AWS Cloud Security Architect

  • Neoshore -
  • Tunis, Tunisie
  • Il'y a 1 mois
Postes vacants:
1 poste ouvert
Type d'emploi désiré :
CDI

Description de l'emploi

About Neoshore Neoshore is a fast-growing IT services company specializing in providing offshore teams of developers and technical experts. Based in Madagascar, Mauritius, and Tunisia, our talents help European tech companies accelerate their development. Our value proposition is built on reliability, technical excellence, and seamless integration within our clients' teams, backed by rigorous oversight and support to guarantee an impeccable quality of service. About the Mission The client firm is building out a secure, well-governed AWS foundation to support its platform and its expansion across several countries, as part of a broader operational-resilience programme (DORA). The mission is hands-on: architect it, then implement it, working alongside the internal development team. Mission Objectives Multi-account architecture: Design and implement the AWS organisation: account structure and OUs, guardrails (SCPs), centralised logging and billing, aligned with AWS Well-Architected and security best practices. Identity & access: Least-privilege IAM design: roles over long-lived keys, instance profiles for workloads, conditional access policies, joiner/leaver and key-rotation procedures. Networking: VPC design and isolation, network ACLs and security groups, secure connectivity to external partners (SSM Session Manager, bastion-less access patterns, proxying). Data protection & backups: Immutable, versioned, cross-account backup architecture (S3 Object Lock, lifecycle policies) with defined RTO/RPO and tested restores, plus a documented DR plan. Detection & operations: GuardDuty, CloudTrail, Config, alerting (SNS), billing-anomaly detection; patching and maintenance via SSM. Hybrid connectivity: Site-to-site VPN configuration and hybrid network connectivity (AWS Site-to-Site VPN, IPsec tunnels, routing, VPC-to-on-premise/partner network integration). Required Profile 8+ years in cloud/infrastructure engineering, with deep AWS specialisation and a strong security orientation. Current AWS certification required: AWS Certified Solutions Architect (Professional) and/or AWS Certified Security (Specialty). Associate-level certifications alone are insufficient for this seniority. Proven delivery of multi-account AWS foundations (Organizations, Control Tower or equivalent, SCPs) — not just single-account setups. Expert-level IAM: policy authoring, permission boundaries, conditional logic, migration away from static credentials. Strong AWS networking (VPC, endpoints, hybrid access) and SSM (Session Manager, Patch Manager, port forwarding). Backup/DR architecture with tested-restore discipline (S3 versioning, Object Lock, cross-account replication). Solid Terraform skills; solid Linux (Ubuntu) administration. Autonomous and pragmatic, documents work as it progresses; comfortable operating within a small senior team. Verifiable references from at least two comparable missions. Nice to Have Additional certifications: AWS Advanced Networking Specialty, GCIH, OSCP. Experience in regulated financial environments (DORA, ISO 27001). Multi-cloud exposure (DigitalOcean or similar).

Date d'expiration

06/08/2026