Power Platform Solution Architect Expert
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+40 more
Job description
- Own and maintain the authoritative STAAND architecture: logical and physical data models, Dataverse table and relationship design, solution segmentation, environment strategy, and integration topology.
- Personally build in the platform - model-driven app configuration, plug-ins and custom APIs (C#/.NET), PCF controls, TypeScript/JavaScript client extensions, Power Fx, and plug-in pipeline optimization.
- Establish and enforce architecture standards, design patterns, naming conventions, and technical debt registers across all modules and portals.
- Chair design authority review for significant changes; sign off on solution designs before build.
- Diagnose deep platform issues: performance degradation, API and service-protection limits, plug-in execution ordering, solution layering conflicts, storage growth, portal rendering.
- Maintain architecture artifacts sufficient to satisfy CCWIS review, federal audit, and District IT governance. 2. Cross-Cloud Architecture: GCC and Commercial Azure:
- Design, document, and harden the boundary between the GCC Dynamics/Power Platform tenant and Azure commercial-cloud services.
- Define what data may traverse that boundary, in what form (de-identified, tokenized, aggregated, or full record), under what authorization, and with what logging - including explicit architectural boundaries for protected data categories such as Medicaid Enrollment.
- Implement cross-tenant identity, managed identities, service principals, Key Vault secret lifecycle, private networking, and API gateway patterns.
- Maintain a defensible position on data residency and FedRAMP authorization boundaries for every commercial-cloud service in use, and present that position to auditors and federal reviewers. 3. AI and Agentic Development:
- Serve as hands-on technical lead for CFSA’s AI capability, including CORA and its expansion into agentic workflows.
- Design, build, evaluate, and productionize agents in Azure AI Foundry and Copilot Studio: tool and function calling, orchestration and multi-agent patterns, grounding and retrieval over Dataverse and document stores, prompt and context engineering, structured output, and human-in-the-loop checkpoints.
- Own AI evaluation discipline: golden datasets, automated evals, groundedness and hallucination measurement, regression testing on model or prompt changes, latency and cost benchmarking, controlled rollout.
- Manage the AI model lifecycle - track model releases and deprecations, run comparative evaluation before adopting a new model, execute migrations without regression to worker-facing quality.
- Implement responsible AI controls appropriate to a child welfare setting: content safety, PII/PHI handling, bias and fairness testing, explainability, audit logging of AI-influenced actions, and clear framing of AI output as decision support rather than decision making.
- Support predictive and analytic capability aligned to agency mission priorities, ensuring models are validated, monitored for drift, and governed.
- Build reusable AI platform assets - prompt libraries, agent templates, evaluation harnesses, observability dashboards. 4. Application and Platform Security:
- Own the security architecture of STAAND end to end; serve as technical counterpart to the agency ISSO, OCTO security, and District privacy officials.
- Apply and evidence compliance with OCTO IT policies (octo.dc.gov/page/it-policies), NIST SP 800-53, FISMA, FedRAMP, HIPAA, 45 CFR 1355 (CCWIS), Title IV-E confidentiality, and District data protection law including DC Code 28-3851 et seq. breach notification obligations.
- Design and enforce least privilege: Dataverse business unit and role architecture, row/column-level security, portal web roles and table permissions, privileged access management, separation of duties for finance and eligibility functions.
- Lead secure SDLC: threat modeling, secure code review, static and dynamic analysis, dependency and supply-chain scanning, secrets management, remediation tracking with severity-based SLAs.
- Support penetration tests, vulnerability assessments, and audit response; own STAAND-assigned POA&M items.
- Define AI-specific security requirements: prompt injection defenses, tool-permission scoping, data exfiltration prevention, agent action auditing.
- Contribute to incident response, continuity, and disaster recovery planning; validate RTO/RPO through periodic exercises. 5. Continuous Improvement and Release Management:
- Own the STAAND change pipeline from enhancement request through design, build, test, release, and post-release verification, including published release notes and coordination with the CISA training organization.
- Plan and execute against Microsoft’s Dynamics 365 biannual release waves and Power Platform service updates: early-access testing in a dedicated environment, deprecation and breaking-change assessment, and a documented impact and remediation plan per wave.
