Job Description
Cloud Architect
Grade: IS5 | Location: Offshore India | Tower: DCC
Role Summary:
Owns the cloud infrastructure architecture for the SCF platform. Designs and governs the cloud-agnostic Kubernetes-based deployment model, ensuring the platform is portable across AWS (EKS), Azure (AKS), and on premises without code changes. Responsible for infrastructure-as-code strategy, environment provisioning, and cloud cost/security posture.
Key Responsibilities:
- Design the cloud-agnostic infrastructure architecture: Kubernetes cluster topology,
networking, storage, and service mesh (Istio/Linkerd).
- Own Terraform and Helm chart design for reproducible, environment-consistent
deployments across AWS, Azure, and on premises.
- Define and implement environment strategy: Dev, UAT, Staging, and Production-equivalent environments.
- Design cloud-native equivalents for platform components: Aurora/RDS (PostgreSQL),
ElastiCache (Redis), S3/Blob (object store), MSK/Event Hubs (Ka a).
- Establish secrets management architecture using HashiCorp Vault or cloud-native Key Vault equivalents.
- Define auto-scaling policies, resource quotas, and horizontal pod autoscaler configuration to meet NFR targets (
- Collaborate with the DevSecOps team on cloud security posture: IAM policies, network
segmentation, encryption at rest/in transit.
- Produce infrastructure architecture documentation and handover artefacts (Terraform
scripts, Helm charts, runbooks).
Required Skills Experience:
- 10+ years in infrastructure/cloud engineering with 4+ years as a Cloud Architect.
- Expert-level Kubernetes (EKS, AKS, or self-managed) cluster design, networking (CNI),
RBAC, and multi-tenancy.
- Strong Terraform and Helm experience for IaC and GitOps-based deployments.
- Hands-on experience with AWS (EKS, RDS Aurora, ElastiCache, S3, MSK, IAM) or Azure
Equivalents.
- Experience designing cloud-agnostic platforms with abstraction layers for cloud-provider
Services.
- Knowledge of service mesh (Istio or Linkerd), API gateway deployment (Kong), and mTLS
Configuration.
- Familiarity with secrets management (HashiCorp Vault, AWS Secrets Manager, or Azure Key Vault).
- Experience with observability stack: Prometheus, Grafana, OpenTelemetry.
Nice to Have:
- AWS Solutions Architect Associate or Azure Solutions Architect Associate certification.
- Experience with Ka a/Confluent on Kubernetes (MSK, Confluent Cloud, or self-managed).
- Knowledge of FinOps practices and cloud cost optimization for financial services workloads.
- Experience with multi-region, multi-AZ high-availability designs for banking platforms.