Lead Architect, GenAI Platform & Agentic AI

Bessemer Trust Company

$170K — $220K *
Enterprise Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years in platform engineering or similar role with hands-on technical leadership experience.
  • Deep expertise in AWS services including IAM, CloudFormation, and API Gateway.
  • Strong skills in AWS CDK or equivalent infrastructure-as-code frameworks.
  • In-depth knowledge of IAM security principles and CI/CD security practices.
  • Experience in enterprise authentication mechanisms, including OIDC/OAuth 2.0 and SAML.
  • Production experience with secure cloud platforms and stateful data layers such as graph databases.
  • Ability to identify architectural gaps and deliver improvements across teams.

Responsibilities

  • Own the delivery of the firm’s GenAI priorities and architectural evolution.
  • Lead the development of the GenAI platform's reference cloud architecture on AWS.
  • Create reusable reference implementations using infrastructure-as-code patterns.
  • Design and implement secure deployment models across multiple environments.
  • Define operating patterns for data layers, ensuring secure access and performance.
  • Collaborate with security teams to establish governance and audit standards.
  • Troubleshoot platform issues and mentor engineers in architectural practices.

Benefits

  • 401(k) program with profit-sharing contribution.
  • Medical, dental, and vision coverage.
  • Life and disability insurance.
  • Paid holidays, vacation, and sick time.
  • Participation in incentive compensation plans.
Full Job Description
Lead Architect, GenAI Platform & Agentic AI

About the Role

As a Lead GenAI Platform Architect on the AI Platform & Infrastructure Engineering team, you will be responsible for the end-to-end architecture of the firm's Generative AI platform, while staying deeply hands-on in the design, execution, and delivery of GenAI initiatives. You will set technical directions for the firm's GenAI platform while also building the first reference implementations that other engineering teams will adopt. You will define the evolving GenAI reference architecture, codify secure delivery patterns, write reusable infrastructure constructs, design IAM and deployment role chains, provision agent runtimes and data layers, and resolve the platform-level issues.

You will build a strong understanding of the firm's existing technology platform, identify architectural and control gaps, and establish the secure paved road for GenAI delivery: reusable infrastructure patterns, guardrails, runbooks, operational standards, and reference implementations that allow teams to move faster without compromising security, resilience, auditability, or regulatory expectations. You will serve as a key technical authority for GenAI platform infrastructure, help define the firm's Enterprise Architecture for GenAI in collaboration with application engineering, Information Security and platform operations to define secure, scalable, and enterprise-ready delivery patterns.

Job Responsibilities
  • Contribute and own the successful delivery of the firm's GenAI priorities.
  • Own and evolve the reference cloud architecture for the firm's GenAI platform on AWS, including Amazon Bedrock, AgentCore runtimes, agent gateways, shared data layers, and secure integration patterns.
  • Build reusable reference implementations using AWS CDK and infrastructure-as-code patterns so engineering teams can adopt approved GenAI capabilities consistently and securely.
  • Design and implement secure multi-account, multi-environment, and multi-repo deployment patterns, including least-privilege IAM, OIDC federation, role chains, permission boundaries, and clear separation of deployment and runtime roles in partnership with Infrastructure teams.
  • Provision and define operating patterns for platform data layers, including graph databases, vector search capabilities, Redis, semantic caching, secure access, backup/restore, scaling, and performance tuning.
  • Partner with Infrastructure teams and Information Security to define guardrails, audit logging, governance standards, and security-review patterns for AI and LLM workloads.
  • Own and improve CI/CD, container deployment, networking, observability, rollback, drift detection, and operational validation patterns across GenAI platform components.
  • Troubleshoot complex platform issues, produce runbooks and design guidance, and mentor senior engineers through architecture, security, and operational design reviews.

Required Qualifications
  • 10+ years of experience in platform engineering, cloud infrastructure, DevOps, or platform ownership, including experience in a principal, staff, lead architect, or equivalent hands-on technical leadership role.
  • Deep hands-on AWS experience across IAM, CloudFormation, Lambda, API Gateway, CloudWatch, SSM, Secrets Manager, ECR, VPC, Cognito, and related enterprise platform services.
  • Strong experience with AWS CDK or equivalent infrastructure-as-code frameworks, including reusable constructs, shared bootstrapping, multi-account deployments, and multi-environment delivery patterns.
  • Expertise in IAM least privilege and CI/CD security, including OIDC federation, short-lived credentials, role assumption, trust policies, permission boundaries, pass-role controls, and deployment/runtime role separation.
  • Understanding of enterprise authentication and authorization patterns using Okta, including OIDC/OAuth 2.0 and SAML federation, MFA, SSO, group-to-role mapping, token validation, and integration with AWS IAM Identity Center, Cognito, API Gateway, and GenAI agent runtimes.
  • Production experience designing and operating secure cloud platforms with stateful data layers such as graph databases, vector stores, Redis, OpenSearch, or equivalent systems.
  • Ability to assess an existing platform, identify architectural and security gaps, deliver practical improvements with limited oversight, and communicate effectively across engineering, architecture, security, and business stakeholders.

Preferred Qualifications
  • Hands-on experience with Amazon Bedrock, Amazon Bedrock AgentCore, or comparable GenAI agent orchestration and runtime platforms.
  • Experience securing GenAI platforms, including agent-to-agent communication, service-to-service authentication, tool access, runtime isolation, and API-driven LLM systems.
  • Experience integrating graph databases, vector stores, and Redis-like systems into GenAI architectures for knowledge graphs, retrieval, semantic caching, session memory, or rate limiting.
  • Experience with enterprise guardrails, audit logging, AI governance, model risk, evaluation, and security-review processes for AI workloads in regulated environments.
  • Familiarity with private subnet architectures, VPC endpoints, AWS PrivateLink, OpenTelemetry, CloudWatch, and network-aware deployment patterns for Lambda, Bedrock, data stores, and containerized GenAI runtimes.

The base salary range for this position is $170,000 - $220,000 per year. This range reflects the minimum and maximum base salary we reasonably expect to pay for this role. In addition, this position may be eligible to participate in the relevant business unit's incentive compensation plan, and other compensation programs as applicable. Eligible employees may participate in a 401(k) program with a generous profit-sharing contribution, medical, prescription dental, and vision coverage; life insurance; disability coverage; paid holidays; vacation; and sick time, subject to plan terms and Company policies.

Similar Jobs

More Jobs at Bessemer Trust Company

More Enterprise Technology Jobs

Find similar Lead Architect, GenAI Platform & Agentic AI jobs: