Maryland Benefits (MD Benefits) is a dynamic, cloud-based platform. This enterprise-wide digital service allows organizations to build, test, host, operate, and integrate mission-driven applications, data, and emerging technologies. MD Benefits offers cloud-based Platform-as-a-Service (PaaS) capabilities, a shared data architecture, and product development services, all developed by the State of Maryland to help multiple agencies deliver and manage health, human, and social service benefits and programs. On July 1, 2025, the operation of the MD Benefits shared platform and statewide applications transitioned from the Department of Human Services (DHS) to the Department of Information Technology (DoIT).
***This is a contractual position, with limited benefits***
***All hires need to be eligible to work in the U.S., either as a U.S. Citizen or those who have a Permanent Resident or green card, as the state of Maryland does not have the ability to sponsor employees***
***Applicants are required to submit an up-to-date and accurate resume.***
Main Purpose
The Cloud Infrastructure Architect, reporting to the Director of Infrastructure and Cloud Services, is responsible for designing, standardizing, and governing the enterprise's cloud infrastructure architecture. The primary focus of this role is defining scalable, secure, and resilient architectures across compute, storage, networking, and platform services, and establishing the reference architectures, patterns, and guardrails that engineering teams build against. Working at the intersection of engineering implementation and operations, this individual sets the technical direction for the cloud platform, makes sound tradeoffs across performance, reliability, security, and cost, and serves as the senior technical authority for infrastructure design decisions.
Position Duties
- Cloud Architecture and Design: Lead the design of scalable, secure, and resilient cloud infrastructure architectures spanning compute, storage, networking, container orchestration, and platform services.
- Solution Design: Translate business goals and requirements into architectural diagrams, blueprints, and infrastructure-as-code (IaC) models that engineering teams can implement, recommending appropriate cloud service providers, operating models, and integration frameworks.
- Reference Architectures and Standards: Establish and maintain reference architectures, design patterns, technical standards, and guardrails that engineering teams build against to ensure consistency and quality.
- Infrastructure as Code and Automation: Define the infrastructure-as-code strategy and drive automation of provisioning, configuration, and deployment across environments.
- Landing Zones and Multi-Cloud Strategy: Design and govern cloud landing zones, account and subscription structure, and multi-cloud or hybrid architectures, including connectivity to on-premises environments.
- Cloud Strategy and Migration: Lead efforts to migrate legacy on-premises workloads to public or hybrid cloud environments while minimizing downtime and business disruption, developing migration roadmaps, conducting risk assessments, and using automated tools to streamline the transition.
- Network and Security Architecture: Treat security as an architectural constraint from the outset, architecting secure network topologies and segmentation, Identity and Access Management (IAM) policies, network boundaries, encryption and key management, zero-trust principles, and defense-in-depth controls that meet enterprise security and compliance requirements.
- Reliability and Performance: Architect for high availability, disaster recovery, backup, scalability, and performance, defining service-level objectives (SLOs), capacity planning approaches, and designs that accommodate future growth.
- Monitoring and Optimization: Continuously monitor system health, performance, and usage using monitoring, analytics, and application performance monitoring (APM) tools; predict capacity needs; troubleshoot issues; and identify bottlenecks and opportunities for automation.
- Cost Optimization: Forecast resource needs, evaluate service pricing models, and implement strategies to prevent over-provisioning, providing guidance on right-sizing, capacity, and optimization in partnership with engineering and finance.
- Governance and Compliance: Ensure architectures meet security, compliance, and regulatory requirements (such as GDPR or HIPAA where applicable), conduct regular audits of cloud environments for vulnerabilities, participate in architecture review boards, and collaborate with security teams on threat and incident response.
- Cross-Functional Collaboration: Act as the primary technical liaison between infrastructure and engineering teams (DevOps engineers, SREs), business units, executives, and external vendors, presenting technical concepts to both technical and non-technical audiences and aligning architecture with business needs.
- Technical Leadership and Mentorship: Serve as the senior technical authority for infrastructure design, review engineering designs, and mentor engineers across teams.
- Documentation: Create and maintain comprehensive architecture documentation, diagrams, and architecture decision records (ADRs).
Minimum Qualifications
- Bachelor's degree in Computer Science, Information Technology, Engineering, or a related field. (Five years of relevant professional experience may be substituted for a degree).
- 7 to 10 years of experience in cloud or infrastructure engineering, including public cloud, DevOps, and modern application deployment, with demonstrated experience in an architecture or senior design role.
- Deep, hands-on expertise with a major cloud platform (AWS, Azure, GCP) and its core compute, storage, networking, and identity services, along with virtualization and API concepts.
- Strong understanding of networking and security concepts including TCP/IP, DNS, VPNs, firewalls, load balancing, and content delivery networks (CDNs).
- Proven experience with infrastructure-as-code such as Terraform, CloudFormation, or Pulumi.
- Understanding of microservices architecture, containerization, and CI/CD pipelines (e.g., Docker, Kubernetes, and modern delivery pipelines).
- