Cloud Architect

All In Solutions, LLC
United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$175,000.0
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Agile Methodology Amazon Web Services Amazon S3 Cloud Computing Cloud Engineering Computer Networks Databases Software Design Documents Domain Name System (DNS) Failover Federal Information Processing Standards (FIPS)
+15 more
Identity and Access Management Subnetting Data Streaming Management of Software Versions Load Balancing Cloud Platform System Istio HybridCloud Change Data Capture Amazon Virtual Private Cloud (VPC) Kubernetes Low Latency Database Replication Route53 Terraform

Job description

  • Design and implement EKS cluster topology, VPC layouts, subnet architectures, IAM role structures, security group definitions, and cross-region connectivity paths

  • Ensure 100% of multi-region infrastructure is provisioned and managed through Terraform IaC with configuration parity across all environments

  • Design and implement Route 53 traffic management strategies including health-check-driven failover, latency-based routing, and weighted routing policies at the application and API level

  • Design and implement S3 Cross-Region Replication configurations for mission-critical data with versioning, FIPS 140-3 encryption, and strict IAM controls

  • Design database replication architectures accommodating GovCloud RDS limitations including independent per-region instances, change data capture, streaming replication, and periodic snapshot export

  • Implement and configure AWS Backup and VA-approved Kubernetes-native backup tooling for centralized cross-region backup with independent per-region encryption

  • Design and implement autoscaling policies using Kubernetes Horizontal Pod Autoscaler and Cluster Autoscaler to prevent resource saturation and enable elastic capacity management

  • Validate that cluster add-ons remain within one minor version of the EKS cluster version across all regions and environments

  • Ensure node management follows standardized AMI deployment with greater than 95% of nodes running the approved image

  • Design cross-VPC connectivity maintaining 99.995% availability between regions

  • Implement automated configuration drift detection running at least weekly with remediation within three business days

  • Design S3 lifecycle policies and Intelligent-Tiering configurations optimizing storage costs while meeting retrieval SLA requirements

  • Coordinate with the Senior Architect on High-Level and Low-Level Design documents depicting regional topology, failover routing, data flows, and monitoring infrastructure

  • Coordinate with tenant application teams on database failover configurations, connection endpoint updates, and application-level validation

  • Participate in Program Increment planning, architecture reviews, and change management activities

Requirements

  • Demonstrated experience designing and implementing cloud infrastructure for complex, mission-critical systems in AWS or equivalent cloud environments

  • Hands-on experience with AWS Elastic Kubernetes Service (EKS), Kubernetes cluster management, and containerized application deployment

  • Deep expertise with Infrastructure as Code tooling, specifically Terraform, for provisioning and managing cloud infrastructure at scale

  • Experience with AWS Route 53 including DNS failover, health checks, latency-based routing, and weighted routing configurations

  • Experience with S3 Cross-Region Replication, lifecycle policies, Intelligent-Tiering, and encryption configurations

  • Knowledge of AWS GovCloud services and their specific limitations compared to commercial AWS regions

  • Experience with database replication strategies including change data capture, streaming replication, and snapshot-based recovery

  • Experience with AWS Backup, Velero, or equivalent backup and recovery tooling for Kubernetes environments

  • Knowledge of networking concepts including VPC design, subnet architecture, security groups, IAM, and cross-region connectivity

  • Experience with Istio service mesh or equivalent service mesh technologies for traffic management, circuit-breaking, and load balancing

  • Familiarity with FIPS 140-3 encryption requirements and Federal security compliance standards

  • Experience working in Agile or SAFe environments with sprint-based delivery cadences

  • AWS Solutions Architect Associate or Professional certification required

  • Certified Kubernetes Administrator (CKA) or equivalent certification preferred

  • Bachelor’s Degree from an accredited academic institution with a minimum of 10 years of experience in cloud infrastructure architecture and engineering, with at least 3 years designing infrastructure in AWS GovCloud or equivalent FedRAMP-authorized environments

  • OR

  • Master’s Degree from an accredited academic institution with a minimum of 7 years of experience in cloud infrastructure architecture and engineering, with at least 2 years designing infrastructure in AWS GovCloud or equivalent FedRAMP-authorized environments

  • Plus:

  • Department of Veterans Affairs (VA) experience

  • Active Personal Identity Verification (PIV) card

  • Experience designing multi-region architectures within AWS GovCloud including failover patterns and cross-region data replication

  • Experience with VA Enterprise Cloud (VAEC) environment-specific connectivity and compliance requirements

Benefits & conditions

Up to $175,000 a year - Full-time, Contract

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:13 min

Defining cloud proficiency by technical role

Piet Van Dongen · LIVE

2:59 min

Scaling clusters and handling automated replica failover

Jürgen Pilz · WWC 2023

2:53 min

Configuring dynamic proxy updates with Istio Pilot

Jan Mensch Jan Mensch · WWC Europe 2026

1:24 min

Evaluating formal AWS certifications versus raw practical engineering experience

Jan Giacomelli · LIVE

5:25 min

Implementing redundancy, failover, and architectural load balancing patterns

Mihaela-Roxana Ghidersa · LIVE

7:15 min

Installing Istio programmatically with bash scripts

Thomas Südbröcker · LIVE

Videos

See all

Related articles

See all