Why This Role Stands Out
This hybrid role offers a fantastic opportunity to lead innovative solutions within Microsoft's D365, Power Platform, and Azure ecosystem, with potential for project extensions. You'll thrive here if you're a seasoned architect passionate about designing robust, scalable architectures and driving technical excellence within a collaborative environment. Seize this chance to make a significant impact and advance your career.
Quick Overview
Job Description
Position Title & Code: Solution Architect Lead - D365/Power Platform/Azure
Location: Washington, DC 20003
Project End Date: 09/30/2026 (With Possible extension to next fiscal year)
Scope of Work and Responsibilities:
- Solution and Platform Architecture:
- Own and maintain the authoritative STAAND architecture: logical and physical data models, Dataverse table and relationship design, solution segmentation, environment strategy, and integration topology.
- Personally build in the platform - model-driven app configuration, plug-ins and custom APIs (C#/.NET), PCF controls, TypeScript/JavaScript client extensions, Power Fx, and plug-in pipeline optimization.
- Establish and enforce architecture standards, design patterns, naming conventions, and technical debt registers across all modules and portals.
- Chair design authority review for significant changes; sign off on solution designs before build.
- Diagnose deep platform issues: performance degradation, API and service-protection limits, plug-in execution ordering, solution layering conflicts, storage growth, portal rendering.
- Maintain architecture artifacts sufficient to satisfy CCWIS review, federal audit, and District IT governance.
- Cross-Cloud Architecture: GCC and Commercial Azure:
- Design, document, and harden the boundary between the GCC Dynamics/Power Platform tenant and Azure commercial-cloud services.
- Define what data may traverse that boundary, in what form (de-identified, tokenized, aggregated, or full record), under what authorization, and with what logging - including explicit architectural boundaries for protected data categories such as Medicaid Enrollment.
- Implement cross-tenant identity, managed identities, service principals, Key Vault secret lifecycle, private networking, and API gateway patterns.
- Maintain a defensible position on data residency and FedRAMP authorization boundaries for every commercial-cloud service in use, and present that position to auditors and federal reviewers.
- AI and Agentic Development:
- Serve as hands-on technical lead for CFSA's AI capability, including CORA and its expansion into agentic workflows.
- Design, build, evaluate, and productionize agents in Azure AI Foundry and Copilot Studio: tool and function calling, orchestration and multi-agent patterns, grounding and retrieval over Dataverse and document stores, prompt and context engineering, structured output, and human-in-the-loop checkpoints.
- Own AI evaluation discipline: golden datasets, automated evals, groundedness and hallucination measurement, regression testing on model or prompt changes, latency and cost benchmarking, controlled rollout.
- Manage the AI model lifecycle - track model releases and deprecations, run comparative evaluation before adopting a new model, execute migrations without regression to worker-facing quality.
- Implement responsible AI controls appropriate to a child welfare setting: content safety, PII/PHI handling, bias and fairness testing, explainability, audit logging of AI-influenced actions, and clear framing of AI output as decision support rather than decision making.
- Support predictive and analytic capability aligned to agency mission priorities, ensuring models are validated, monitored for drift, and governed.
- Build reusable AI platform assets - prompt libraries, agent templates, evaluation harnesses, observability dashboards.
- Application and Platform Security:
- Own the security architecture of STAAND end to end; serve as technical counterpart to the agency ISSO, OCTO security, and District privacy officials.
- Apply and evidence compliance with OCTO IT policies (octo.dc.gov/page/it-policies), NIST SP 800-53, FISMA, FedRAMP, HIPAA, 45 CFR 1355 (CCWIS), Title IV-E confidentiality, and District data protection law including DC Code 28-3851 et seq. breach notification obligations.
- Design and enforce least privilege: Dataverse business unit and role architecture, row/column-level security, portal web roles and table permissions, privileged access management, separation of duties for finance and eligibility functions.
- Lead secure SDLC: threat modeling, secure code review, static and dynamic analysis, dependency and supply-chain scanning, secrets management, remediation tracking with severity-based SLAs.
- Support penetration tests, vulnerability assessments, and audit response; own STAAND-assigned POA&M items.
- Define AI-specific security requirements: prompt injection defenses, tool-permission scoping, data exfiltration prevention, agent action auditing.
- Contribute to incident response, continuity, and disaster recovery planning; validate RTO/RPO through periodic exercises.
- Continuous Improvement and Release Management:
- Own the STAAND change pipeline from enhancement request through design, build, test, release, and post-release verification, including published release notes and coordination with the CISA training organization.
- Plan and execute against Microsoft's Dynamics 365 biannual release waves and Power Platform service updates: early-access testing in a dedicated environment, deprecation and breaking-change assessment, and a documented impact and remediation plan per wave.
- Evaluate new platform, Azure, and AI capabilities against the STAAND roadmap; run structured proofs of concept and make evidence-based adopt / trial / hold / retire recommendations.
- Maintain a rolling multi-year technical roadmap balancing stabilization, platform health, security, federal compliance, and innovation.
- Drive performance, reliability, and cost optimization - capacity and license consumption, Azure spend, storage tiering, API efficiency.
- Advance DevOps maturity: source-controlled solutions, automated build and deploy pipelines, environment refresh, automated regression testing, release quality metrics.
- Maintain and report the technical issues and risk register with mitigation owners and timelines.
- Data, Interoperability, and Federal Reporting:
- Own the data architecture supporting AFCARS, NCANDS, NYTD, CFSR, and Title IV-E reporting, including lineage, quality rules, exception handling, and submission validation.
