Point your AI agent at freehire and let it find you a job.

Get the CLI →

Heirs Technologies

NewBe an early applicant

Senior Cloud Architect

Posted Updated
Discussion

About Heirs Technologies

Heirs Technologies is the technology subsidiary of Heirs Holdings, Africa's leading investment holding company. We build world-class digital products and platforms that serve millions of Africans across the continent and diaspora.

About the Engagement

We are building a next-generation digital banking platform for one of Africa's largest financial institutions — a product built to serve 15 million users at launch, scaling to hundreds of millions across the continent and diaspora. This is a once-in-a-generation opportunity to design cloud infrastructure that will define how Africa transacts, saves, and grows.

The Role

The Senior Cloud Architect is the strategic owner of the platform's cloud infrastructure design — the person who decides how compute, networking, storage, and managed services are structured, connected, and governed across a dual-cloud environment at continental scale. Working under the Enterprise Architect and providing technical leadership to the Cloud Engineers, you will define the cloud architecture patterns, standards, and reference designs that the entire platform is built on. Where the Cloud Engineers own the build and operation, you own the blueprint — and on a platform serving millions of Africans, that blueprint must be resilient, secure, and built to last.

What You'll Do

Cloud Architecture & Strategy — Define and own the platform's dual-cloud architecture strategy across AWS and Azure — setting the structural principles, service selection standards, and governance frameworks that govern how the platform is built, deployed, and operated across both cloud environments. Ensure the architecture is designed to scale from 15 million to hundreds of millions of users without requiring fundamental rework, and that no single cloud provider represents a single point of failure for the platform.

Multi-Cloud & Active-Active Design — Own the architectural design of the platform's multi-cloud strategy — defining how AWS and Azure environments are structured to operate in active-active or active-passive configuration, how traffic is distributed between them, and how failover is triggered and executed seamlessly. Design the global traffic management architecture — including AWS Route 53 / Global Accelerator and Azure Traffic Manager / Front Door — and specify the cross-cloud connectivity, routing, and health-check standards that make seamless failover possible.

Reference Architecture & Standards — Produce and maintain clear, well-documented reference architectures for all major cloud infrastructure patterns on the platform — including compute, networking, storage, managed services, containerisation, and serverless. Define architectural decision records (ADRs) for all significant technology choices. Ensure every engineering team has the architectural clarity they need to build correctly and consistently, without reinventing patterns that have already been solved.

Network Architecture Design — Define the platform's high-level network architecture across both cloud environments — including VNet topology, subnet design principles, private connectivity patterns, zero-trust enforcement boundaries, hybrid connectivity design (AWS Direct Connect, Azure ExpressRoute, IPSec VPN Gateways), and on-premises integration architecture. Provide the Network & Security Engineers with a clear, well-reasoned network design to implement.

Security Architecture — Define the platform's cloud security architecture — specifying IAM patterns, encryption standards (AES-256 at rest, TLS 1.2+ in transit), secrets management architecture, zero-trust enforcement points, and the security controls that must be embedded in every cloud service provisioned on the platform. Work closely with the Platform Manager (Security) to ensure the cloud architecture is designed to meet PCI DSS, CBN, and applicable data protection requirements from the ground up.

Container & Serverless Architecture — Define the platform's container and serverless architecture — specifying the Kubernetes platform design (AKS, EKS), namespace and cluster topology, workload placement standards, and the use of serverless container platforms (Azure Container Apps, AWS App Runner / ECS Fargate) and serverless compute (Azure Functions, AWS Lambda) for appropriate workloads. Ensure the container architecture supports zero-downtime deployments, auto-scaling, and full observability.

Technology Governance & Service Catalogue — Own the platform's approved cloud service catalogue — defining which AWS and Azure services are approved for use, under what conditions, and with what configuration standards. Evaluate new managed services and cloud capabilities against the platform's requirements and make principled, well-documented technology decisions that balance capability, operational complexity, vendor risk, and long-term cost.

FinOps & Cost Architecture — Design the platform's cloud infrastructure for cost efficiency from the ground up — specifying auto-scaling boundaries, right-sizing standards, reserved capacity strategies, and architectural patterns that avoid waste at scale. Work with the Platform Manager on cloud cost governance and ensure that cost efficiency is a first-class architectural concern, not an afterthought.

Observability Architecture — Define the platform's observability architecture — specifying the standards and tooling for centralised logging, metrics collection, distributed tracing, and alerting across both cloud environments. Ensure the observability stack provides complete visibility into every layer of the infrastructure, and that architectural decisions do not create blind spots in production.

Technical Leadership & Architecture Review — Provide technical leadership and architectural guidance to the Cloud Engineers — reviewing their implementation approaches against architectural intent, identifying deviations early, and ensuring the build remains true to the design. Participate actively in the platform's architecture review process alongside the Enterprise Architect and Database Architect, assessing proposed changes and new service designs for architectural compliance, risk, and long-term impact.

What We're Looking For

Must Have

8+ years of cloud infrastructure experience, with at least 3 years in a cloud architecture role — designing and governing production cloud environments at significant scale.

Deep expertise across both AWS and Azure — not just familiarity, but hands-on architectural knowledge of compute, networking, storage, managed databases, messaging, and security services on both platforms.

Demonstrated experience designing multi-cloud or multi-region architectures — including active-active or active-passive configurations, global traffic management, and cross-cloud failover design.

Strong cloud security architecture knowledge — zero-trust design, IAM patterns, encryption architecture, secrets management, and security controls embedded in infrastructure design.

Expert-level knowledge of cloud networking architecture — VNet and VPC design, private connectivity patterns, hybrid connectivity (Direct Connect, ExpressRoute), and zero-trust network segmentation.

Proven ability to produce clear, well-structured architectural documentation — reference architectures, ADRs, infrastructure diagrams, and standards that engineering teams can build confidently from.

AWS Certified Solutions Architect – Professional (SAP-C02) — required.

Microsoft Certified: Azure Solutions Architect Expert (AZ-305) — required.

Nice to Have

Experience designing container platform architecture at scale — Kubernetes cluster topology, multi-tenancy patterns, workload placement, and serverless container platforms.

FinOps practitioner experience — cloud cost architecture, reserved capacity strategy, and engineering-level cost optimisation.

Experience in fintech, banking, or a regulated cloud environment — with working knowledge of PCI DSS cloud architecture requirements or CBN guidelines.

Familiarity with service mesh architecture (Istio or equivalent) and east-west traffic security patterns in microservices environments.

Experience with Infrastructure as Code at the architectural level — reviewing and governing Terraform, Ansible, and Bash-based provisioning standards across a large engineering organisation.

Compensation

Competitive and commensurate with experience. Details will be shared with shortlisted candidates.

What We Offer

Impactful work — you'll design the cloud architecture of a platform built to serve hundreds of millions of Africans.

World-class team — you'll work alongside architects, engineers, and security specialists from some of the best organisations on the continent and globally.

Modern ways of working — architecture-led, cloud-native, and built on a dual-cloud (AWS + Azure) foundation.

Lagos, Nigeria — based at our Lagos office, at the heart of Africa's most dynamic technology ecosystem.

How to Apply

To apply, please use the link provided in the job posting. Applications are managed through our recruitment platform and reviewed on a rolling basis.

Skills

See also

Architecture jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available