Required Skills and Qualifications
Proven, hands-on experience architecting and operating enterprise cloud infrastructure across both Microsoft Azure and Amazon Web Services (AWS), including direct responsibility for provisioning and securing core infrastructure — not just consuming managed AI services on top of it.
Expertise
· Infrastructure as Code (hands-on): Terraform, AWS CloudFormation, and/or AWS CDK for AWS provisioning; Azure Resource Manager (ARM) templates and/or Bicep for Azure provisioning; Python (Boto3 for AWS, Azure SDK for Python for Azure) for automation, scripting, and operational tooling against cloud APIs — candidate should be able to write and maintain IaC and scripts directly, not just review them.
· Networking & isolation: VPC design (subnets, route tables, peering/transit gateway, NAT), Azure Virtual Network equivalents, and secure network segmentation for multi-tier applications
· Identity & access: IAM policy design (roles, least-privilege, resource policies), Amazon Cognito (user pools, identity pools, federated auth) and Azure AD/Entra ID equivalents, service-to-service authentication and authorization patterns
· Container orchestration: Kubernetes hands-on experience (EKS and AKS), including cluster setup, networking (CNI, ingress), scaling, and workload security
· API & edge layer: API Gateway (REST/HTTP APIs, authorizers, throttling), AWS Lambda, CloudFront (CDN configuration, caching strategies, origin security, WAF integration)
· Security : Security group and policy design, encryption at rest/in transit, secrets management, compliance controls (SOC2/HIPAA/etc. as applicable), and audit/logging setup
· Hybrid/on-prem integration: VPN Gateway setup (AWS Site-to-Site VPN, AWS VPN Gateway/Client VPN, Azure VPN Gateway) for dedicated connectivity, secure and reliable data flow between on-premises systems and Azure/AWS, hybrid identity federation a plus.
· Azure services such as App Services, API Management, Azure OpenAI, AI Search, Cognitive Services, and Azure SQL Database
· AWS services such as Bedrock, Lambda, API Gateway, ECS/EKS, S3, Textract, Comprehend, and supporting data services for AI workloads
· CI/CD and DevOps practices for multi-cloud delivery using Azure DevOps, GitHub Actions, or AWS-native tooling
· GenAI architecture: solid understanding of GenAI solution architecture and hands-on experience standing up the underlying infrastructure — LLM hosting/integration patterns, API/orchestration layers, scaling, monitoring, and cost/security controls
· Agentic & multi-agent architecture: ability to architect infrastructure supporting single- and multi-agent solutions — orchestration/coordination layers, agent-to-agent communication, state and memory management, tool/API integration points, scaling, and observability for agentic workflows.
· Highly desirable: understanding of data pipelines, retrieval-augmented generation (RAG) concepts (standard and agentic RAG patterns), and vector databases, including how they're provisioned and integrated within GenAI and multi-agent architectures
· Ability to evaluate and recommend the right services for a given workload based on cost, scalability, latency, and operational tradeoffs.
· Understanding of data governance, security, compliance, and model risk requirements for regulated or mission-critical workloads
· Oversee that all solutions are resilient, cost-efficient, observable, and compliant with organizational and industry standards for data privacy, security, model governance, and responsible AI.
· Strong communication and teamwork skills in agile, cross-functional environments
Preference
Java experience preferred.