Jobs and Careers
ST

Security Architect (Cloud Security & Compliance)

Stanley Black & Decker
New Britain, United Statesfull_timeVerifiedPosted 14 Jan 2026

About the role

Security Architect (Cloud Security & Compliance) - Hybrid

New Britain, CT, United States

Towson, MD, United States

Come build something that matters.

It takes great people to achieve greatness. People with a sense of purpose and integrity. People with a relentless pursuit of excellence. People who care about making things better For Those Who Make The World™. Sound like you? Join our top-notch team of approximately 48,000 diverse and high-performing professionals globally who are making their mark on some of the world’s most beloved brands, including DEWALT®, BLACK+DECKER®, CRAFTSMAN®, STANLEY®, CUB CADET®, and HUSTLER®.

The Job:  

As a Security Architect (Cloud Security & Compliance), you’ll be part of our Information Technology team working as a hybrid employee.    You’ll get to:  

Cloud Security Architecture & Strategy:

  • Design, develop, and oversee the implementation of comprehensive security architectures for AWS cloud environments and connected products, ensuring confidentiality, integrity, and availability of systems and data.

Security Solution Design & Integration:

  • Architect and integrate AWS native security tools (e.g., GuardDuty, Security Hub, IAM, KMS, CloudTrail, Config) and external solutions (e.g., CSPM, Secure SDLC, SIEM) for holistic security coverage.

AST - Application security testing:

  • Knowledge and understanding of static analysis, software composition analysis, dynamic analysis, secret scanner etc.

Compliance & Certification:

  • Lead the security strategy for SOC2, NIST, ISO27001, and other regulatory certifications. Define and maintain documentation, evidence, and processes required for compliance readiness.

Governance, Risk, and Compliance (GRC):

  • Architect and oversee GRC processes, including risk assessments, policy development, control mapping, and remediation tracking for cloud environments.

Security Automation & Infrastructure:

  • Design and implement automated security controls and monitoring solutions using infrastructure-as-code (Terraform, CloudFormation), CI/CD pipelines, and scripting (Python, Shell).

Incident Response Strategy:

  • Develop and guide incident response plans, lead detection and investigation efforts, and coordinate with internal teams for timely resolution and root cause analysis.

Vulnerability Management Oversight:

  • Architect vulnerability management programs, including regular assessments, penetration testing, and remediation for cloud infrastructure and applications.

Security Awareness & Enablement:

  • Lead organization-wide security awareness initiatives, provide training, and foster a culture of security through strategic communication and enablement.

Documentation & Reporting:

  • Define and maintain security architecture documentation, controls, incident records, and compliance activities. Prepare executive-level reports for stakeholders and leadership.

The Person:  

You love to learn and grow and be acknowledged for your valuable contributions. You’re not intimidated by innovation. Wouldn’t it be great if you could do your job and do a world of good? In fact, you embrace it. You also have:

  • 10+ years of experience in security architecture, cloud security, or related roles. 
  • Proven track record designing and managing security architectures in AWS cloud environments. 
  • Experience leading organizations through SOC2, NIST, ISO27001, or similar compliance frameworks. 
  • Undergraduate degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field, or equivalent work experience in cloud security and architecture. 
  • Preferred certifications: AWS Certified Security – Specialty, Certified Information Systems Security Professional (CISSP), Certified Cloud Security Professional (CCSP). 

Core Technologies and Skills 

  • AWS Security Tools: 
    GuardDuty, Security Hub, IAM, KMS, CloudTrail, Config, Macie, Inspector. 
  • External Security Solutions: 
  • WIZ.io, Mend.io, SonarQube, Cortex, Akamai, Cognito, Balbix, Splunk, GitLeaks or similar 

  • GRC Platforms: 
    ServiceNow GRC, Archer, OneTrust, and related processes. 
  • Infrastructure as Code: 
    Terraform, CloudFormation for security automation and compliance. 
  • CI/CD Security: 
    Security integration in CI/CD pipelines (Bitbucket, Jenkins, GitHub Actions). 
  • Scripting: 
    Python and Shell for automation and securit

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Stanley Black & Decker

View company profile →