Haystack
← Back to Jobs
Technology
ED

Principal Cloud Infrastructure Architect

Elevate DigitalUnited States🇺🇸United StatesPosted Sep 16, 2026

Quick Overview

Seniority
Leader
Work mode
Hybrid
Location
United States
Posted
19 hours ago
OracleAWSMachine LearningPCI DSSSOC 2SSOAzureCDKCloudFormation.NETGDPRHIPAALLMPlaywrightPostgreSQLPulumiPythonRailsReactTerraformTypeScript

Job Description

Principal Cloud Infrastructure Architect

Reports To: VP of Engineering

Location: Remote (US)

FLSA: Exempt

Client-Facing Designation: Chief Infrastructure Architect on the launch engagement; equivalent designation on future engagements

Initial Engagement: Enterprise cloud platform build for a regulated healthcare-technology client on Azure, expanding to Enterprise Architecture leadership across Elevate's client portfolio on Azure and AWS

Job Summary

The Principal Cloud Infrastructure Architect is Elevate Digital's most senior technical authority for cloud platform and infrastructure architecture on our largest enterprise engagements. The role launches on a large, regulated enterprise engagement, owning the end-to-end design of a shared, multi-tenant Azure platform, codified as a reusable infrastructure-as-code component library, that hosts the client's entire application portfolio and integrates with the legacy enterprise systems around it. The Principal sets the infrastructure, DevOps, identity, security, and operational patterns every product team inherits as its terms of entry, owns the platform's AI infrastructure (model hosting, inference compute, AI gateways, agent runtimes, and their governance), and sets the standard for how the team applies AI to its own engineering and operations. Operating at the executive-architecture level with the client, the Principal partners with application architecture, security, and delivery leadership to keep the platform buildable, secure, cost-efficient, and ready for long-term managed operations. Beyond the launch engagement, the role is built to lead Enterprise Architecture across Elevate's client portfolio, turning the platform, AI, and modernization patterns proven here into Elevate's reference architecture for future clients on Azure and AWS. In doing so it advances all three of Elevate's pillars: People Advantage by raising the technical bar of the teams around it, Client Growth by making Elevate indispensable to the client's cloud future, and Services Transformation by codifying patterns that carry from one engagement to the next.

Leadership Responsibilities

   Serve as the single accountable architecture owner for the shared cloud platform, directing infrastructure, DevOps, and platform engineers and holding pattern continuity across every workstream in partnership with the Chief Application Architect.

   Represent Elevate as the senior infrastructure voice in client executive and architecture forums, translating technical decisions into terms sponsors and functional owners can act on.

   Mentor and grow engineers and architects on the account and across Elevate's architecture practice, building succession depth so no critical capability rests on one person.

   Lead the platform team's adoption of AI-assisted and agentic engineering, setting the standards for how these tools are used, reviewed, and held accountable so throughput rises without lowering the bar on security or quality.

   Guide platform ownership into a durable operating model and managed-service handoff, and build toward leading Elevate's Enterprise Architecture practice: standardized reference architectures, ADR conventions, and governance across engagements, with the Principal as the senior architecture escalation point as new accounts come on.

   Model Elevate's values and delivery standards in how the team engages the client and one another.

Duties and Responsibilities

Platform & Infrastructure Architecture

   Own the reference architecture for the shared Azure platform: tenant model, subscription and resource-group structure, network topology and hybrid connectivity to on-premises data centers, baseline policy, compute, and the PaaS data services hosting the client application portfolio.

   Own and evolve the Pulumi (or equivalent modern IaC) component library that codifies platform patterns for reuse across every product team and workload, with tenant isolation as a first-class design constraint, and define the environment, promotion, and configuration-management standards (development, staging, production) that workstreams inherit rather than reinvent.

   Author and maintain ADRs, C4 diagrams, and platform standards, promoting them through the ADR registry (Proposed, Under Review, Accepted) under the Architectural Steering Committee with the source repository as system of record, and balance architectural rigor against cost, resilience, and time-to-value across the build-out roadmap.

   Design the hybrid and migration patterns that connect the platform to the client's existing estate (on-premises data centers, mainframe and midrange systems, ERP and systems of record such as SAP and Oracle, legacy middleware and messaging, VM-based workloads), selecting the right path per workload (rehost, replatform, refactor, retire) and keeping legacy and modern systems coexisting safely during transition.

DevOps & Delivery Enablement

   Establish the CI/CD and DevOps patterns application teams adopt as terms of entry: build, test, scan, and deployment workflows with enforced segregation of duties and Release Manager authorization gates. Own the merge gate and ADR-conformance check for all platform infrastructure code and co-sign high-risk and security-impacting decisions before they merge.

   Define the platform observability stack (logs, metrics, traces, alerting baselines) and the reliability targets it is held to: deployment success rate, mean time to recovery, and availability.

