About the Role
This role focuses on developing cloud architectures, frameworks, standards, governance, and policies. The ideal candidate will engage with business users and technology teams to understand requirements and develop multi/hybrid cloud solution architectures for implementation by engineering teams. The resource will also augment cloud engineering skills or guide engineers as needed, requiring on-premises infrastructure knowledge for systems interacting with or migrating to the cloud. The organization aims to advance its Infrastructure-as-Code practices.
Responsibilities
- Design scalable, resilient, cost-optimized, and secure cloud solutions aligned with business needs and cybersecurity policies.
- Assess applications for cloud suitability and develop migration roadmaps.
- Document architectural designs (Microsoft Visio), cloud governance frameworks, cloud standards, and implementation guides.
- Implement cloud security best practices.
- Optimize cloud environments for cost efficiency.
- Monitor performance and availability using cloud-native tools.
- Implement auto-scaling, caching, and load balancing strategies.
- Configure and optimize CDNs for low-latency applications.
- Debug and troubleshoot cloud infrastructure, networking, and service-related issues.
- Use cloud-native monitoring, logging, and tracing tools for root cause analysis.
- Work closely with cross-functional teams.
- Translate complex technical concepts into business-friendly language.
- Participate in technical discussions, cloud strategy planning, and decision-making processes.
Requirements
- Proficiency in engaging with business users and other technology teams to understand and assess requirements.
- Requires a degree of on-premises infrastructure knowledge.
- Hands-on experience with Terraform, AWS CloudFormation, Azure ARM, or Pulumi for infrastructure provisioning.
- Develop CI/CD pipelines for automated deployment using GitHub Actions, GitLab CI/CD, Jenkins, or AWS CodePipeline.
- Automate configuration management using Ansible, Chef, or Puppet.
- Knowledge of Zero-Trust architectures and cloud security frameworks (CIS, NIST, ISO 27001).
- Experience with SIEM tools (Splunk, Chronicle Security) for security monitoring.
- Experience with cost management tools like Cost Explorer, Cost & Usage Reports, Savings Plans, Azure Advisor, Cost and Billing Management, Reservations, and general FinOps practices.
- Monitor performance and availability using CloudWatch, Azure Monitor, Azure Resource Health, SolarWinds.
- Strong understanding of VPC design, VNet design, Hub & Spoke, Transit Gateway, Peering, Application Load Balancers, Application Gateway, Network Load Balancers, Traffic Manager, VPNs, Direct Connect, ExpressRoute, and hybrid networking.
- Configure and optimize CDNs (CloudFront, Global Accelerator, Frontdoor, Cloudflare, Akamai) for low-latency applications.
- Use cloud-native monitoring, logging, and tracing tools (CloudWatch, Network Monitor, VPC Flow Logs, Azure Monitor, Network Watcher) for root cause analysis.
- Work closely with cross-functional teams (Network, Server, DevOps, Cybersecurity, Finance, and Procurement).
- Translate complex technical concepts into business-friendly language.
- Participate in technical discussions, cloud strategy planning, and decision-making processes.
- AWS: 6-10 years
- Azure: 2-4 years
- Hybrid On-Prem/Knowledge: 4-6 years
- Cloud Networking: 4-6 years
- Cloud DevOps: 4-6 years
- Cloud Security: 2-3 years
- Cloud FinOps: 1-2 years
- Microsoft Visio: 2-3 years
- Deep understanding of cloud platforms, services, frameworks, governance.
- Proficiency with AWS and Azure cloud platforms is a must.
- The resource will primarily focus on designing architectures, standards, and governance for the AWS platform but will also support other architects on Azure when required.
- Expertise in efficiently managing multi-account AWS Organization and multi-subscription Azure Tenant.
- AWS Cloud Shell / Azure Cloud Shell – PowerShell or CLI.
- Resource may augment existing teams’ skillsets for other cloud platforms as needed.
- Experience with hybrid and multi-cloud interoperability and on-prem to cloud integrations.
- Bright, motivated, skilled, a difference-maker, able to get things done, work with minimum direction, enthusiastic, a thinker, able to juggle and multi-task, communicate effectively, and lead.
