Job Description
<p><b>Role: Cloud Architect </b></p> <p><b>Location: Des Moines, IA - Quarterly travel, but prefer CST or EST time zone</b></p> <p> </p> <p> </p> <p><b>Top 3 skills looking for:</b> </p> <ul> <li>Building Azure template and developer guardrails.
Delivered enterprise landing zones, network/identity baselines, and automated guardrails at scale.</li> <li>Combo of DevSecOps </li> <li>CI/CD</li> </ul> <p> </p> <p>Our client is designing and building a modern cloud platform template using Microsoft Azure to accelerate product delivery, reduce risk, and improve reliability.</p> <p>You'll lead architecture for Azure landing zones, core platforms, and reference patterns-enabling product teams to ship secure, resilient solutions at speed.</p> <p> </p> <p><b>The day to day will be:</b></p> <ul> <li>Strategy & Reference Architecture o Define and socialize Azure reference architectures aligned to CAF and Well-Architected Framework (networking, identity, data, app, SecOps).</li> <li>Translate business capabilities into cloud services & patterns (APIs, events, data, containers, serverless).</li> <li>Landing Zones & Governance o Design/iterate Enterprise-Scale Landing Zones (hierarchy, subscriptions, policy, RBAC, PIM, tagging, budgets).</li> <li>Implement policy-as-code (Azure Policy), guardrails, blueprints, and automated compliance baselines (HIPAA/HITRUST/SOC2 as relevant).</li> <li>Platform Engineering & DevSecOps</li> <li>Partner with Platform/Engineering to deliver golden paths and reusable modules (Terraform/Bicep, GitHub Actions/Azure DevOps).</li> <li>Enable multi-stage CI/CD, secrets via Key Vault, artifacts via ACR, and environment promotion with approvals.</li> <li>Application & Integration Architecture</li> <li>Guide product teams on AKS, App Service, Functions, Logic Apps, APIM, Event Grid/Event Hubs/Service Bus, Front Door/App Gateway/WAF.</li> <li>Establish API/event standards, versioning, and schema governance; promote event-driven and zero-trust patterns.</li> <li>Data & Analytics</li> <li>Advise on Databricks, Synapse/Microsoft Fabric, Data Factory, Purview (catalog/lineage), Cosmos DB, SQL MI, and secure data zones.</li> <li>Security, Resiliency & Observability</li> <li>Embed Defender for Cloud, Sentinel, Conditional Access, private endpoints/Private Link, and network isolation patterns.</li> <li>Design for HA/DR (Availability Zones, paired regions, ASR/Backup, RTO/RPO); mature Azure Monitor/Log Analytics/App Insights dashboards and SLOs.</li> <li>FinOps & Performance</li> <li>Implement tagging/chargeback, rightsizing, reservation planning, autoscale & performance testing; drive unit economics and cost KPIs.</li> <li>SAFe Enablement & Coaching</li> <li>Provide runway views before PI Planning; decompose enabler epics/features; mentor architects/engineers; run architecture clinics/guilds.</li> </ul> <p> </p> <p><b>What you've done</b></p> <ul> <li>10+ years in architecture/engineering with 6+ years hands-on Azure in large enterprises.</li> <li>Delivered enterprise landing zones, network/identity baselines, and automated guardrails at scale.</li> <li>Production experience with AKS (or App Service), APIM, Functions/Logic Apps, Event Grid/Hubs/Service Bus, Key Vault, Front Door/App Gateway/WAF, Cosmos/SQL, Storage, private networking.</li> <li>Built secure CI/CD with Terraform/Bicep, GitHub Actions or Azure DevOps, and policy gates; strong IaC code review discipline.</li> <li>Proven security & compliance grounding (Zero Trust, MFA/PIM/CAP, Defender, Sentinel; HIPAA/HITRUST/SOC2/PCI as applicable).</li> <li>Designed for resiliency (zones/regions), performance, and cost; fluent with WAF pillars.</li> <li>Comfortable operating in SAFe and a product operating model; coaching teams and influencing execs.</li> <li>Enterprise landing zones live with automated guardrails; 90% resource deployments via IaC.</li> <li>Reference architectures & golden paths adopted by 70% of product teams.</li> <li>Mean time to first deploy on new products down 30%; critical incidents tied to cloud misconfigurations reduced 50%.</li> <li>Cost per tenant/workload visibility with monthly variance 10% vs budget; top 5 cost drivers optimized.</li> </ul> <p><b>Responsibilities (day to day)</b></p> <ul> <li>Microsoft certifications (e.g., AZ-305, AZ-400, AZ-500, DP-203, SC-100).</li> <li>Containers/mesh (e.g., AKS, Dapr, service mesh), API design at scale, event modeling.</li> <li>Regulated industry experience (healthcare/finance).</li> <li>Observability expertise (OpenTelemetry, SLO error budgets).</li> <li>BizzDesign experience.</li> <li>Author ADRs and solution blueprints; run design reviews and threat modeling.</li> <li>Pair with engineers to codify patterns as reusable modules/templates.</li> <li>Create executive and engineering views (runway, dependencies, risks, trade-offs).</li> <li>Partner with Security/Networking/Data to standardize interfaces and controls.</li> <li>Track and report platform KPIs (reliability, performance, cost, risk).</li> </ul>