Cloud Architect – Azure & AWS
| Department: |
Information Technology |
| Reports To: |
Senior Director, IT Infrastructure |
| Location: |
Offshore |
Role Overview
The Cloud Architect is the technical authority for Therabody’s dual-cloud
environment, responsible for designing, governing, and evolving production
infrastructure across Microsoft Azure and Amazon Web Services (AWS). This is
a hands-on architect role - the person in this seat sets the architectural
direction and also builds, codes, and operates reference implementations
alongside the engineering team.
The role owns cloud reference architectures, landing zones, network
topology, identity and access models, DNS strategy, and cost governance
across both platforms. It partners closely with Security Operations (SOC),
Infrastructure, Business Applications, and Application Development teams to
ensure cloud platforms are well-architected, secure, cost-efficient, and
aligned with enterprise and business objectives.
Certifications are required. Candidates must hold current professional-level
cloud certifications in both Azure and AWS, and must be able to demonstrate
hands-on, production-grade experience - not just advisory or design-only
exposure.
Key Responsibilities
Cloud Architecture & Engineering (Azure & AWS)
-
Define and own reference architectures, landing zones, and platform
blueprints across Azure and AWS.
-
Design and implement production workloads spanning compute, networking,
storage, databases, containers, and serverless services in both clouds.
-
Lead cloud migration, modernization, and workload placement decisions,
including cross-cloud and hybrid scenarios.
-
Ensure parity in governance, reliability, security, and operational
standards across Azure and AWS where appropriate.
-
Write and maintain production Infrastructure as Code (Terraform required;
Bicep, ARM, and CloudFormation as applicable).
-
Act as the technical escalation point for complex cloud architecture and
engineering issues.
Identity, Access & Governance
-
Design enterprise IAM models across Azure (Entra ID) and AWS (IAM, IAM
Identity Center).
-
Implement least-privilege access using role-based, attribute-based, and
group-based controls.
-
Architect federation, SSO, and conditional access patterns integrated with
Microsoft Entra ID.
-
Lead periodic access reviews, governance processes, and policy-as-code
enforcement.
-
Align cloud access controls with enterprise identity standards and audit
requirements.
Network, DNS, Domains & Certificates
-
Architect cloud networking including VNets/VPCs, transit networking,
private endpoints, peering, and hybrid connectivity.
-
Own and govern DNS and domain services across Amazon Route 53, GoDaddy,
Marcaria, and Microsoft tenant DNS records.
-
Manage the full domain lifecycle: acquisition, registration, renewals,
transfers, and decommissioning.
-
Coordinate certificate strategy and renewals with Security and
Infrastructure teams.
-
Maintain accurate, current DNS, network, and domain documentation.
Security Collaboration (SOC-Partnered)
-
Translate SOC and Security Architecture requirements into cloud-native
controls and guardrails.
-
Partner with the SOC on logging, monitoring, alerting, and SIEM
integration across both clouds.
-
Support security investigations by providing cloud context, forensic
access, and remediation.
-
Participate in security reviews, audits, and certifications as the cloud
subject-matter expert.
-
Ensure cloud services remain continuously compliant with approved security
baselines.
Cost Management & FinOps
-
Own dual-cloud cost visibility, forecasting, chargeback/showback, and
optimization across Azure and AWS.
-
Drive continuous cost optimization through rightsizing, commitment
management (Azure Reservations/Savings Plans, AWS Reserved
Instances/Savings Plans), and architectural improvements.
-
Partner with Finance and IT leadership on cloud budget planning and ROI
reporting.
-
Establish FinOps practices and cost guardrails as part of the landing
zone.
Operations, Reliability & Team Enablement
-
Define SLOs, runbooks, and incident response patterns for cloud workloads.
-
Act as escalation for cloud-related incidents, changes, and post-incident
reviews.
-
Mentor cloud engineers and upskill the broader IT team on Azure and AWS
best practices.
-
Participate in change management and on-call rotations as required.
-
Produce and maintain clear architecture diagrams, design documents,
standards, and operational runbooks as the source of truth for Therabody’s
cloud environment.
Required Qualifications
-
6+ years of cloud infrastructure or platform engineering experience, with
at least 2+ years in a cloud architect capacity.
-
Hands-on, production experience across both major clouds: Microsoft Azure
and Amazon Web Services (AWS) - candidates must have built and operated
workloads, not just designed them.
-
Current, active professional/expert-level cloud certification in BOTH of
the following (required):
-
Microsoft Certified: Azure Solutions Architect Expert
-
AWS Certified Solutions Architect – Professional (or AWS Certified
DevOps Engineer – Professional)
-
Deep expertise in cloud networking, IAM, identity federation, and platform
services in both Azure and AWS.
-
Production experience with Infrastructure as Code - Terraform required;
Bicep, ARM, and/or CloudFormation preferred.
-
Experience designing and operating landing zones, hub-and-spoke
topologies, and enterprise-scale governance.
-
Experience managing DNS and domains across multiple registrars and
platforms, including Amazon Route 53.
-
Strong troubleshooting and executive-level communication skills, with
demonstrated ability to produce high-quality architecture diagrams and
technical documentation (Lucidchart).
-
Proven ability to lead cross-functional initiatives and work effectively
in an offshore, globally distributed team.
Preferred Qualifications
-
Additional certifications: AWS Security Specialty, AWS Advanced Networking
Specialty, Azure Security Engineer, Azure Network Engineer, HashiCorp
Certified: Terraform Associate, or CKA/CKAD.
-
Experience with Kubernetes at scale (AKS, EKS) and service mesh
technologies.
-
Experience with DevOps, CI/CD, and GitOps practices (Azure DevOps, GitHub
Actions, Argo CD, Flux).
-
Familiarity with cloud AI/ML service infrastructure (Azure OpenAI, AWS
Bedrock) and associated cost and governance considerations.
-
Experience supporting SaaS and application hosting platforms at enterprise
scale.
-
Experience with cloud cost management tools (native, plus third-party such
as CloudHealth, Apptio, or Vantage).
-
Familiarity with compliance frameworks (SOC 2, ISO 27001, PCI-DSS) as they
apply to cloud environments.
-
Exposure to consumer products, e-commerce, or DTC technology environments.