Key Responsibilities
- Design and own the target-state cloud architecture compute, networking, data, and security layers — for a cloud-native, AI-enabled application platform, and translate it into infrastructure-as-code (Terraform or equivalent).
- Define the Kubernetes, container registry, database, object storage, secrets management, and networking topology, and guide implementation teams through build-out.
- Architect and continuously improve CI/CD pipelines and source-control workflows to automate build, test, and deployment of backend, frontend, and AI-agent services.
- Design identity and access strategy (RBAC/IAM, managed identities, key/secret stores) that enforces least privilege while remaining operable at scale.
- Define the observability strategy — logging, monitoring, tracing, and alerting — for application, container, and AI/LLM runtime metrics.
- Architect the integration of AI/RAG components (knowledge bases, agents, vector search, model endpoints) with the platform's data and API layers.
- Lead root-cause analysis and drive resolution of complex deployment, connectivity, and performance issues across compute, network, and data layers.
- Establish infrastructure standards, reference architectures, and reusable modules; maintain deployment documentation, runbooks, and environment configuration across dev/test/prod.
- Evaluate architecture for cost efficiency, scalability, resilience, and disaster recovery, and recommend improvements.
- Partner with application, security, and AI engineering leads to align infrastructure decisions with product and business goals, and mentor engineers on cloud and DevOps best practices.
- Design and provision the EKS cluster, node groups, and supporting VPC/subnet topology.
- Architect the data layer using RDS (PostgreSQL) and DynamoDB, along with S3 buckets for build artifacts, infrastructure-as-code state, and knowledge-base content.
- Set up ECR repositories, Lambda functions, and private API Gateway endpoints for application, agent, and metrics services.
- Design DNS and ingress via Route 53 and Application Load Balancer, and configure required VPC endpoints (STS, ECR, RDS, Lambda, Secrets Manager, Bedrock, S3, AOSS, etc.).
- Design and implement IAM roles and policies for Bedrock agents, build/pipeline services, Lambda, and knowledge-base access, following least‑privilege scoping.
- Architect the integration of Amazon Bedrock (Guardrails, Knowledge Bases, Agents) and OpenSearch Serverless / Aurora PostgreSQL for RAG and semantic search.
- Define CloudWatch logging/monitoring and dashboards for platform and AI metrics, and review the architecture periodically for cost, security, and resilience improvements.
Required Technical Skills Amazon Web Services (AWS)
Compute & Orchestration: EKS, EC2 (jump host), Kubernetes Data & Storage: RDS (PostgreSQL), DynamoDB, S3, Aurora PostgreSQL (vector store, optional) Serverless & Integration: AWS Lambda, Amazon API Gateway, Amazon Route 53 AI / ML: Amazon Bedrock (Guardrails, Knowledge Bases, Agents), OpenSearch Serverless (AOSS), SageMaker Security & Identity: IAM roles/policies, AWS Secrets Manager, SSM Parameter Store, SSO (e.g., Azure AD / AWS Cognito) CI/CD: AWS CodePipeline, AWS CodeBuild, AWS CodeConnections, Git-based source control Observability: CloudWatch, Container Insights, LLM/AI observability tooling