- Design and maintain bi-directional exchanges with District and external partners consistent with CCWIS interoperability requirements.
- Establish automated data quality controls, duplicate person detection and merge integrity, and reconciliation with legacy records.
- Stakeholder and Senior Leadership Engagement:
- Translate between social work practice and technical architecture; observe real workflow with intake workers, investigators, case managers, placement staff, and fiscal teams before designing for it.
- Brief the CFSA IT Steering Committee Members, CIO, STAAND Product Leadership, OCTO leadership, Council oversight staff, court monitors, and ACF/Children's Bureau reviewers, calibrating to each audience.
- Serve as principal technical liaison to Microsoft (Industry Solutions Delivery, Customer Success, product groups) and to implementation and support vendors; hold them to architectural and quality standards.
- Author decision memos, architecture decision records, briefing decks, and federal reporting content requiring minimal editing.
- Mentor CFSA staff and other contract resources; build internal capability and reduce single-point-of-failure dependency.
Skill Assessment: (Please include the years of experience last used and brief description on skills below, information is to be submitted along with the resume)
| Skill | Required / Desired | Amount of Experience | Years of Experience |
| Bachelor's degree in Computer Science, Software Engineering, Information Systems, Data Science, or a closely related technical discipline from an accr | Required | 20 Years | |
| Dynamics 365 Customer Service (MB-230) | Required | ||
| Microsoft Certified: Power Platform Solution Architect Expert (PL-600) | Required | ||
| Microsoft Dynamics 365 CE / Dataverse / Power Platform - hands-on | Required | ||
| Microsoft Certified: Azure Solutions Architect Expert (AZ-305) | Required | ||
| Microsoft Certified: Power Platform Developer Associate (PL-400) | Desired | ||
| TOGAF 9/10 Certified | Desired | ||
| Microsoft Certified: Azure AI Engineer Associate (AI-102) | Desired | ||
| Microsoft Certified: Azure Security Engineer Associate (AZ-500) | Desired | ||
| CISSP or CCSP (ISC ) | Desired | ||
| Microsoft Certified: Cybersecurity Architect Expert (SC-100) | Desired | ||
| Microsoft Certified: Fabric Analytics Engineer (DP-600) or Azure Data Engineer (DP-203) | Desired | ||
| Progressive IT experience | Required | 16 Years | |
| Solution or enterprise architecture on enterprise-scale, mission-critical systems | Required | 8 Years | |
| Lead or principal architect on full D365 implementation lifecycles (min. 2 lifecycles) | Required | 5 Years | |
| Microsoft Azure architecture and hands-on build (PaaS integration, data, identity) | Required | 4 Years | |
| Generative AI / agentic development in production - Azure AI Foundry, Azure OpenAI, or Copilot Studio | Required | 2 Years | |
| RAG / grounding, tool calling, agent orchestration, and AI evaluation methodology | Required | 2 Years | |
| Application security in a regulated environment (NIST 800-53 or equivalent, threat modeling, secure SDLC) | Required | 5 Years | |
| Government cloud delivery - GCC, GCC High, or Azure Government | Required | 2 Years | |
| Pro-code D365 extensibility - C#/.NET plug-ins, custom APIs, PCF controls | Required | 5 Years | |
| Cross-cloud or cross-tenant architecture (government ? commercial) | Required | 2 Years | |
| Power Platform ALM, solution layering, Azure DevOps CI/CD | Required | 4 Years | |
| Operating a live production system through vendor platform release waves without disruption | Required | 3 Years | |
| Direct briefing of executive / non-technical program leadership | Required | 5 Years | |
| Health and Human Services domain - child welfare (CCWIS/SACWIS), Medicaid/MMIS, integrated eligibility, behavioral health, or public health systems | Desired | 3 Years | |
| Federal child welfare reporting - AFCARS, NCANDS, NYTD, CFSR, Title IV-E | Desired | 2 Years | |
| Power Pages / portal architecture and external-user security | Desired | 3 Years | |
| Data engineering and BI - Fabric, Synapse, Data Factory, Power BI | Desired | 3 Years | |
| Public sector or District government delivery experience | Desired | 2 Years |
Similar jobs
- RA
HEALTHCARE SOLUTION ARCHITECT
NewRapidIT, Inc
United States🇺🇸Hybrid14 hours agoSAFeMicroservicesAWS+4Technology - CA
Oracle Cloud Solution Architect - Finance
Capgemini America, Inc.
IL🇺🇸$103.9k - $282k/yrHybrid4 weeks agoOracleGenerative AIStakeholder ManagementTechnology - AS
Senior Network Architect
NewApex Systems
Austin, TX🇺🇸Hybrid14 hours agoAzureStrategic PlanningVendor Management+1Technology - CH
Solutions Architect I or II, DOE - Healthcare Services
NewCambia Health Solutions
Renton, Washington🇺🇸$114k - $143k/yrHybrid2 hours agoMicroservicesSQLAWS+4Technology - VA
Sr Manufacturing Solutions Architect
NewVaco LLC
Boerne, Texas🇺🇸On-site2 hours agoAgileStakeholder ManagementManufacturing - CH
Solutions Architect I or II, DOE - Healthcare Services
NewCambia Health Solutions
Salt Lake City, Utah🇺🇸$114k - $143k/yrHybrid2 hours agoMicroservicesSQLAWS+4Technology