   Track infrastructure build-out effort and platform-level delivery against the engagement's phase plan (Foundation, Build-Out, Harden & Prove, Operate & Scale), and partner with delivery leadership so platform dependencies never block application milestones.

Security, Compliance & Operational Readiness

   Own the platform-layer identity architecture: enterprise IdP integration (e.g., Microsoft Entra ID, Okta, Ping, or the client's enterprise SSO), tenant-level RBAC, service-principal and managed-identity governance, and secrets management.

   Architect the multi-framework compliance evidence pipeline, built once and harvested continuously across every workload, supporting SOC 2 Type 1/Type 2, HIPAA, ISO 27001, and HITRUST CSF and extensible to frameworks future clients require (e.g., PCI DSS, GDPR/CCPA), with per-story evidence captured at the ticket level. Set the platform-enforced quality gates that feed it: automated functional validation (e.g., Playwright) in CI, database row-level-security verification (e.g., pgTAP), policy-as-code and IaC security scanning, and consumer-driven contract tests.

   Define the operational-readiness model (monitoring, support, run-book standards), shape the build-to-handover path to managed-service operations, and support the selection, onboarding, and interim operating model for the managed-service providers taking on long-term platform support.

AI Platform, Governance & AI-Enabled Operations

   Architect the platform's AI landing zone as reusable IaC components: Azure AI Foundry and Azure OpenAI model endpoints behind a governed AI gateway, GPU and inference compute for managed and self-hosted open-weight models, vector and retrieval data services, evaluation and AI-observability infrastructure, and hosting patterns for agentic services and MCP tool servers, so every product team inherits AI capability the same way it inherits identity, networking, and observability. Stand up the shared enablement services teams consume (evaluation harnesses, prompt and agent registries, RAG pipelines, AI observability) so AI features ship on governed rails rather than one-off stacks.

   Own the AI infrastructure roadmap and capacity plan: model and GPU capacity forecasting, inference cost and token FinOps, model lifecycle and deprecation management, and build-versus-buy decisions between managed model services and self-hosted models.

   Define and enforce AI guardrails through policy rather than convention: private networking for model endpoints, tenant-isolation and data-boundary controls on model inputs and outputs, PHI/PII handling, prompt and output logging and retention, agent permission and tool-access scoping, and cost governance (token and GPU quotas, chargeback). Extend the compliance evidence pipeline and quality gates to AI systems (model and prompt versioning, evaluation and red-team results, responsible-AI controls) aligned to NIST AI RMF, ISO/IEC 42001, and the EU AI Act where applicable.

   Set the standard for AI-assisted infrastructure engineering: agentic coding tools (e.g., Claude Code, GitHub Copilot, Cursor) for IaC, pipeline, and documentation work, with provenance, review, and security expectations for AI-generated code before it reaches the merge gate.

   Apply AI to operations and modernization with explicit human-in-the-loop boundaries: anomaly detection across logs, metrics, and spend; alert correlation and triage; runbook automation; capacity and cost forecasting; agentic remediation of well-understood incident classes; and, for legacy systems with thin documentation, code and schema discovery, dependency mapping, documentation reconstruction, and migration acceleration, with human review on every change to a system of record.

Cross-Workload Platform Patterns & Client Alignment

   Maintain architectural pattern continuity as new product teams, business units, and migrated legacy workloads are onboarded, governing each through the established change process so it conforms to platform identity, security, observability, and evidence standards.

   Stay conversant with the application stacks the platform hosts (event-sourced .NET services on an actor/grain model, PostgreSQL with row-level security and tenant isolation, React single-page applications, on-premises and edge device integration over HL7 and instrument protocols, and the legacy enterprise systems they integrate with such as ERP, on-premises databases, and message queues), sufficient to design the platform services those workloads inherit rather than to build them.

   Act as the connective architecture authority across siloed client business units so platform decisions land and are retained; advise on shared-services operating and governance models, including how peer business units opt into platform standards as terms of entry; and partner with client product and engineering leadership to prioritize the roadmap and gauge appetite to accelerate.

Enterprise Architecture Practice Leadership

   Translate the platform, AI, and governance patterns proven on the launch engagement into Elevate's reusable enterprise architecture reference for future clients on Azure and AWS, and lead architecture discovery, assessment, and roadmap definition for new enterprise clients across cloud platform, AI infrastructure, and legacy modernization (mainframe, ERP, on-premises data centers), shaping the statements of work that follow.

   Serve as the senior architecture voice in pursuits and executive briefings and as the escalation point for architecture decisions across Elevate's engagements as the portfolio grows.

 

 

Required Competencies and Skills

   Azure & AWS Platform Mastery: Deep, hands-on expertise architecting enterprise-scale, multi-tenant Azure platforms (tenant and subscription structure, networking, identity, policy, PaaS data services hosting multi-application portfolios), with production depth in AWS (Organizations and account structure, IAM, VPC networking, managed data services) sufficient to lead AWS-based platforms on future engagements.

