Haystack
← Back to Jobs
Technology

Senior Azure Cloud Architect with AZ-305, AZ-104, and AZ-500 certifications

Triwave Solutions IncWashington, DC🇺🇸United StatesPosted 13 Aug 2026

Quick Overview

Work Type
On Site
Level
Mid Senior

Job Description

Senior Azure Cloud Architect
Project Identifier NEA
Project Name Cloud Infrastructure & Modernization
Client National Endowment for the Arts
Agency NEA
Location Hybrid (1 day per week on-site at NEA Washington DC)
Interview Type MS Teams
Contract Duration 2 years with Possible extension
Tentative Start Date Immediate
Deadline Immediate
Project Overview
The National Endowment for the Arts (NEA), Office of Information & Technology Management, operates
and continues to modernize its enterprise environment on Microsoft Azure. The agency requires a Senior
Azure Cloud Architect to own the design, governance, security posture, and migration of workloads across
Azure compute, storage, networking, identity, data, and integration services.
This position specifically requires both deep hands-on Azure engineering and architecture-level design in
a single individual. The Architect will produce reference architectures, diagrams, and architecture decision
records that engineering teams can implement directly; define infrastructure as code standards for the
team; lead architecture review boards and design authority meetings; and drive enterprise-scale landing
zone design and governance aligned to the Microsoft Cloud Adoption Framework and the Azure WellArchitected Framework.
The Architect shall be adept at interpersonal communications, teamwork, goal setting, and business
process improvement, and shall be comfortable translating business requirements into technical designs
and presenting solution designs and tradeoffs to CIOs, CTOs, and senior leadership.
Duties/Responsibilities
Work effectively with federal and contractor personnel to execute the project tasks;
Collaborate with NEA and other federal staff and contractors to refine and elaborate requirements;
Design enterprise-scale Azure solutions across compute services including Virtual Machines, VM
Scale Sets, App Services, Azure Functions, Container Apps, AKS, and Azure Batch, selecting the right
option for a given workload;
Architect advanced Azure networking spanning Virtual Networks, NSGs, UDRs, Private Endpoints,
Load Balancer, Application Gateway, Azure Firewall, Front Door, Virtual WAN, ExpressRoute, and
VPN Gateway, including hub and spoke topologies and enterprise DNS strategy;
Design identity architecture using Microsoft Entra ID, including Conditional Access, Privileged
Identity Management, B2B and B2C scenarios, federation with on-premises Active Directory,
managed identities, and RBAC;
Innosoft is an Equal Opportunity/Affirmative Action employer
Apply the Azure Well-Architected Framework across reliability, security, cost optimization,
operational excellence, and performance efficiency;
Implement Cloud Adoption Framework practices, including enterprise scale landing zone design and
governance blueprints;
Design multi region, highly available, and disaster resilient solutions with defined recovery time and
recovery point objectives;
Produce reference architectures, diagrams, and architecture decision records that an engineering
team can implement directly;
Lead workload assessments using Azure Migrate and map applications to the five Rs of rehost,
refactor, rearchitect, rebuild, and replace;
Perform wave planning for large scale datacenter exits, including dependency mapping and cutover
planning;
Define infrastructure as code standards and repository structure for the team, and review and
validate Bicep or Terraform code written by others;
Build and maintain CI/CD pipelines in Azure DevOps or GitHub Actions, including artifact
management, secret scanning, and pipeline security hardening;
Implement release strategies including blue and green, canary, and ring based deployments;
Operate production AKS clusters, including upgrades, node pool management, and networking
through Azure CNI or Calico, with Helm chart authoring and GitOps workflows using Flux or ArgoCD;
Implement security, compliance, and governance using Microsoft Defender for Cloud, Microsoft
Sentinel, and Key Vault with secret rotation, together with Azure Policy, Management Groups, and
Blueprints, applying Zero Trust principles across identity, network, and data layers;
Configure Azure Monitor, Log Analytics, and Application Insights, and author KQL queries for
diagnostics, alerting, and dashboards;
Provide incident command, including root cause analysis and capacity planning at scale;