- Evaluate new platform, Azure, and AI capabilities against the STAAND roadmap; run structured proofs of concept and make evidence-based adopt / trial / hold / retire recommendations.
- Maintain a rolling multi-year technical roadmap balancing stabilization, platform health, security, federal compliance, and innovation.
- Drive performance, reliability, and cost optimization - capacity and license consumption, Azure spend, storage tiering, API efficiency.
- Advance DevOps maturity: source-controlled solutions, automated build and deploy pipelines, environment refresh, automated regression testing, release quality metrics.
- Maintain and report the technical issues and risk register with mitigation owners and timelines. 6. Data, Interoperability, and Federal Reporting:
- Own the data architecture supporting AFCARS, NCANDS, NYTD, CFSR, and Title IV-E reporting, including lineage, quality rules, exception handling, and submission validation.
- Design and maintain bi-directional exchanges with District and external partners consistent with CCWIS interoperability requirements.
- Establish automated data quality controls, duplicate person detection and merge integrity, and reconciliation with legacy records. 7. Stakeholder and Senior Leadership Engagement:
- Translate between social work practice and technical architecture; observe real workflow with intake workers, investigators, case managers, placement staff, and fiscal teams before designing for it.
- Brief the CFSA IT Steering Committee Members, CIO, STAAND Product Leadership, OCTO leadership, Council oversight staff, court monitors, and ACF/Children’s Bureau reviewers, calibrating to each audience.
- Serve as principal technical liaison to Microsoft (Industry Solutions Delivery, Customer Success, product groups) and to implementation and support vendors; hold them to architectural and quality standards.
- Author decision memos, architecture decision records, briefing decks, and federal reporting content requiring minimal editing.
- Mentor CFSA staff and other contract resources; build internal capability and reduce single-point-of-failure dependency.
Requirements
Bachelor’s degree in Computer Science, Software Engineering, Information Systems, Data Science, or a closely related technical discipline from an accr, Microsoft Certified: Cybersecurity Architect Expert (SC-100)
Desired
Microsoft Certified: Fabric Analytics Engineer (DP-600) or Azure Data Engineer (DP-203)
Desired
Progressive IT experience
Required
16 Years
Solution or enterprise architecture on enterprise-scale, mission-critical systems
Required
8 Years
Lead or principal architect on full D365 implementation lifecycles (min. 2 lifecycles)
Required
5 Years
Microsoft Azure architecture and hands-on build (PaaS integration, data, identity)
Required
4 Years
Generative AI / agentic development in production - Azure AI Foundry, Azure OpenAI, or Copilot Studio
Required
2 Years
RAG / grounding, tool calling, agent orchestration, and AI evaluation methodology
Required
2 Years
Application security in a regulated environment (NIST 800-53 or equivalent, threat modeling, secure SDLC)
Required
5 Years
Government cloud delivery - GCC, GCC High, or Azure Government
Required
2 Years
Pro-code D365 extensibility - C#/.NET plug-ins, custom APIs, PCF controls
Required
5 Years
Cross-cloud or cross-tenant architecture (government ? commercial)
Required
2 Years
Power Platform ALM, solution layering, Azure DevOps CI/CD
Required
4 Years
Operating a live production system through vendor platform release waves without disruption
Required
3 Years
Direct briefing of executive / non-technical program leadership
Required
5 Years
Health and Human Services domain - child welfare (CCWIS/SACWIS), Medicaid/MMIS, integrated eligibility, behavioral health, or public health systems
Desired
3 Years
Federal child welfare reporting - AFCARS, NCANDS, NYTD, CFSR, Title IV-E
Desired
2 Years
Power Pages / portal architecture and external-user security
Desired
3 Years
Data engineering and BI - Fabric, Synapse, Data Factory, Power BI
Desired
3 Years
Public sector or District government delivery experience
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
From Prototype to Production: Build AI Agents with This Free 4-Course Learning Path
Dev Digest 120 - Apple and peers
Top Must-Visit Developer Conferences in the US in 2026