operating systems
- Develop automated remediation workflows and security playbooks.
Identity & Access Security
- Design and enforce Zero-Trust security principles.
- Strengthen Identity and Access Management (IAM) governance across cloud platforms.
- Implement:
- Just-In-Time (JIT) access
- Privileged Access Management (PAM)
- Role-Based Access Control (RBAC)
- Federated identity solutions
- Partner with security stakeholders to reduce privileged access risks.
Security Technology Integration
- Evaluate, deploy, and govern best-in-class cloud security technologies.
- Integrate third-party security platforms including:
- CyberArk
- Wiz
- Palo Alto Prisma Cloud
- CrowdStrike
- Other strategic security tooling
- Drive consistent security controls and operational excellence across the cloud ecosystem.
REQUIRED QUALIFICATIONS:
- Extensive experience designing and securing enterprise-scale AWS and Azure environments.Deep knowledge of cloud-native security services, controls, and governance frameworks.Hands-on expertise with:
- SIEM platforms
- EDR/XDR technologies
- Vulnerability management solutions
- CSPM tools
- Azure Policy
- AWS Control Tower
- Service Control Policies (SCPs)
- Cloud governance frameworks
- Modern cyber threats
- MITRE ATT&CK framework
- Cloud attack vectors
- Security monitoring and incident response processes
- Cloud Engineering teams
- Security Operations Centers (SOC)
- Risk, Compliance, and Audit functions
We offer a flexible collaboration model based on a B2B contract, with the opportunity to work on diverse projects.
Recruitment Process:
- HR Interview with the recruiter
- Technical Interview
- Client Interview
- Feedback and offer
#LI-HYBRID
Match this job to your CV
ApplySarthi scores your CV against this role, shows the skills you are missing, and writes a tailored version for the application.
Check my match →Similar open roles
- AI Architect Capco · bengaluru
- AI EngineerCapco · pune
- AI Engineer_Agentic AICapco · bengaluru
- Alteryx DeveloperCapco · mumbai
- Automation Testing – Selenium Java and API Capco · bengaluru
- BA Automation Specialist - MumbaiCapco · mumbai
- BA -Capital Market - BangaloreCapco · bengaluru
- BA- InsuranceCapco · pune
Need answers during your interview? Try Live Sarthi.
Live Sarthi, an Interview Sarthi app, shows answer suggestions during the call.
- Hidden from supported screen sharingThe overlay stays out of supported Windows screen captures.
- Answers start in about 1.5 secondsResponse time varies with your connection and model.
- From your own CVYour projects and your experience, not a generic script.
- 30 minutes freeThen ₹99 for a 2-day pass with unlimited calls — you pay for the days you are interviewing, not a subscription.
A Windows app, from the same team as ApplySarthi.
Listed on greenhouse · posted 2026-07-03. ApplySarthi collects openings and links to application pages; the role is advertised by Capco, not by us.