Cloud Solutions Architect - AWS & Azure
Summary
Design and deploy secure, scalable multi-cloud solutions across AWS, Azure, and GCP, including landing zones, migrations, and observability, while enforcing security, governance, and FinOps practices.
Role
Description:
· Design and architect scalable, secure cloud
solutions across Azure and AWS.
· Build and manage cloud landing zones (identity,
governance, networking, security).
· Lead cloud migration transformation initiatives,
including assessments, wave planning, modernization, and execution.
· Develop reference architectures, HLDLLD, and
cloud design patterns.
· Implement and optimize cloud infrastructure
compute, storage, networking, load balancing, monitoring.
· Deploy and manage PaaS services (AKSEKS, App
Services, Functions, Lambda, managed databases).
· Define and enforce cloud security, IAMRBAC,
encryption, and governance frameworks.
· Architect hybrid connectivity (VNet, VPC, VPN,
ExpressRoute Direct Connect).
· Drive automation using Terraform, BicepARM,
CloudFormation, and CI/CD pipelines.
· Collaborate with DevOps, Security, and
Application teams provide technical leadership.
Essential
Skills:
· More than 10 years in cloud architecture,
infrastructure, or platform engineering.
· Deep hands-on experience with Azure and AWS
services.
· Good experience in designing a multi-cloud
architecture spanning Azure, AWS, and GCP with unified governance and cost
management.
· Strong background in cloud migration,
modernization, and transformation programs. Relevant certifications (Azure, AWS
Architect, Terraform Associate).
· Experience with FinOps practices tagging
strategy, chargeback models, and multi-cloud cost analytics.
· Ability to design and deploy an Azure
Enterprise-Scale Landing Zone with Hub-Spoke / VWAN topology. proficient with
AKS private clusters, AAD integration, ingress, KEDA autoscaling, and GitOps.
· Knowledge of Azure Entra ID Conditional Access,
PIM, Managed Identities, and B2B/B2C federation.
· Ability to design multi-account AWS environments
with AWS Organizations, SCPs, and Transit Gateway networking. proficient with
AWS container/serverless workloads EKS, Fargate, Lambda, and event-driven patterns.
· Experience in designing a GCP Shared VPC, GKE
Autopilot environment with IAM hierarchy governance.
· Experience with GCP data/analytics services like
BigQuery, Dataflow, Pub/Sub, and Looker. ability to design OCI VCN
architectures with DRG, FastConnect, and compute fleet sizing. Experience with
OCI Autonomous DB, Exadata Cloud, and Oracle DB migrations. Experience with
design hybrid connectivity (ExpressRoute / Direct Connect / FastConnect) with
BGP and failover. SD-WAN and network virtualization experience (NSX-T, VXLAN,
overlay architectures).
· IAM/PAM design expertise for least-privilege,
CyberArk/BeyondTrust, and federated identity (SAML/OIDC).
· Experience with CSPM tools (Defender for Cloud,
Prisma Cloud, Wiz) and posture remediation.
· Ability to map cloud controls to compliance
frameworks (ISO 27001, SOC 2, PCI-DSS) for audit readiness.
· Terraform / Bicep / CDK proficiency module
design, remote state, policy gates, and cross-provider IaC.
· Experienced with building CI/CD pipelines with
GitHub Actions/Azure DevOps and GitOps (ArgoCD/Flux).
· Design a multi-cloud observability strategy
using Azure Monitor, Datadog. design and deploy Generative AI / LLM solutions
(Azure OpenAI, AWS Bedrock, Vertex AI Gemini) with RAG. MLOps maturity model
registry, feature stores, training pipelines, and inference endpoint
governance. experienced with Edge / IoT architectures (Azure IoT Edge, AWS
Greengrass, GCP Edge) and cloud-to-edge pipelines. Excellent communication,
requirement analysis, documentation, and presentation skills.
Desirable
Skills:
· Microsoft Azure
· Amazon Web Service (AWS) Cloud Computing
· Google Cloud
· EAS
· Oracle Cloud Infrastructure
· Multi-cloud Security - WIZ CNAPP
· Cloud Computing (General)