Expert Cloud Architect
Location: Oakland, CA
Duration: 12+ months
Remote Role
We are seeking an Expert Cloud Architect to lead the architecture, design, and automation of our enterprise cloud platform and security integration frameworks. In this role, you will bridge cloud platform engineering with advanced automation architecting landing zones, designing Infrastructure-as-Code (IaC) module libraries, and integrating intelligent agentic workflows that orchestrate data from enterprise platforms like Tenable, Infoblox, and firewall management systems.
This is a hands-on technical role for a builder who can author enterprise Terraform at scale, design resilient multi-stage CI/CD pipelines, and design automated security attack path mapping and compensating control frameworks.
Key Responsibilities
1. Platform Architecture & Infrastructure-as-Code
- Landing Zone Evolution: Own and evolve enterprise landing zone architectures, network segmentation, and identity federation in AWS or Azure.
- LLM & Bedrock
- Build agent on Kubernetes and Bedrock
- Strong Python Programing
- Terraform Module Engineering: Author, version, and maintain reusable enterprise Terraform module libraries, setting strict security defaults and modular design principles.
- Pipeline Architectures: Build multi-stage CI/CD pipeline architectures in Azure DevOps or GitHub Actions, incorporating policy-as-code enforcement, drift detection, and automated validation.
- Hybrid Networking: Design secure enterprise network topologies, including transit networks, private endpoints, DNS resolution frameworks, and micro-segmentation.
2. Security Automation & Agentic Workflow Design
- Vulnerability & Topology Integration: Architect automated workflows and agentic integrations that connect directly to security tooling (e.g., Tenable) to extract vulnerability data.
- Network & Firewall Intelligence: Leverage network topology data (e.g., Infoblox) and active firewall rule sets to model potential attack vectors and exposure paths across hosted workloads.
- Compensating Controls & Remediation: Implement automated governance and architecture frameworks to identify required compensating controls (e.g., preventing data exfiltration or lateral movement).
- Policy-as-Code Enforcement: Embed security standards into deployment pipelines using tools such as Azure Policy, AWS SCPs, OPA/Rego, or Sentinel.
3. Escalation & Technical Leadership
- Technical Unblocking: Serve as the top-tier escalation point for Senior Cloud Engineers, resolving complex county migration, provider upgrades, and cross-account orchestration issues.
- Architecture Decision Records (ADRs): Document and enforce binding technical patterns, non-functional requirements, and architectural standards across engineering squads.
Required Qualifications
- Experience: 8+ years of hands-on experience in cloud infrastructure, systems engineering, or cloud platform architecture.
- Cloud Platform: Deep expertise in AWS (preferred) or Azure (single-cloud depth in either environment is acceptable).
- Infrastructure-as-Code: 5+ years of hands-on experience writing Terraform at scale (enterprise module libraries, multi-environment county management, and custom provider/module development).
- CI/CD Automation: 4+ years designing CI/CD pipelines using Azure DevOps, GitHub Actions, or equivalent frameworks.
- Security & Network Integration: Proven track record of integrating enterprise security/networking tools (e.g., Tenable API, Infoblox, Palo Alto/NVA firewalls) into automated cloud infrastructure workflows.
- Education: Bachelor s degree in Computer Science, Information Technology, or equivalent industry experience.
Metasys Technologies/NVISH is an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identify, national origin, veteran or disability status.
Preferred / Desirable Skills
- AWS Certified Solutions Architect Professional OR Azure Solutions Architect Expert.
- HashiCorp Certified: Terraform Associate.
- Familiarity with agentic AI integration concepts, API-driven security orchestrations, and automated threat/attack path modeling.
- Hands-on experience with container platforms (EKS / AKS) and GitOps workflows.
- Knowledge of zero-trust architecture, identity federation (SAML/OIDC), and secrets management.
Metasys Technologies/NVISH is an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identify, national origin, veteran or disability status.