Key Responsibilities
- Design and own the target-state cloud architecture compute, networking, data, and security layers for a cloud-native, AI-enabled application platform, and translate it into infrastructure-as-code (Terraform or equivalent).
- Define the Kubernetes, container registry, database, object storage, secrets management, and networking topology, and guide implementation teams through build-out.
- Architect and continuously improve CI/CD pipelines and source-control workflows to automate build, test, and deployment of backend, frontend, and AI-agent services.
- Design identity and access strategy (RBAC/IAM, managed identities, key/secret stores) that enforces least privilege while remaining operable at scale.
- Define the observability strategy — logging, monitoring, tracing, and alerting — for application, container, and AI/LLM runtime metrics.
- Architect the integration of AI/RAG components (knowledge bases, agents, vector search, model endpoints) with the platform's data and API layers.
- Lead root-cause analysis and drive resolution of complex deployment, connectivity, and performance issues across compute, network, and data layers.
- Establish infrastructure standards, reference architectures, and reusable modules; maintain deployment documentation, runbooks, and environment configuration across dev/test/prod.
- Evaluate architecture for cost efficiency, scalability, resilience, and disaster recovery, and recommend improvements.
- Partner with application, security, and AI engineering leads to align infrastructure decisions with product and business goals, and mentor engineers on cloud and DevOps best practices.
- Design and provision the AKS cluster and supporting VNet/subnet topology (private and public subnets for AKS nodes and database segregation).
- Architect the data layer using Azure Database for PostgreSQL (flexible server), Azure Storage Accounts, and Azure Container Registry (ACR).
- Set up Azure Function Apps and an Azure App Service Environment for application and backend API logic, with Azure API Management for secure HTTPS routing.
- Design VNet integration and private endpoints so API Management and Function Apps communicate privately.
- Design DNS and ingress via Azure DNS Zones and Load Balancer, and configure Managed Identities (control plane, CI/CD runners, Function Apps, API Management).
- Design the secrets and credential strategy using Azure Key Vault for application and third-party service credentials.
- Define Azure Monitor logging, metrics, tracing, and container insights, and review the architecture periodically for cost, security, and resilience improvements.
- Architect CI/CD pipelines (e.g., GitHub Actions or Azure DevOps) for build/deploy automation.
Required Technical Skills — Microsoft Azure Compute & Orchestration: AKS, Kubernetes, Azure Virtual Machines (jump host) Data & Storage: Azure Database for PostgreSQL (flexible server), Azure Storage Account Serverless & Integration: Azure Function App, Azure App Service Environment, Azure API Management Networking: VNet, Private Endpoints, Azure DNS Zones, Load Balancer / Ingress Security & Identity: Azure Key Vault, Azure Managed Identity, Azure RBAC, Azure AD SSO CI/CD: GitHub Actions (or equivalent), Infrastructure-as-code tooling, Git-based source control Runtime / Dev Portal: Internal developer portal tooling, Node.js, PostgreSQL