Senior Cloud Architect (all genders)
Role details
Job location
Tech stack
Job description
Lam is seeking a Senior Cloud Architect to lead our evolution of AWS and Azure into true internal developer platforms-secure, reliable, and frictionless foundations that enable product teams to ship customer value rapidly and safely. You will be the company's subject matter expert for all things cloud, owning the strategy, architecture, and hands-on delivery of platform capabilities, while designing, developing, and supporting endto-end automation across the stack. You will drive advanced prototyping of new cloud services and capabilities, validating business value quickly, and will rapidly accelerate our technical maturity in Infrastructure as Code (Terraform and Ansible), cloud platform governance, and developer experience. This is a high-impact, hands-on leadership role that blends architecture, platform engineering, DevEx, and SRE practices to create paved roads ("golden paths") that scale across Lam.
What you'll do
Platform Architecture & Strategy
- Own the cloud platform reference architecture and roadmaps across AWS and Azure; align with enterprise architecture, security, data, and app teams.
- Define and maintain golden paths (IaC modules, pipeline templates, reference stacks) for common workloads (containers, serverless, data, analytics, batch).
- Establish multi-cloud landing zones (AWS Organizations + Control Tower; Azure Management Groups + Landing Zones) with policy, identity, and network guardrails.
Developer Platform & Experience
- Build an internal developer platform (IDP) that abstracts complexity and provides self-service: project scaffolding, environment creation, CI/CD, observability, and secrets management.
- Curate platform catalogs/registries (Terraform module registry, container base images, reusable pipeline templates).
- Partner with product/engineering teams to eliminate friction and adopt platform standards; champion platform SLAs/SLOs and intake processes.
IaC & Automation (Terraform + Ansible)
- Lead standardization of Terraform (workspaces, state mgmt, backends, code structure, version pinning, testing with Terratest/checkov, policy-as-code).
- Lead Ansible usage patterns for configuration mgmt, immutable infra patterns where appropriate, and orchestration of provisioning-to-config.
- Drive pipeline-native IaC (GitOps principles, PR-based workflows, security scans, unit/integration tests, drift detection, and change approvals).
Security, Governance, and Compliance
- Design identity-first architectures (Azure AD/Microsoft Entra ID, AWS IAM), role-based access models, and secrets management (Key Vault, AWS Secrets Manager).
- Implement and enforce policy-as-code (Azure Policy, OPA, Conftest) and continuous compliance.
- Build secure-by-default blueprints: network segmentation, private endpoints, encryption, vulnerability mgmt, and SBOM/SLSA practices.
SRE, Observability, and Operations
- Embed SRE practices: SLOs, error budgets, incident response, postmortems, chaos/gamedays.
- Standardize observability: logs, metrics, traces, dashboards, and alerts (e.g., Azure Monitor, CloudWatch, OpenTelemetry, Grafana).
- Establish runbooks and playbooks for common events; integrate with ChatOps/ITSM.
Prototyping & Technical R&D
- Run rapid prototypes/PoCs for new capabilities (e.g., Landing Zone Accelerator enhancements, data mesh patterns, EKS/AKS platforms, serverless/event-driven).
- Produce reference implementations with documentation, guardrails, and adoption guides; define measurable value and rollout plans.
FinOps & Cost Optimization
- Partner with Finance and engineering for showback/chargeback, budgets, and anomaly detection.
- Provide patterns and tooling for cost-aware architectures (rightsizing, autoscaling, scheduling, storage lifecycle policies
Coaching & Influence
- Mentor senior engineers and architects; lead communities of practice.
- Define standards, guidelines, and review processes (architecture review board, design reviews, threat modeling).
- Evangelize platform capabilities and best practices through demos, docs, and training., This position will be occupied in Villach. It is subject to the Austrian Collective Bargaining Agreement for Employees in the Metal Technology Industry in occupation group G. A higher payment is negotiable depending on expertise and skills. The monthly salary is paid 14 times per year. Please follow the link on the below section "Employment in Austria" for further information.
Requirements
- 12+ years in cloud/platform architecture or SRE/DevOps leadership roles; 5+ years hands-on with both AWS and Azure in enterprise settings.
- Expert in Terraform (modules, registries, testing, state mgmt) and Ansible (roles, collections, CI integration).
- Deep knowledge of AWS (e.g., Organizations/Control Tower, VPC, IAM, ECS/EKS, Lambda, RDS, S3, CloudWatch) and Azure (Management Groups/Landing Zones, VNets, Entra ID, AKS, Functions, Key Vault, Monitor).
- Proven delivery of internal developer platforms, golden paths, or platform engineering initiatives at scale.
- Strong grasp of security engineering (IAM design, secrets, key management, network security, container security, vulnerability mgmt) and policy-as-code.
- Proficiency with CI/CD (GitHub Actions, Azure DevOps, GitLab CI), artifact registries, and pipeline security.
- Experience with observability (OpenTelemetry, Prometheus/Grafana, Azure Monitor, CloudWatch), SRE practices, and production operations.
- Excellent communication, influence, and executive storytelling skills; ability to set strategy and lead hands-on.
Core Competencies
- Platform Mindset: Product thinking, developer empathy, lifecycle ownership, and SLAs/SLOs for platform capabilities.
- Automation & Quality: Bias for code, testing, and continuous improvement; remove toil.
- Security by Default: Defense-in-depth, least privilege, provable compliance.
- Stakeholder Leadership: Align across security, networking, data, finance, and product teams.
- Outcome Orientation: Measurable improvements to speed, reliability, cost, and risk.