STEM OPT Cloud Security Architect Jobs
Cloud Security Architect roles sit squarely within STEM OPT eligibility, drawing on degrees in computer science, information security, and related fields. Your STEM OPT extension adds 24 months of work authorization beyond your initial OPT period, but your employer must be enrolled in E-Verify before you can start.
See All Cloud Security Architect JobsOverview
Showing 5 of 7+ Cloud Security Architect jobs


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?
See all Cloud Security Architect jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Cloud Security Architect roles.
Get Access To All Jobs
Job Description
What We Do
At Goldman Sachs, our Engineers don’t just make things – we make things possible. Change the world by connecting people and capital with ideas. Solve the most challenging and pressing engineering problems for our clients. Join our engineering teams that build massively scalable software and systems, architect low latency infrastructure solutions, proactively guard against cyber threats, and leverage machine learning alongside financial engineering to continuously turn data into action. Create new businesses, transform finance, and explore a world of opportunity at the speed of markets. Goldman Sachs Engineers are innovators and problem-solvers, building solutions in Artificial Intelligence, risk management, big data, mobile and more.
Cloud Platform
As part of Core Engineering at Goldman Sachs, the Cloud Platform team is responsible for enabling the use of public cloud services across the firm. You will be working as part of a multi-disciplinary team responsible for researching, architecting and building a cutting-edge platform that enables Goldman Sachs teams to deploy and manage services in public cloud safely and securely. We are at an early stage of modernizing our services around cloud native principles, and you will be directly contributing to a platform that programmatically enforces safety, security and compliance of services and enables engineers to innovate faster. The organization is seeking highly collaborative, creative, and intellectually curious engineers who are passionate about developing and implementing cutting-edge cloud computing solutions. The ideal candidate will thrive in a DevOps culture and contribute to customer-centric product development. They will work closely with cross-functional teams, and will be creative collaborators who evolve, adapt to change and thrive in a fast-paced global environment.
Key Responsibilities
Cloud Security Platform Implementation:
- Design, implement, and maintain secure cloud architecture aligned with NIST frameworks and industry-recognized cloud security standards, ensuring compliance, resilience, and least-privilege access across cloud environments
- Build and deploy cloud security posture management infrastructure using Infrastructure as Code (Terraform/CDK)
- Implement integrations with enterprise services including risk management systems, monitoring platforms, SIEM, and compliance frameworks
- Deploy and maintain security policies, automated compliance validation, and remediation workflows
Policy-as-Code & Automation:
- Demonstrates thought leadership: Guides and upskills other engineers and clients in cloud best practices; demonstrates expertise with automation and infrastructure as code (IaC)
- Migrate infrastructure security controls to policy-as-code frameworks with automated testing and validation
- Integrate security controls into CI/CD pipelines for shift-left security and pre-deployment validation
- Optimize security policies during migration for improved coverage and reduced false positives
- Implement policy versioning, change management workflows, and automated deployment pipelines
Secure Infrastructure & SDLC:
- Understanding of AWS
- Support secure-by-default infrastructure initiatives for standardized cloud account provisioning
- Integrate security controls into Software Development Lifecycle (SDLC) with automated gates and validation
- Implement security baselines and automated compliance checks for new cloud accounts and services
- Provide self-service security scanning and remediation tools for development teams
DevOps & Platform Engineering:
- Past enterprise level experience in DevOps, Software, Infrastructure or Site Reliability Engineering (2-4 years)
- Proficient in infrastructure as code practices using technologies such as CDK, Terraform, AWS CloudFormation, and/or SaltStack
- Experience building CI/CD pipelines from scratch or integrating security controls into existing pipelines
- Hands-on experience developing and improving all phases of the software development/delivery lifecycle
- Strong grasp of container technology including container orchestration
Authentication & Access Management:
- Support implementation of cloud-native authentication and authorization frameworks for service flows
- Assist with service identity onboarding and certificate lifecycle management
- Execute migration procedures and validate authentication flows for cloud-native access patterns
- Troubleshoot authentication issues, performance bottlenecks, and integration challenges
- Provide technical support to application teams during authentication framework migrations
Observability & Operational Support:
- Proficient in one or more enterprise scale observability tools such as Splunk, Datadog, FluentD, ELK
- Experience maintaining and improving the reliability of applications and infrastructure
- Provide regional timezone coverage for cloud access and security platform operational issues
- Participate in 24/7 on-call rotation for security incidents and platform support
- Monitor platform health, respond to alerts, and escalate critical incidents as needed
- Implement monitoring, alerting, and automated remediation workflows
Collaboration & Documentation:
- Ability to document solutions, cloud architectural patterns, and best practices to ensure that clients have guidance as needed
- Proven ability to partner with cloud hyperscale partners to define and troubleshoot cloud architectures and service enablements
- Create runbooks for operational scenarios, troubleshooting guides, and training materials
- Collaborate with global team members for consistent implementation across regions
Software Development & Problem Solving:
- Solid understanding of Microservices and APIs
- Develop automation scripts for operational tasks, security workflows, and remediation processes
- Build dashboards and reporting mechanisms for security posture visibility
- Eager to problem solve and troubleshoot issues that may arise day to day
Basic Qualifications
- Minimum 2-4 years of relevant professional experience with at least 1+ years of familiarity with AWS services
- B.S. or higher in Computer Science (or equivalent work experience)
- Familiarity with disciplines of enterprise software development such as configuration and release management, source code and version controls along with operating considerations such as monitoring
- Experience performing and/or leading root cause analysis following incidents
- Experience in Security or Data engineering preferably in an SRE/DevOps environment
- Practiced in Java, Python, Javascript / Typescript / Node
- Strong written and verbal communication skills
- Ability to establish trusted partnerships with product leads and engineering stakeholders
- Comfort with agile operating model and DevOps culture
- Understanding of authentication protocols (OAuth 2.0, mTLS, certificate-based authentication)
- Familiarity with cloud security standards (CIS Benchmarks, NIST frameworks) and compliance requirements
Salary Range
The expected base salary for this Seattle, Washington, United States-based position is $115000-$180000. In addition, you may be eligible for a discretionary bonus if you are an active employee as of fiscal year-end.
