D365/Power Platform/Azure - Washington, DC
Role and Responsibilities Client requires a senior, hands-on Solution Architect resource to serve as the technical design authority for STAAND (Stronger Together Against Abuse and Neglect in DC), the District's federally certified Comprehensive Child Welfare Information System.
Need a senior, deeply hands-on Solution Architect resource to serve as the technical design authority for STAAND (Stronger Together Against Abuse and Neglect in DC), the District's federally certified Comprehensive Child Welfare Information System (CCWIS).
- 3.1 Solution and Platform Architecture
- Own and maintain the authoritative STAAND architecture: logical and physical data models, Dataverse table and relationship design, solution segmentation, environment strategy, and integration topology.
- Personally build in the platform - model-driven app configuration, plug-ins and custom APIs (C#/.NET), PCF controls, TypeScript/JavaScript client extensions, Power Fx, and plug-in pipeline optimization.
- Establish and enforce architecture standards, design patterns, naming conventions, and technical debt registers across all modules and portals.
- Chair design authority review for significant changes; sign off on solution designs before build.
- Diagnose deep platform issues: performance degradation, API and service-protection limits, plug-in execution ordering, solution layering conflicts, storage growth, portal rendering.
- Maintain architecture artifacts sufficient to satisfy CCWIS review, federal audit, and District IT governance.
- 3.2 Cross-Cloud Architecture: GCC and Commercial Azure
- Design, document, and harden the boundary between the GCC Dynamics/Power Platform tenant and Azure commercial-cloud services.
- Define what data may traverse that boundary, in what form (de-identified, tokenized, aggregated, or full record), under what authorization, and with what logging - including explicit architectural boundaries for protected data categories such as Medicaid Enrollment.
- Implement cross-tenant identity, managed identities, service principals, Key Vault secret lifecycle, private networking, and API gateway patterns.
- Maintain a defensible position on data residency and FedRAMP authorization boundaries for every commercial-cloud service in use, and present that position to auditors and federal reviewers.
- 3.3 AI and Agentic Development
- Serve as hands-on technical lead for CFSA's AI capability, including CORA and its expansion into agentic workflows.
- Design, build, evaluate, and productionize agents in Azure AI Foundry and Copilot Studio: tool and function calling, orchestration and multi-agent patterns, grounding and retrieval over Dataverse and document stores, prompt and context engineering, structured output, and human-in-the-loop checkpoints.
- Own AI evaluation discipline: golden datasets, automated evals, groundedness and hallucination measurement, regression testing on model or prompt changes, latency and cost benchmarking, controlled rollout.
- Manage the AI model lifecycle - track model releases and deprecations, run comparative evaluation before adopting a new model, execute migrations without regression to worker-facing quality.
- Implement responsible AI controls appropriate to a child welfare setting: content safety, PII/PHI handling, bias and fairness testing, explainability, audit logging of AI-influenced actions, and clear framing of AI output as decision support rather than decision making.
- Support predictive and analytic capability aligned to agency mission priorities, ensuring models are validated, monitored for drift, and governed.
- Build reusable AI platform assets - prompt libraries, agent templates, evaluation harnesses, observability dashboards.
- 3.4 Application and Platform Security
- Own the security architecture of STAAND end to end; serve as technical counterpart to the agency ISSO, OCTO security, and District privacy officials.
- Apply and evidence compliance with OCTO IT policies (octo.dc.gov/page/it-policies), NIST SP 800-53, FISMA, FedRAMP, HIPAA, 45 CFR 1355 (CCWIS), Title IV-E confidentiality, and District data protection law including DC Code a7 28-3851 et seq. breach notification obligations.
- Design and enforce least privilege: Dataverse business unit and role architecture, row/column-level security, portal web roles and table permissions, privileged access management, separation of duties for finance and eligibility functions.
- Lead secure SDLC: threat modeling, secure code review, static and dynamic analysis, dependency and supply-chain scanning, secrets management, remediation tracking with severity-based SLAs.
- Support penetration tests, vulnerability assessments, and audit response; own STAAND-assigned POA&M items.
- Define AI-specific security requirements: prompt injection defenses, tool-permission scoping, data exfiltration prevention, agent action auditing.
- Contribute to incident response, continuity, and disaster recovery planning; validate RTO/RPO through periodic exercises.
- 3.5 Continuous Improvement and Release Management
- Own the STAAND change pipeline from enhancement request through design, build, test, release, and post-release verification, including published release notes and coordination with the CISA training organization.
- Plan and execute against Microsoft's Dynamics 365 biannual release waves and Power Platform service updates: early-access testing in a dedicated environment, deprecation and breaking-change assessment, and a documented impact and remediation plan per wave.
- Evaluate new platform, Azure, and AI capabilities against the STAAND roadmap; run structured proofs of concept and make evidence-based adopt / trial / hold / retire recommendations.
- Maintain a rolling multi-year technical roadmap balancing stabilization, platform health, security, federal compliance, and innovation.
- Drive performance, reliability, and cost optimization - capacity and license consumption, Azure spend, storage tiering, API efficiency.
- Advance DevOps maturity: source-controlled solutions, automated build and deploy pipelines, environment refresh, automated regression testing, release quality metrics.
- Maintain and report the technical issues and risk register with mitigation owners and timelines.
- 3.6 Data, Interoperability, and Federal Reporting
- Own the data architecture supporting AFCARS, NCANDS, NYTD, CFSR, and Title IV-E reporting, including lineage, quality rules, exception handling, and submission validation.
- Design and maintain bi-directional exchanges with District and external partners consistent with CCWIS interoperability requirements.
- Establish automated data quality controls, duplicate person detection and merge integrity, and reconciliation with legacy records.
- 3.7 Stakeholder and Senior Leadership Engagement
- Translate between social work practice and technical architecture; observe real workflow with intake workers, investigators, case managers, placement staff, and fiscal teams before designing for it.
- Brief the CFSA IT Steering Committee Members, CIO, STAAND Product Leadership, OCTO leadership, Council oversight staff, court monitors, and ACF/Children's Bureau reviewers, calibrating to each audience.
- Serve as principal technical liaison to Microsoft (Industry Solutions Delivery, Customer Success, product groups) and to implementation and support vendors; hold them to architectural and quality standards.
- Author decision memos, architecture decision records, briefing decks, and federal reporting content requiring minimal editing.
- Mentor CFSA staff and other contract resources; build internal capability and reduce single-point-of-failure dependency.