AWS Cloud Architect

Federal Support Specialists, LLC
United States
5 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
$200,000.0 - $220,000.0
Working hours
Shift work
Job source

Tech stack

ASP.NET JavaScript (Programming Language) .NET Framework Multitier Architecture Application Programming Interfaces (APIs) Agile Methodology Artificial Intelligence Amazon Web Services Amazon Elastic Compute Cloud Amazon S3 Application Performance Management Audit Trail
+58 more
Microsoft Azure Bash Shell C Sharp (Programming Language) Cloud Computing Cloud Computing Security Cloud Engineering Cloud Storage Continuous Integration Data Security Software Design Patterns Linux Distributed Systems Amazon DynamoDB Github Infrastructure as a Service (IaaS) Identity and Access Management Virtual Private Networks (VPN) Python (Programming Language) Key Management Microsoft SQL Server Windows Servers Network Control Windows PowerShell Systems Development Life Cycle Role-Based Access Control Azure Active Directory Cloud Services Amazon Simple Notification Service (SNS) Virtualization Technology Data Logging Delivery Pipeline Large Language Models State Machines Multi-Cloud Amazon Virtual Private Cloud (VPC) Backend Cloudformation Servicebus Event Driven Architecture AI Platforms Kubernetes Information Technology Low Latency Bicep Azure AKS Graphql Functional Programming Cloudwatch Api Gateway Amazon Simple Queue Service (SQS) Terraform Data Pipelines Dynatrace Api Management Docker Key Vault Vmware Microservices

Job description

FSS Government Solutions is seeking a Senior AWS Architect to lead the design, implementation, and operation of Amazon Web Services cloud solutions for complex government programs, with Microsoft Azure as the secondary cloud in a multi-cloud estate. You will shape AWS-first architecture for scalability, security, and operational excellence, stand up infrastructure from the ground up, and optimize platforms for AI-enabled products. Azure is in scope where programs, data, or identity already live there, or where dual-cloud resilience is required. The work spans solution architecture, secure multi-cloud infrastructure, event-driven systems, and hands-on delivery with engineering teams., * Lead cloud architecture for client programs with AWS as the primary landing zone: accounts/OUs, network, identity, data, integration, and application patterns aligned to security and scalability requirements. Extend or integrate Azure where the program requires it.

  • Stand up new cloud infrastructure first on AWS (organizations/accounts, VPC, IAM, CloudTrail/Config, baseline security controls), and on Azure subscriptions when a workload is explicitly Azure-hosted or hybrid.
  • Optimize architecture for AI products: model-serving and inference paths (Amazon Bedrock first, Azure OpenAI / Foundry where needed), retrieval and data pipelines, agent/tool interfaces, cost and latency, evaluation hooks, and secure access to LLMs.
  • Design and deliver cloud-native, event-driven platforms that integrate many independent systems into a unified operational ecosystem.
  • Architect AWS orchestration with Step Functions, EventBridge, SQS, and SNS for high daily event volumes with reliability, retries, and recovery. Use Azure Durable Functions, Service Bus, and Event Grid for Azure-resident workflows and cross-cloud event exchange.
  • Design and implement infrastructure using VPC, EC2, Lambda, ECS/EKS, API Gateway, S3, DynamoDB/RDS, and equivalent Azure services (VNets, VMs, Functions, App Services, AKS, Private Link) to support microservices and distributed systems.
  • Build C# / .NET backend services that generate and distribute structured metadata and events to downstream consumers under tight availability SLAs, hosted preferentially on AWS compute (Lambda, ECS/EKS, EC2) and on Azure where that is the system of record.
  • Integrate internal and external systems through REST and GraphQL; use Amazon API Gateway as the default gateway and Azure API Management for Azure-fronted APIs; support AI-enabled integrations, including MCP-style interfaces for LLM tooling.
  • Implement durable storage (S3 first, plus DynamoDB/RDS; Azure Blob/Table where Azure owns the data) for event-driven exchange, audit, and recovery.
  • Develop infrastructure as code and deployment pipelines (Terraform and/or CDK / CloudFormation, plus Bicep where Azure is in play; AWS pipelines / GitHub Actions and Azure DevOps; PowerShell, Bash) to standardize and automate environments.
  • Lead or support migration of applications and data to AWS as the target, and between AWS and Azure with minimal disruption and documented security controls.
  • Implement identity and access management with AWS IAM as the primary control plane, plus Microsoft Entra ID for Azure and hybrid identity; least-privilege RBAC, Secrets Manager / SSM and Key Vault, encryption in transit and at rest.
  • Design resilient network and hybrid connectivity (Direct Connect, Transit Gateway, PrivateLink, plus VPN; ExpressRoute and Azure private endpoints when connecting to Azure or on-prem government/partner systems).
  • Embed FedRAMP and related federal control baselines into architecture, including logging, monitoring, segmentation, and evidence for ATO packages - with FedRAMP-authorized AWS services as the default pattern.
  • Establish observability: structured logging, distributed tracing, and alerting in CloudWatch / X-Ray first, and Application Insights / Azure Monitor for Azure-hosted components.
  • Influence architecture decisions, raise engineering quality, and mentor developers and cloud engineers on AWS-first, multi-cloud patterns.
  • Translate stakeholder requirements into production-ready designs and incremental delivery under Agile / SDLC practices.

