Cloud Security Architect
Job
ezyVet
Westbrook, ME (In Person)
$135,000 Salary, Full-Time
Review key factors to help you decide if the role fits your goals.
Pay Growth
?
out of 5
Not enough data
Not enough info to score pay or growth
Job Security
?
out of 5
Not enough data
Calculating job security score...
Total Score
83
out of 100
Average of individual scores
Skill Insights
Compare your current skills to what this opportunity needs—we'll show you what you already have and what could strengthen your application.
Job Description
IDEXX Laboratories is seeking a Cloud Security Architect to lead our multi-cloud security architecture across AWS, Azure, and GCP environments. This senior-level position will architect and implement cloud security posture management (CSPM) solutions, drive security standards enforcement, and partner with engineering teams to embed security controls directly into cloud deployment pipelines. You will play a critical role in protecting applications that serve our global veterinary diagnostics business while enabling development teams to move fast without compromising security. This position reports to the Senior Manager of Product & Application Security and works closely with DevOps engineers and cloud platform owners across the organization. In this role, you will be responsible for… Cloud Security Architecture & CSPM Architect, implement, and continuously improve cloud security posture management across AWS, Azure, and GCP environments supporting hundreds of applications Lead the migration from AquaSec to CrowdStrike Falcon CSPM, ensuring continuity of visibility and compliance enforcement Establish and maintain compliance with CIS Benchmarks Level 1 standards across all cloud platforms Design monitoring and alerting strategies that surface actionable security gaps to both security and engineering teams Infrastructure-as-Code Security Implement automated security scanning and policy enforcement for Terraform, CloudFormation, and other IaC frameworks Integrate tools like CrowdStrike Falcon, Checkov and Trivy into CI/CD pipelines to prevent misconfigurations before deployment Develop policy-as-code frameworks that codify security requirements and enable self-service compliance DevOps Partnership & Enablement Embed security controls directly into cloud deployment pipelines using native platform capabilities and third-party tooling Partner with DevOps teams to build secure-by-default infrastructure templates and golden paths Conduct architecture reviews for new cloud services and deployment patterns Translate complex security requirements into practical, actionable guidance for engineering teams Security Assessments & Risk Management Conduct cloud security assessments, threat modeling, and architecture reviews for critical workloads Identify and prioritize security risks based on business impact, exploitability, and compensating controls Work with product teams to implement mitigations that balance security effectiveness with operational feasibility Tooling, Automation & Metrics Manage and optimize cloud-native security tooling including CSPM, CNAPP, and secret scanning solutions Build automation to reduce manual security work and improve consistency of controls Establish metrics and reporting that demonstrate security posture improvement and compliance trends What You Will Need to Succeed Technical Expertise Deep hands-on experience architecting security controls in AWS, Azure, and GCP production environments Demonstrated proficiency with CSPM tools (CrowdStrike Falcon, Wiz, Prisma Cloud, or similar platforms) Strong knowledge of CIS Benchmarks, cloud security frameworks (CSA
CCM, NIST
), and compliance standards (SOC 2, GDPR, HIPAA) Expertise in Infrastructure-as-Code security scanning and policy enforcement (Checkov, Trivy, Terraform Sentinel, OPA) Experience integrating security controls into CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins, Azure DevOps) Solid understanding of container security, Kubernetes security, and serverless security patterns Proficiency with scripting and automation (Python, Bash, PowerShell) Strategic & Operational Skills Proven ability to design security architectures that scale across large, complex cloud environments Track record of successfully partnering with DevOps and engineering teams to implement security without blocking delivery Experience driving security tool migrations and consolidations with minimal disruption Strong analytical skills to assess risk, prioritize work, and make pragmatic security decisions Ability to translate technical security concepts into language that resonates with both technical and business stakeholders Leadership & Communication Excellent written and verbal communication skills; able to produce concise architecture documentation and executive summaries Demonstrated ability to influence engineering teams through technical credibility rather than authority Comfortable presenting security recommendations to senior technical leadership and defending design decisions Self-directed and outcome-focused; able to identify problems, propose solutions, and drive them to completion with minimal supervision Required 7 to 10+ years of experience in information security with at least 5 years focused on cloud security architecture Hands-on experience implementing and operating CSPM solutions in multi-cloud environments Proven track record architecting security controls for large-scale cloud deployments (1,000+ resources) Experience with CIS Benchmarks implementation and compliance enforcement Strong understanding of cloud-native architecture patterns and security implications Bachelor's degree in Computer Science, Information Security, or equivalent practical experience Preferred Relevant cloud security certifications (AWS Certified Security - Specialty, Azure Security Engineer Associate, GCP Professional Cloud Security Engineer, CCSP) Experience with CrowdStrike Falcon CSPM or other leadingCSPM/CNAPP
platforms Background in DevSecOps, SRE, or cloud platform engineering Familiarity with OWASP SAMM or similar security maturity frameworks Prior experience in regulated industries (healthcare, financial services) with SOC 2, HIPAA, or PCI-DSS compliance requirements Contributions to open-source security tools or cloud security communities What you can expect from us:- Base annual salary target: $120000 - $150000 (yes, we do have flexibility if needed)
- Opportunity for annual cash bonus
- Health / Dental / Vision Benefits Day-One
- 5% matching 401k
- Additional benefits including but not limited to financial support, pet insurance, mental health resources, volunteer paid days off, employee stock program, foundation donation matching, and much more!
Similar remote jobs
Nityo Infotech Corporation
Posted1 day ago
Updated1 hour ago
GE Vernova
Boston, MA
Posted1 day ago
Updated1 hour ago
Similar jobs in Westbrook, ME
IDEXX Laboratories, Inc
Westbrook, ME
Posted1 day ago
Updated1 hour ago
MaineHealth
Westbrook, ME
Posted1 day ago
Updated1 hour ago
USC1 IDEXX Laboratories, Inc.
Westbrook, ME
Posted2 days ago
Updated1 hour ago
Similar jobs in Maine
BrightSpring Health Services
Bangor, ME
Posted1 day ago
Updated1 hour ago