Benefits
Goldman Sachs is committed to providing our people with valuable and competitive benefits and wellness offerings, as it is a core part of providing a strong overall employee experience. A summary of these offerings, which are generally available to active, non-temporary, full-time and part-time US employees who work at least 20 hours per week, can be found here.
See all Cloud Security Architect jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Cloud Security Architect roles.
Get Access To All JobsTips for Finding STEM OPT Authorization in Cloud Security Architect
Verify your CIP code matches security
Cloud Security Architect roles typically require a degree in computer science, cybersecurity, or information systems. Check your diploma's CIP code against the DHS STEM Designated Degree Program List to confirm your degree qualifies before applying.
Confirm E-Verify enrollment before accepting offers
Your employer must be enrolled in E-Verify to legally employ you on STEM OPT. Ask recruiters directly whether the hiring entity, not just the parent company, is enrolled, since subsidiaries and staffing agencies have separate accounts.
Build a cloud security credential stack early
Employers filing STEM OPT training plans for architect-level roles expect hands-on cloud platform experience. Earning credentials like AWS Security Specialty or Google Professional Cloud Security Engineer before your job search strengthens your I-983 learning objectives significantly.
Target employers with active H-1B filing history
Use Migrate Mate to filter Cloud Security Architect roles by employers who have filed H-1B LCAs, giving you visibility into which companies routinely sponsor immigration beyond the OPT window and are already familiar with the compliance requirements.
Negotiate your I-983 training plan scope carefully
Your I-983 must list specific learning objectives tied to your architecture role. Push to include cloud security framework implementation, zero-trust design projects, and compliance audits so your training plan reflects real work and survives SEVP scrutiny.
Time your H-1B registration around your OPT end date
STEM OPT extensions last 24 months, but H-1B cap-gap protection only applies if USCIS receives a timely filed petition before your authorization expires. Map your OPT end date against the April 1 H-1B filing window to identify whether a gap exists.
Cloud Security Architect jobs are hiring across the US. Find yours.
Find Cloud Security Architect JobsFrequently Asked Questions
Does a Cloud Security Architect role qualify for the STEM OPT extension?
Yes, provided your degree is on the DHS STEM Designated Degree Program List. Cloud Security Architect positions are classified under computer and information systems occupations in O*NET, and degrees in computer science, cybersecurity, information assurance, or related engineering fields typically carry qualifying CIP codes. Confirm your specific CIP code with your DSO before filing the extension.
What must my employer do to hire me on STEM OPT as a Cloud Security Architect?
Your employer must be enrolled in E-Verify before your STEM OPT employment begins. They must also sign your Form I-983 training plan, which requires documenting specific learning objectives tied to your Cloud Security Architect duties, confirming you'll be paid and supervised like a regular employee, and committing to report material changes in your role to your DSO.
What should my I-983 training plan include for a Cloud Security Architect position?
Your I-983 should detail learning objectives directly tied to your role, such as designing cloud security architectures, implementing identity and access management frameworks, conducting threat modeling, and achieving compliance with standards like NIST or FedRAMP. Generic objectives like 'gain experience in IT' won't hold up. Your employer's supervisor signs the plan and is responsible for its accuracy.
How do I find Cloud Security Architect employers who support STEM OPT and sponsor visas long-term?
Migrate Mate surfaces Cloud Security Architect roles filtered for employers with active E-Verify enrollment and H-1B Labor Condition Application filing history, so you can prioritize companies that have already navigated immigration compliance. This matters because STEM OPT is a bridge, not a permanent solution, and your employer's H-1B track record signals whether they'll support your next status change.
Does cap-gap protection apply if my STEM OPT expires before my H-1B start date?
Cap-gap protection extends your OPT work authorization through September 30 of the H-1B fiscal year if USCIS receives a properly filed, timely H-1B petition before your STEM OPT expires. You must remain in valid F-1 status, and your employer must continue your E-Verify-compliant employment without interruption. USCIS issues an updated I-20 reflecting the cap-gap period through your DSO.
See which Cloud Security Architect employers are hiring and sponsoring visas right now.
Search Cloud Security Architect Jobs