Requirements

  • Senior or lead experience designing and implementing enterprise cloud solutions with AWS as the primary production platform, plus working Azure in a multi-cloud or hybrid program - including production event-driven and distributed systems.
  • Demonstrated experience standing up infrastructure (new AWS accounts/organizations and landing zones; Azure subscriptions when required), networking, identity, CI/CD, and baseline observability - not only extending existing estates.
  • Experience optimizing architecture for AI products, including inference/serving design, data and retrieval pipelines, tool/MCP integration, cost, latency, reliability, and security of model access.
  • Strong C# / .NET (including .NET 6/8+ and ASP.NET Core) used to build cloud services, not only diagrams.
  • Hands-on AWS in production: IAM, VPC, EC2, Lambda, Step Functions, EventBridge, SQS/SNS, S3, API Gateway, ECS/EKS or equivalent compute, Secrets Manager / SSM.
  • Hands-on Azure sufficient to design and operate secondary workloads: Functions, Durable Functions, Service Bus, Event Grid, API Management, App Services, Blob/Table Storage, Key Vault, Virtual Networks, Entra ID.
  • Experience with service-oriented and microservice architectures, including orchestration, pub/sub, idempotency, and failure handling.
  • REST and GraphQL integration; API gateway design and operations.
  • SQL Server and/or Aurora/RDS and data access via EF Core or equivalent.
  • Infrastructure as code and CI/CD (Terraform and/or CDK; CloudFormation; Bicep a plus; AWS pipelines and/or Azure DevOps; PowerShell).
  • Cloud security practices: IAM, secrets management, network isolation, encryption.
  • Observability in production (CloudWatch / X-Ray required; Application Insights / Azure Monitor for Azure paths).
  • Ability to lead architecture conversations and work directly with government stakeholders and delivery teams., * AWS Certified Solutions Architect - Associate or Professional (strongly preferred).
  • Azure Solutions Architect Expert (AZ-305) or Azure Administrator Associate (AZ-104).
  • FedRAMP, NIST 800-53, CMMC, or comparable federal authorization experience, especially on AWS.
  • EKS/ECS and AKS, Docker, and Kubernetes in production.
  • Amazon Bedrock in a governed environment; Azure OpenAI / Foundry as the alternate provider.
  • Explicit hybrid or multi-cloud design patterns with AWS as system of record.
  • Virtualization background (VMware or similar) as it relates to migration onto AWS.
  • Clean Architecture, DDD, or behavior-driven design.
  • Python, JavaScript, or additional automation languages.
  • Linux and Windows Server administration sufficient to support IaaS workloads.
  • Broadcast, media metadata (e.g., SCTE-224), or other high-volume integration standards.
  • B.S. in Computer Science or equivalent experience.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:24 min

Evaluating formal AWS certifications versus raw practical engineering experience

Jan Giacomelli · LIVE

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

2:56 min

Provisioning a secure container infrastructure with Bicep

Matthias Falkenberg +1 · World Congress 2022

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

4:09 min

Selecting infrastructure tools and determining proper abstraction layers

Alayshia Knighten Alayshia Knighten · World Congress 2024

Videos

See all

Related articles

See all