Cloud Architect
Location: Remote
Mandatory: "Fiserv DNA", AKS, Azure
Own the end-to-end architecture for CLIENT Azure-based digital banking platform — spanning solution, cloud platform, integration, and security architecture. Translate business outcomes into a secure, scalable, integration-ready, production-grade platform, and act as the single technical authority (architecture gate owner) from design through production readiness and operational transition.
Boundary: partners with the Front End Architect, who owns the client tier (React Native/web app architecture, component library, design system). The Solution Architect holds final authority on platform, backend/microservices, integration, cloud, and security decisions, and owns the BFF contract.
KEY RESPONSIBILITIES
1. End-to-end architecture ownership
· Own conceptual, logical, and physical architecture across application, platform, integration, and infrastructure layers.
· Author architecture decisions, reference architectures, and guardrails (ADRs); chair architecture/design reviews and the architecture sign-off gate.
· Ensure alignment with CLIENT enterprise architecture and the Azure Well-Architected Framework.
2. Solution & integration architecture
· Define cloud-native, API-first, event-driven, microservices, and domain-driven patterns; own the Backend-for-Frontend (BFF) contract for mobile and web channels.
· Lead integration architecture across Fiserv DNA core banking, MuleSoft APIs, and near-real-time core data sync (CDC) via Oracle GoldenGate over ExpressRoute.
· Define resiliency, observability, and scalability patterns across the application landscape.
3. Cloud platform architecture (Azure)
· Design and govern AKS, API Management, Azure Functions/Durable Functions, Service Bus, Event Grid, Azure SQL/Storage, Azure Monitor & Application Insights.
· Define hub-and-spoke networking, ExpressRoute, private endpoints, DNS, and secure connectivity.
· Establish environment strategy (Dev/QA/UAT/Prod) and deployment topologies.
4. Security, compliance & resiliency
· Define security architecture with identity/security teams: Microsoft Entra External ID (CIAM), OAuth 2.0, OIDC, JWT; Zero Trust, encryption, secrets management, and Key Vault integration.
· Own PCI-DSS scope definition, cardholder-data trust boundaries (CDE), tokenization strategy, and QSA coordination.
· Design HA/DR, failover, and operational-readiness (monitoring, logging, alerting).
5. DevSecOps & delivery enablement
· Define CI/CD and infrastructure-as-code (ARM/Bicep, Azure DevOps) direction; guide deployment/release strategy and production readiness.
6. Technical leadership & stakeholder collaboration
· Provide direction to engineering, QA, DevSecOps, and integration teams; resolve cross-team dependencies.
· Present architecture, trade-offs, and recommendations to leadership; collaborate with CLIENT and vendors (Fiserv, MuleSoft) through delivery and hypercare/handover.
7. AI-enabled engineering
· Direct enterprise-approved AI tools across the SDLC with human review, secure prompt/data handling, traceability, and governance; define AI guardrails and adoption practices and own architecture-level review of AI-generated design/code.
REQUIRED QUALIFICATIONS
· 15+ years in software engineering, incl. 5+ years in solution and/or cloud architecture.
· Bachelor''s in Computer Science / Engineering / Information Systems, or equivalent experience.
· Proven end-to-end delivery (architecture → production) in Agile, cross-functional, distributed teams.
REQUIRED TECHNICAL SKILLS
· Azure: AKS, API Management, Functions/Durable Functions, Service Bus, Event Grid, Azure SQL, Storage, Monitor, Application Insights.
· Architecture: cloud-native, microservices, API-first, event-driven, domain-driven design, BFF, enterprise integration patterns.
· Security & identity: Microsoft Entra External ID, OAuth 2.0/OIDC/JWT, Zero Trust, secrets management, encryption.
· Platform engineering: ARM/Bicep, Azure DevOps/CI-CD, architecture governance (ADRs, reviews).
· Networking: VNets, ExpressRoute, private endpoints, DNS, secure connectivity.
Fiserv DNA
PREFERRED EXPERIENCE
· Digital banking / credit union / regulated financial-services domain.
· Fiserv DNA, MuleSoft, Oracle GoldenGate; Thales CipherTrust (CTVL) and/or Akeyless (secrets).
· PCI-DSS-compliant Azure platforms; Azure AI Foundry / Azure OpenAI / AI Search.
· Microsoft Certified: Azure Solutions Architect Expert.
SUCCESS PROFILE
· Takes full ownership from concept to production; balances speed with security, quality, and compliance.
· Strong communicator across technical and executive audiences; drives clarity across complex multi-system landscapes; enables teams with reusable patterns and guardrails.