In my last three interviews this month, the brief was less “own the SIEM” and more “build secure AWS multi-account landing zones, codify policies in OPA/Rego, and enforce guardrails in Terraform pipelines.” Are others seeing Cloud Security Architect roles hired under Platform Engineering instead of Security, and has that shift changed scope or comp for you?
Seeing the same — ‘own the SIEM’ is out; it’s AWS multi-account landing zones, OPA/Rego, and Terraform guardrails, increasingly parked under Platform at the last two places I’ve worked. My comp bumped when mapped to Staff Platform Eng, but only after I locked in ownership of the policy repo + CI gate and an on-call stipend. If you’re close to offer, push for a security dotted line and a budget for shared modules — anyone landed a Principal title for a Cloud Sec Architect under Platform?
At my last shop, the Cloud Sec Architect role moved under Platform; comp shifted to the SRE ladder (about 8% bump) but , it came with on-call for the Terraform pipeline and owning the ‘OPA/Rego’ policy repo. If you’re being asked to ‘build secure AWS multi-account landing zones’, push to own the Control Tower/SCP stack and merge gates, and get on-call pay spelled out; this Cloud Security Governance - AWS Control Tower - AWS helped us frame scope. Did your interviews call out Control Tower vs DIY?