Drive FinOps practices using Azure Cost Management, reserved instances, savings plans, and
rightsizing, and build total cost of ownership and return on investment models for executive
stakeholders;
Lead a team of engineers, including task assignment and design reviews with clear, constructive
feedback;
Lead architecture review boards and design authority meetings, and facilitate discovery workshops
with business and technical stakeholders;
Mentor engineers and architects on design patterns and troubleshooting technique.
Required Education and Experience
Degree in Computer Science or related field.
Between 9 and 15 years of total IT experience, including at least 5 to 7 years of hands-on Azure
engineering and at least 2 to 4 years operating at an architecture or technical leadership level.
A career path that progressed from hands-on engineering into architecture, since this position
specifically requires both skill sets in one candidate.
Innosoft is an Equal Opportunity/Affirmative Action employer
Advanced, hands-on expertise across Azure compute services, including Virtual Machines, VM Scale
Sets, App Services, Azure Functions, Container Apps, AKS, and Azure Batch.
Full lifecycle knowledge of Blob Storage, Azure Files, Managed Disks, and storage lifecycle
management policies.
Advanced Azure networking experience at an enterprise level, including hub and spoke design and
DNS strategy.
Identity expertise covering Microsoft Entra ID administration and architecture, including Conditional
Access, Privileged Identity Management, B2B and B2C, federation, managed identities, and RBAC
design.
Data platform experience across Azure SQL, Cosmos DB, PostgreSQL Flexible Server, Synapse
Analytics, Microsoft Fabric, and Data Lake Storage, from both an administration and a solution
design perspective.
Integration services knowledge including API Management, Service Bus, Event Grid, Event Hubs, and
Logic Apps.
Deep mastery of the Azure Well-Architected Framework and fluency with the Cloud Adoption
Framework.
Expert level, hands-on proficiency in Bicep or Terraform, including module design, state
management, and reusable patterns.
Working knowledge of ARM templates for legacy or complex deployments.
Strong scripting ability in PowerShell, Bash, and Python for automation and validation.
Production experience operating AKS, including upgrades, node pool management, and networking
through Azure CNI or Calico.
Hands-on experience with Microsoft Defender for Cloud, Microsoft Sentinel, and Key Vault,
including secret rotation practices.
Governance design using Azure Policy, Management Groups, and Blueprints.
Advanced configuration of Azure Monitor, Log Analytics, and Application Insights, with strong KQL
query writing.
Practical experience with Azure Cost Management, reserved instances, savings plans, and
rightsizing.
Clear written and verbal communication, including polished design documentation, with strong
stakeholder management, negotiation, and the ability to influence without direct authority.
Preferred Qualifications
Background in Windows Server, Linux administration, or virtualization platforms such as VMware,
which is valuable for migration and hybrid scenarios.
Exposure to a regulated industry such as financial services, healthcare, or government.
Hybrid architecture experience using Azure Arc, Azure Stack HCI, and Azure Stack Edge.
Application modernization expertise, including microservices, event driven architectures, serverless
patterns, and strangler fig migrations.
Innosoft is an Equal Opportunity/Affirmative Action employer
Familiarity with relevant frameworks such as the CIS Azure Benchmark, NIST 800-53, FedRAMP,
HIPAA, or PCI DSS.
Working knowledge of service mesh concepts through Istio or Open Service Mesh.
Understanding of Enterprise Agreement, Microsoft Customer Agreement, and bring your own
license structures.
Experience with Agile/Scrum development environments.
Experience working with cross-functional teams in a federal or regulated environment.
An ownership mentality and comfort operating with ambiguity.
Certifications (Azure Only)
Required: AZ-305, Azure Solutions Architect Expert.
Required: AZ-104, Azure Administrator Associate.
Required: AZ-500, Azure Security Engineer Associate.
Preferred: AZ-700, Azure Network Engineer Associate.
Preferred: SC-100, Cybersecurity Architect Expert.
Preferred: CKA, Certified Kubernetes Administrator

Skills

Microservices
SQL
PCI DSS
Scrum
Service Mesh
Active Directory
Agile
ArgoCD
Azure
Bash
DNS
GitHub Actions
HIPAA
Helm
Istio
Kubernetes
PostgreSQL
PowerShell
Python
Stakeholder Management
Terraform
VMware
Vault
Zero Trust

Similar jobs