   Infrastructure-as-Code & DevOps: Fluency in modern IaC (Pulumi strongly preferred, in TypeScript or Python; Terraform, Bicep, or CloudFormation/CDK acceptable) and in CI/CD with enforced segregation of duties, release-authorization gates, and IaC merge governance at scale.

   Identity, Secrets & Compliance-by-Design: Command of enterprise IdP integration, tenant-level RBAC, cross-cloud identity federation, service-principal, managed-identity, and IAM-role governance, and secrets management; track record embedding SOC 2, HIPAA, ISO 27001, HITRUST, and comparable controls (e.g., PCI DSS for retail and QSR clients) as a continuous evidence pipeline rather than a retrofit.

   Observability & Reliability: Fluency designing logs, metrics, traces, alerting baselines, and reliability targets (deployment success, MTTR, availability) for a platform operated under managed service.

   AI Platform Architecture & Governance: Working command of Azure's AI services (AI Foundry, Azure OpenAI) and AWS's (Amazon Bedrock, SageMaker): model endpoints and AI gateways, agent runtimes and MCP tool servers, vector and retrieval stores, GPU and inference compute for managed and self-hosted open-weight models, and evaluation and AI-observability tooling, plus the networking, identity, data-boundary, and cost patterns to host AI on a multi-tenant regulated platform. Able to translate NIST AI RMF and ISO/IEC 42001 into platform-enforced controls and reason clearly about PHI/PII exposure, model access, and data boundaries.

   AI-Native Engineering & Operations: Daily fluency with agentic coding and AI-assisted tooling for infrastructure work and the judgment to set team standards for when to trust, review, and reject AI-generated output; experience applying AI to operations (anomaly detection, alert triage, cost anomalies, capacity and token-spend forecasting, runbook automation, agentic remediation) while keeping human approval on production change.

   Application, Legacy & Hybrid Literacy: Working knowledge of event-sourced .NET services, PostgreSQL with RLS, React SPAs, edge and device integration, and the legacy enterprise systems (ERP, mainframe and midrange, on-premises databases, message queues) enterprise workloads depend on; proven ability to design landing zones that coexist with on-premises data centers and legacy systems of record (ExpressRoute or Direct Connect, cross-cloud identity, data replication and integration) and to execute the right modernization path per workload without disrupting the business.

   Architectural Judgment & Executive Presence: Makes and defends high-stakes design decisions, documents them clearly (ADRs, C4), holds pattern continuity across many concurrent workstreams, and translates infrastructure trade-offs into business language with credibility in client executive forums.

   Enterprise Architecture Leadership: Ability to grow from single-engagement platform authority into a practice leader, defining reference architectures, standards, and governance that hold across clients, industries, and clouds, and shaping pursuits and roadmaps for new accounts.

   Coach's Mindset, Cross-Silo Operator, Bias to Structure: A genuine drive to elevate the engineers around them and build succession depth; skill at driving alignment across siloed organizations through connective artifacts and named ownership rather than communication volume; and an instinct for turning ambiguity into repeatable patterns and operating models that outlast any single engagement.

 

Experience and Education

   10+ years in cloud/infrastructure architecture and engineering, including senior ownership of enterprise-scale cloud platforms and demonstrated experience as the top infrastructure architect on a large, multi-workstream engagement or platform program.

   Proven delivery of multi-tenant PaaS or shared-platform environments hosting a portfolio of production applications, with tenant isolation as a core design constraint.

   Hands-on depth with Azure (primary for the launch engagement) and AWS, modern infrastructure-as-code (Pulumi strongly preferred; Terraform, Bicep, or CloudFormation/CDK acceptable), and mature CI/CD ecosystems.

   Experience architecting or hosting production AI/ML, LLM, or agentic workloads on Azure or AWS, including the security, data-boundary, capacity-planning, and cost-governance patterns for those workloads in a regulated setting, and demonstrated day-to-day use of AI-assisted and agentic engineering tools in infrastructure delivery (establishing team norms for AI-generated code and applying AI to operations strongly preferred).

   Direct experience architecting healthcare or other regulated-industry platforms against SOC 2, HIPAA, ISO 27001, and/or HITRUST strongly preferred; experience in other regulated industries (retail and payments, CPG and manufacturing) valued as the role expands to new clients.

   Experience leading enterprise-scale cloud migration or legacy modernization programs (hybrid and multi-cloud connectivity, data migration, coexistence with on-premises systems), plus familiarity with event-driven and event-sourced architectures, PostgreSQL multi-tenancy (row-level security), and the legacy systems those workloads integrate with.

   Experience defining operational-readiness and managed-service (MSP) transition models, and building or leading an architecture practice or center of excellence across multiple clients or business units, strongly preferred.

   Relevant certifications (e.g., Azure Solutions Architect Expert, AWS Solutions Architect Professional, Azure AI Engineer Associate, AWS Machine Learning Specialty) preferred. Bachelor's degree in Computer Science, Engineering, or a related field, or equivalent professional experience.

Similar jobs