About the Role
This senior-level role focuses on developing cloud architectures, frameworks, standards, governance, and policies. The ideal candidate will engage with business users and technology teams to understand requirements and design multi/hybrid cloud architectures. The role also involves augmenting cloud engineering skills or guiding engineers, and requires on-premises infrastructure knowledge for systems interacting with or migrating to the cloud. Advancing Infrastructure-as-Code practices is a future goal.
Responsibilities
- Develop cloud architectures that are scalable, resilient, cost efficient, and secure, ensuring alignment with organizational goals and established cybersecurity policies.
- Evaluate applications to determine their readiness and suitability for cloud adoption, and create detailed migration strategies and roadmaps.
- Produce clear and comprehensive architectural documentation—including Microsoft Visio diagrams—as well as cloud governance models, technical standards, and implementation playbooks.
- Hands-on experience with Terraform, Azure ARM, or Pulumi for infrastructure provisioning.
- Develop CI/CD pipelines for automated deployment using GitHub Actions, GitLab CI/CD, Jenkins, or AWS CodePipeline.
- Automate configuration management using Ansible, Chef, or Puppet.
- Implement cloud security best practices (IAM, RBAC, WAF, NSG, ASG, Service Principals, Managed Identities, Azure Advisor, Defender for Cloud, Key Vault, encryption, monitoring).
- Knowledge of zero-trust architectures and cloud security frameworks (CIS, NIST, ISO 27001).
- Experience with SIEM tools (Splunk, Chronicle Security) for security monitoring.
- Optimize cloud environments for cost efficiency using Azure Advisor, Cost and Billing Management, and general FinOps practices.
- Monitor performance and availability using Azure Monitor, Azure Resource Health, SolarWinds.
- Implement auto-scaling, caching, and load balancing strategies for cloud workloads.
- Strong understanding of vNet design, Hub & Spoke, Peering, Application Gateway, Load Balancers, Traffic Manager, VPNs, ExpressRoute, and hybrid networking.
- Configure and optimize CDNs (Frontdoor, Cloudflare, Akamai) for low-latency applications.
- Debug and troubleshoot cloud infrastructure, networking, and service-related issues.
- Use cloud-native monitoring, logging, and tracing tools (Azure Monitor, Network Watcher) for root cause analysis.
- Work closely with cross-functional teams (Network, Server, DevOps, Cybersecurity, Finance, and Procurement).
- Translate complex technical concepts into business-friendly language.
- Participate in technical discussions, cloud strategy planning, and decision-making processes.
Requirements
- Proficiency with Azure Cloud Platform is a must.
- Expertise in efficiently managing multi-subscription Azure Tenant.
- Azure Cloud Shell - PowerShell, or CLI.
- Resource may augment existing teams’ skillsets for other cloud platforms as needed.
- Experience with hybrid and multi-cloud interoperability and on-prem to cloud integrations.
- Strong understanding of Azure compute services (VMs, Scale-Sets, Batch).
- Strong understanding of Azure storage (storage accounts, blobs, files, tables, queues, data lake).
- Strong understanding of Azure data analytics platforms (Fabric, Data Factory, Synapse, Databricks, Event Hubs etc.).
- Strong understanding of Azure database services (Azure SQL DB, Managed Instance, Hyperscale, Cosmos DB etc.).
- Strong understanding of Serverless services (Azure Functions, Web App, App Services, ASE, Logic Apps, etc.).
- Strong understanding of Containerization (Kubernetes, Docker, AKS, OpenShift, etc.).
- Develop robust disaster recovery and backup strategies that fully meet regulatory obligations and satisfy defined recovery time and recovery point objectives (RTO/RPO).
- Knowledge of zero-trust architectures and cloud security frameworks (CIS, NIST, ISO 27001).
Skills
- Azure
- GCP
- AWS
- OCI
- Hybrid On-Prem/Knowledge
- Cloud Networking
- Cloud DevOps
- Cloud Security
- Cloud FinOps
- Microsoft Visio
- Deep Understanding of Cloud Platforms, Services, Frameworks, Governance
- Terraform
- Azure ARM
- Pulumi
- GitHub Actions
- GitLab CI/CD
- Jenkins
- AWS CodePipeline
- Ansible
- Chef
- Puppet
- SIEM tools (Splunk, Chronicle Security)
- Azure Advisor
- Cost and Billing Management
- Azure Monitor
- Azure Resource Health
- SolarWinds
- vNet design
- Hub & Spoke
- Peering
- Application Gateway
- Load Balancers
- Traffic Manager
- VPNs
- ExpressRoute
- CDNs (Frontdoor, Cloudflare, Akamai)
- Network Watcher
Location
- 2 Broadway - MTA Headquarters
Work Type
- 3 days onsite & 2 days remote
Experience Level
- Senior Level
Education Level
- Azure Solutions Architect Expert certification
