Job Title: AWS Cloud Architect / Technical Lead
Location: SFO Santa Clara, CA – 4 days in office
Role Summary
The AWS Cloud Architect / Technical Lead will provide architecture leadership for establishing a secure, governed, and enterprise-aligned AWS foundation for cloud workloads. The role will lead target-state architecture, migration readiness, security and infrastructure design, technical decision-making, and coordination across cloud, application, data, security, privacy, quality, and operations teams.
The architect will ensure that the AWS foundation, development-environment migration, infrastructure-as-code implementation, Databricks integration, and operational controls are delivered as one cohesive solution. The engagement includes migration of an existing development environment and creation of reusable patterns for future Test, Demo, Production, and additional environments.
Key Responsibilities
- Lead discovery and assessment of the existing development environment, including applications, infrastructure, dependencies, repositories, data stores, deployment processes, network requirements, and operational constraints.
- Define and maintain the target AWS architecture aligned with enterprise account structure, VPC, regional policies, networking, identity, security, encryption, logging, monitoring, tagging, and governance standards.
- Lead technical architecture workshops, decision forums, and architecture and security checkpoints with cloud, application, infrastructure, data, security, privacy, quality, and operations stakeholders.
- Develop the migration strategy and technical execution plan for moving the agreed development workload into the target AWS environment.
- Define reusable architecture patterns for future Test, Demo, Production, multi-account, and scale-out environments.
- Guide the design of Terraform or equivalent infrastructure-as-code modules, including account and VPC baselines, environment configuration, deployment controls, and rollback patterns.
- Establish architecture standards for GitHub repositories, branch strategy, pull-request controls, code scanning, peer review, security review, plan/apply approvals, and deployment evidence capture.
- Ensure integration between AWS infrastructure controls and Databricks workspace, cluster, identity, secrets, encryption, audit logging, lineage, and deployment-control requirements.
- Define IAM roles, least-privilege access, SSO/MFA alignment, KMS encryption, secrets management, private connectivity, and privileged-access patterns.
- Establish observability requirements covering CloudTrail, infrastructure and application logging, monitoring, alerting, operational dashboards, and incident-management integration.
- Define backup, restore, disaster-recovery assumptions, availability requirements, operational support boundaries, and environment recoverability patterns.
- Lead migration-readiness reviews, architecture risk assessments, dependency management, technical issue resolution, and escalation of architecture decisions.
- Oversee development-environment migration, smoke testing, technical validation, rollback rehearsals, and evidence capture.
- Ensure that architecture and implementation decisions support sensitive-data, privacy, auditability, and regulated-workload readiness requirements.
- Support FinOps considerations, including tagging, cost allocation, utilization visibility, environment sizing, scalability assumptions, and AWS consumption transparency.
- Review technical deliverables produced by AWS, DevSecOps, Databricks, and data-engineering team members for architecture compliance and implementation quality.
- Prepare and maintain architecture diagrams, decision records, technical standards, risk assessments, operational runbooks, support RACI, migration documentation, and handover materials.
- Provide technical leadership during validation, operational-readiness reviews, project closure, and knowledge transfer.
Key Deliverables
- Current-state cloud and application-infrastructure assessment
- Target AWS architecture and foundation design
- Account, VPC, network, IAM, KMS, logging, monitoring, and security-control design
- Architecture diagrams and architecture decision records
- Development-environment migration strategy and execution plan
- Infrastructure-as-code architecture and reusable Terraform patterns
- GitHub and CI/CD deployment-control architecture
- Databricks-on-AWS integration and control design
- Security, privacy, auditability, and operational-readiness requirements
- Migration-readiness checklist and dependency assessment
- Smoke-test and rollback approach
- Architecture validation and evidence package
- Operational runbooks, support RACI, and handover documentation
- Recommendations for future Test, Demo, Production, multi-account, and scale-out environments
Required Qualifications
- Bachelor’s degree in Computer Science, Engineering, Information Technology, or a related discipline.
- 8+ years of experience in cloud architecture, infrastructure engineering, platform modernization, or application migration.
- 5+ years of hands-on experience designing and implementing enterprise solutions on AWS.
- Demonstrated experience designing AWS account, VPC, subnet, routing, security-group, load-balancing, DNS, private-connectivity, and hybrid-networking patterns.
- Strong knowledge of AWS services, including:
- Amazon EC2 and EKS
- Amazon VPC and Elastic Load Balancing
- Amazon RDS and Amazon S3
- AWS IAM, KMS, Secrets Manager, and Certificate Manager
- AWS CloudTrail, CloudWatch, Config, and GuardDuty
- Amazon Route 53
- AWS Lambda
- Strong experience with Terraform or comparable infrastructure-as-code technologies.
- Experience implementing GitHub-based source control, pull-request workflows, code scanning, deployment approvals, and CI/CD controls.
- Experience leading application or platform migrations into governed enterprise AWS environments.
- Strong understanding of cloud security, least-privilege access, encryption, secrets management, vulnerability management, audit logging, and evidence capture.
- Experience defining monitoring, alerting, backup, restore, resiliency, disaster-recovery, and operational-support patterns.
- Working knowledge of Databricks on AWS, including workspace architecture, identity integration, cluster policies, secrets, audit logs, lineage, and deployment models.
- Experience working with security, privacy, quality, compliance, and enterprise-architecture review functions.
- Strong architecture documentation, stakeholder communication, facilitation, decision-making, and technical leadership skills.
- Ability to lead globally distributed engineering teams and coordinate across multiple technical workstreams.
Preferred Qualifications
- AWS Certified Solutions Architect – Professional.
- AWS Certified Security – Specialty or AWS Certified Advanced Networking – Specialty.
- Experience with AWS Control Tower, Landing Zone Accelerator, AWS Well-Architected Framework, Migration Evaluator, Application Discovery Service, or AWS Migration Acceleration Program.
- Experience in healthcare, life sciences, medical devices, or other regulated industries.
- Familiarity with PHI, PII, HIPAA-aligned controls, data anonymization, privacy-by-design, GxP, or SaMD environments.
- Experience with Kubernetes, containerized platforms, OpenSearch, PostgreSQL, Redis, and cloud-native application architectures.
- Knowledge of FinOps, cloud cost optimization, tagging standards, utilization management, and capacity planning.
- Experience supporting architecture governance and operational handover within fixed-price project engagements.
Success Measures
- Target AWS architecture is reviewed and accepted by designated architecture, security, and platform stakeholders.
- AWS account, network, IAM, logging, monitoring, encryption, and operational-control requirements are fully documented.
- Reusable infrastructure-as-code and GitHub deployment patterns are established with appropriate review and approval gates.
- The agreed development environment is migrated and validated through successful smoke testing.
- Databricks controls are integrated with the AWS security and governance model.
- Architecture decisions, risks, dependencies, validation evidence, rollback procedures, and runbooks are complete and traceable.
- The organization receives a reusable architecture foundation for future Test, Demo, Production, and scale-out phases.