Skills
- AWS Compute (EC2, Instance Auto Scaling, Batch)
- AWS Storage (S3, EBS, Batch Operations, Tiers, Intelligent Tiering, Lifecycle Policies)
- AWS Data Analytics Platforms (Glue, Lake Formation, Redshift, Athena, etc.)
- AWS Database Services (RDS, Aurora, DynamoDB, etc.)
- Serverless Services (Fargate, Lambda)
- Azure Compute Services (VMs, Scale-Sets, Batch)
- Azure Storage (Storage Accounts, Blobs, Files, Tables, Queues, Data Lake)
- Azure Data Analytics Platforms (Fabric, Data Factory, Synapse, Databricks, Event Hubs etc.)
- Azure Database Services (Azure SQL DB, Managed Instance, Hyperscale, Cosmos DB etc.)
- Serverless Services (Azure Functions, Web App, App Services, ASE, Logic Apps, etc.)
- Containerization (ECS, ECR, EKS, Batch, Kubernetes, Docker, AKS, OpenShift, etc.)
- Implementing Disaster Recovery (DR) and Backup Strategies aligned with Regulatory Compliance (RTO/RPO)
- Infrastructure As Code (IaC)
- Automation
- Terraform
- AWS CloudFormation
- Azure ARM
- Pulumi
- GitHub Actions
- GitLab CI/CD
- Jenkins
- AWS CodePipeline
- Ansible
- Chef
- Puppet
- Cloud Security Best Practices (IAM, RBAC, WAF, Security Groups, NACLs, CloudTrail, GuardDuty, Secrets Manager, NSG, ASG, Service Principals, Managed Identities, Azure Advisor, Defender for Cloud, Key Vault, Encryption, Monitoring)
- Zero-Trust Architectures
- Cloud Security Frameworks (CIS, NIST, ISO 27001)
- SIEM Tools (Splunk, Chronicle Security)
- Performance Optimization
- Cost Management
- CloudWatch
- Azure Monitor
- Azure Resource Health
- SolarWinds
- VPC Design
- VNet Design
- Hub & Spoke
- Transit Gateway
- Peering
- Application Load Balancers
- Application Gateway
- Network Load Balancers
- Traffic Manager
- VPNs
- Direct Connect
- ExpressRoute
- Hybrid Networking
- CDNs (CloudFront, Global Accelerator, Frontdoor, Cloudflare, Akamai)
- Troubleshooting
- Support
- Cloud-Native Monitoring
- Logging
- Tracing Tools
- Network Monitor
- VPC Flow Logs
- Azure Monitor
- Network Watcher
- Collaboration
- Stakeholder Engagement
- AWS
- Azure
- OCI
- GCP
- Hybrid Cloud
- Multi-Cloud
- On-Premises Infrastructure
- Cloud Networking
- Cloud DevOps
- Cloud Security
- Cloud FinOps
- Microsoft Visio
- Multi-Account AWS Organization
- Multi-Subscription Azure Tenant
- AWS Cloud Shell
- Azure Cloud Shell
- PowerShell
- CLI
- Hybrid and Multi-Cloud Interoperability
- On-Prem to Cloud Integrations
Location
- 2 Broadway - MTA Headquarters
Work Type
- 3 Days Onsite & 2 Days Remote
Experience Level
- Senior
- 6-10 Years AWS
- 2-4 Years Azure
- 4-6 Years Hybrid On-Prem/Knowledge
- 4-6 Years Cloud Networking
- 4-6 Years Cloud DevOps
- 2-3 Years Cloud Security
- 1-2 Years Cloud FinOps
- 2-3 Years Microsoft Visio
About the Company
- Since 2000, Tri-Force Consulting Services has been an MBE/SDB certified IT consulting firm in the Philadelphia region.
- Tri-Force specializes in IT staffing, software development (web and mobile apps), systems integration, data analytics, system automation, cybersecurity, and cloud technology solutions for government and commercial clients.
- Tri-Force works with clients to overcome obstacles such as increasing productivity, increasing efficiencies through automation, and lowering costs.
- Our clients benefit from our three distinguishing core values: Integrity, Diligence, and Technological Excellence.
- Tri-Force is a six-time winner among the Fastest-Growing Companies in Philadelphia and a four-time winner on the Inc. 5000 list of the nation's fastest-growing companies.
