Principal Infrastructure & Cloud Architect
$140,000–$200,000 year
On-siteLibertyville, Illinois, United States
Job Summary
Define hybrid infrastructure and cloud architecture strategy, establishing target-state designs, reference architectures, and engineering guardrails for global on-premises and Azure environments. Lead architecture reviews, document decision records, and set standards for networking, identity, compute, storage, and security across data centers and WANs. Partner with Enterprise Architecture, Cybersecurity, and product teams to modernize platforms, optimize costs, and ensure resilience through disaster recovery planning and observability standards. Establish infrastructure-as-code automation frameworks and FinOps practices to drive cost efficiency and operational reliability in a 24x7x365 setting.
Required Qualifications
- Bachelor's Degree
- 12-15 years of related experience
- Minimum 12 years of progressive IT infrastructure experience
- 8+ years architecting and operating enterprise hybrid infrastructure and cloud platforms in a 24x7 environment
- Minimum 5 years in an architecture role (principal, lead, solutions, or enterprise architect)
- Owning reference architectures, standards, and governance across multiple domains, including network, identity, compute, storage, and security
- Travel via plane or automobile as required (typically 10% or less)
- Fluency in English
- Principal-level architecture leadership with responsibility for standards, reference architectures, design reviews, and architecture decision records (ADRs)
- Deep expertise in Microsoft Azure foundations and governance (CAF-aligned landing zones)
- Strong hybrid infrastructure expertise across Windows and/or Linux, virtualization, storage, backup, certificates, and data center operations
- Network architecture expertise spanning routing and switching, segmentation, IP addressing, DNS/DHCP, load balancing, high availability, troubleshooting, and performance management
- Cloud networking expertise, including hub-and-spoke and shared services architectures, ExpressRoute/VPN connectivity, firewall/NVA patterns, Private Link/private endpoints, and routing controls such as BGP and UDRs
- Experience with SD-WAN/SASE and remote access architectures, including secure segmentation, inspection, and identity-based access aligned with Zero Trust principles
- Strong security and compliance focus, including hardening standards, least privilege, vulnerability management, audit readiness, and secure-by-design architecture practices
- Experience with reliability engineering and ITIL-aligned operations, including SLAs/SLOs, observability, incident/problem/change management, root cause analysis, and continuous improvement
- Infrastructure-as-code and automation experience (e.g., Terraform, Bicep/ARM, PowerShell, Python, and configuration management tools)
- Cost and capacity management expertise (FinOps-aligned), including tagging standards, chargeback/showback concepts, rightsizing, lifecycle management, and balancing cost, reliability, and security
- Executive presence and stakeholder management skills, with the ability to communicate risks and trade-offs, align priorities across IT and business leadership, and drive outcomes without direct authority
Desired Qualifications
- Relevant certifications (e.g., Microsoft Azure, Microsoft 365, ITIL, VMware, networking, security)
- Advanced certifications such as AZ-305 (Azure Solutions Architect), AZ-500 (Security), and network/security certifications (e.g., CCNP/CCIE, JNCIP/JNCIE, PCNSE, Fortinet NSE)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.