Sr. Cloud Platform Architect
$137,800–$234,300 year
On-siteMilpitas, California, United States
Job Summary
Design and architect scalable, highly available, resilient, and secure cloud solutions leveraging IaaS and PaaS services across AWS, Azure, and Google Cloud Platform. Lead cloud migration initiatives including re-hosting, re-platforming, refactoring, and re-architecting legacy workloads with an emphasis on security posture improvement. Drive application and infrastructure modernization programs to improve scalability, performance, and operational efficiency. Partner with engineering and security teams to define cloud-native reference architectures, security guardrails, and modernization roadmaps. Optimize cloud infrastructure for performance, availability, reliability, and cost efficiency through FinOps and resource governance. Establish and manage cloud security architectures, including identity-first security, zero-trust networks, and container security. Implement Infrastructure as Code using Terraform and enforce DevSecOps CI/CD pipelines with automated compliance validation. Develop and present architecture diagrams, threat assessments, and executive-level roadmaps. Define cloud operating models aligned with industry standards and internal policies.
Required Qualifications
- Bachelor's level degree in Computer Science, Computer Engineering or related field
- Eight (8) years of related experience
- Seven (7) years of hands-on cloud architecture or engineering experience
- Ownership of secure production environments
- Proficiency in at least one major cloud platform such as Microsoft Azure, AWS, or GCP
- Strong cross-cloud security fundamentals
- In-depth understanding of cloud networking, cloud security, containers, Kubernetes, serverless technologies, and microservices
- Confirmed experience with cloud security controls, including IAM, encryption, key management, network security, and zero-trust principles
- Extensive knowledge of cloud governance, monitoring, observability, FinOps, and cost management
- Strong understanding of compliance and regulatory frameworks (e.g., NIST, ISO, SOC, CIS, PCI, or similar)
- Experience embedding security into architecture design, IaC, and CI/CD pipelines (DevSecOps)
- Exceptional communication, leadership, and customer-management skills
- Ability to influence engineering, security, and executive stakeholders
Desired Qualifications
- Experience with AWS
- Experience with Microsoft Azure
- Experience with Google Cloud Platform (GCP)
- Experience with IaaS and PaaS best practices
- Experience with secure by design architecture principles
- Experience with identity and access management
- Experience with networking
- Experience with cloud security architecture
- Experience with designing, implementing, securing, and governing cloud based solutions
- Experience with cloud-native reference architectures
- Experience with security guardrails
- Experience with modernization roadmaps
- Experience with security hardening
- Experience with cost efficiency
- Experience with cloud security observability
- Experience with logging, monitoring, alerting, and incident response integration
- Experience with evaluating emerging cloud and security technologies
- Experience with developing, documenting, and presenting architecture diagrams, security models, threat assessments, technical documentation, roadmaps, and executive-level presentations
- Experience with defining and operating cloud operating models, including security governance, FinOps, tagging standards, resource governance, and operational excellence frameworks
- Experience with re-hosting, re-platforming, refactoring, and re-architecting legacy and on-premises workloads
- Experience with risk reduction
- Experience with application and infrastructure modernization programs
- Experience with scalability, performance, security, and operational efficiency
- Experience with partner teams to define cloud-native reference architectures, security guardrails, and modernization roadmaps
- Experience with design and enforce identity-first security, including IAM strategies, least-privilege access controls, role-based access, identity federation, and secrets management
- Experience with design and implement secure cloud networking architectures, including VPN, Direct Connect, ExpressRoute, and Cloud Interconnect
- Experience with configure and enforce network segmentation, micro-segmentation, zero-trust architectures, and advanced network security controls
- Experience with secure containers, Kubernetes, serverless, and microservices environments, including image scanning, runtime protection, and policy enforcement
- Experience with Implement Infrastructure as Code (IaC) using Terraform, AWS CloudFormation, and Azure ARM/Bicep templates with built-in security, policy, and compliance controls
- Experience with Design and evolve DevSecOps CI/CD pipelines, integrating security scanning, policy enforcement, and automated compliance validation
- Experience with Define and implement cloud security observability, including logging, monitoring, alerting, and incident response integration
- Experience with Evaluate emerging cloud and security technologies, driving continuous improvement of platform security and resilience
- Experience with Develop, document, and present architecture diagrams, security models, threat assessments, technical documentation, roadmaps, and executive-level presentations
- Experience with Define and operate cloud operating models, including security governance, FinOps, tagging standards, resource governance, and operational excellence frameworks
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.