Job Summary
The Enterprise Managed Container Platform Architect will define, standardize, and mature a secure, resilient, scalable, and cost-effective managed container platform across AWS EKS, AWS ECS, and related cloud-native technologies. The role will establish enterprise architecture, standards, design patterns, guardrails, workload placement guidance, and operating models to improve security and compliance, automate platform lifecycle management, reduce platform fragmentation, and accelerate application delivery. The architect will partner with enterprise architecture, cloud engineering, platform engineering, security, risk, application development, DevOps, infrastructure, operations, and business-unit technology teams to guide container platform adoption and ensure consistent operational practices. Pasted markdown
Key Responsibilities
• Define the enterprise architecture approach for managed container platforms spanning EKS, ECS, Kubernetes, container registries, platform tooling, and supporting cloud services.
• Create and maintain standards, reference architectures, design patterns, guardrails, and architecture review criteria for secure and reliable container adoption.
• Lead the architectural design of the managed container platform and guide designs through Architecture Review Board review and approval.
• Define EKS versus ECS placement strategies and help application teams select the appropriate platform for containerized workloads.
• Design standardized EKS clusters using infrastructure as code, reusable Terraform modules, CI/CD pipelines, Helm, and GitOps-based configuration management.
• Define platform patterns for networking, ingress, DNS, identity, role-based access control, secrets management, certificates, image management, autoscaling, and policy enforcement.
• Guide the selection and implementation of container management, image registry, backup and disaster recovery, networking, security, policy, monitoring, logging, tracing, and observability technologies.
• Establish controls for vulnerability scanning, image signing, admission control, trusted image sources, network policies, patching, upgrades, and compliance.
• Define patterns for automated platform upgrades, Kubernetes lifecycle management, cluster add-on maintenance, base-image maintenance, and removal of unsupported or extended-support components.
• Create the target operating model and responsibility matrix for platform engineering and application development teams.
• Provide architecture guidance from strategy and design through implementation, migration, production readiness, and ongoing operations.
• Define observability patterns using metrics, logs, traces, health monitoring, alerting, and operational dashboards.
• Develop resiliency, high-availability, backup, restore, and disaster-recovery standards for clusters, configurations, persistent data, and business-critical workloads.
• Partner with application teams to define containerization requirements, deployment patterns, resource requests and limits, autoscaling, configuration, release strategies, and application monitoring.
• Drive cost optimization through cluster right-sizing, autoscaling, resource governance, removal of unused infrastructure, standardized tooling, and cost visibility.
• Facilitate architecture governance discussions and communicate architecture decisions, trade-offs, risks, dependencies, and recommendations to stakeholders.
• Mentor architects, platform engineers, DevOps engineers, and application teams on enterprise-ready Kubernetes and container design and operating practices. Pasted markdown
Required Qualifications
• Bachelor's degree in Computer Science, Engineering, Information Systems, or a related field, or equivalent experience.
• 8+ years of experience in enterprise architecture, solution architecture, cloud architecture, platform engineering, DevOps, software engineering, infrastructure engineering, or technology delivery.
• Hands-on experience designing, implementing, or governing enterprise container platforms using AWS EKS, AWS ECS, Kubernetes, Docker, or comparable technologies.
• Experience creating architecture standards, reference architectures, reusable design patterns, platform guardrails, architecture decision records, and review criteria.
• Strong experience with infrastructure as code and automation, including Terraform, CI/CD pipelines, Helm, GitOps, and configuration management.
• Strong understanding of Kubernetes architecture, cluster lifecycle management, networking, ingress, DNS, autoscaling, scheduling, storage, secrets, certificates, and workload deployment patterns.
• Experience with container security, vulnerability management, image scanning and signing, trusted registries, admission control, role-based access control, network policies, and software supply-chain security.
• Experience designing monitoring, logging, metrics, tracing, alerting, health monitoring, and operational support capabilities for cloud-native platforms.
• Experience defining high availability, resiliency, backup, restore, and disaster-recovery strategies for container platforms and stateful workloads.
• Experience with cloud cost optimization, resource governance, capacity management, showback or chargeback, and operational efficiency.
• Experience working within Agile, DevOps, SDLC, architecture governance, technology risk, change management, incident management, and production support practices.
• Strong communication, facilitation, analytical, documentation, and stakeholder management skills.
• Ability to explain complex platform architecture topics to executive, technical, security, operational, and application audiences. Pasted markdown
Preferred Qualifications
• Experience in financial services, insurance, banking, healthcare, or another highly regulated industry.
• AWS certifications related to Solutions Architecture, DevOps Engineering, Security, Advanced Networking, or Kubernetes, or comparable cloud and platform certifications.
• Deep experience with AWS EKS and ECS, including workload placement, cluster upgrades, managed node groups, Fargate, Amazon ECR, IAM integration, load balancing, and cloud-native observability.
• Hands-on experience with Terraform AWS modules, Harness or comparable CI/CD and infrastructure automation platforms, Argo CD, Helm, and GitOps operating models.
• Experience with Cilium or comparable container networking and security platforms, including network policy, load balancing, service connectivity, and traffic observability.
• Experience with Karpenter or comparable autoscaling and cluster-capacity optimization technologies.
• Experience with Rancher, Red Hat OpenShift, Plural, or comparable centralized container-management platforms.
• Experience with Amazon ECR, Harbor, or comparable enterprise container registries, including proxy caching, image replication, signing, scanning, and policy enforcement.
• Experience with Velero or comparable Kubernetes backup, recovery, and migration tools.
• Experience with Kyverno, Open Policy Agent, or comparable policy-as-code and admission-control technologies.
• Experience with OpenTelemetry, Prometheus, Grafana, Fluent Bit, Filebeat, Logstash, or comparable monitoring, logging, and tracing technologies.
• Experience with enterprise certificate and secrets management platforms, including AWS Secrets Manager, cert-manager, Keyfactor, Vault, or comparable technologies.
• Experience establishing platform engineering product models, internal developer platforms, self-service capabilities, operating models, and communities of practice.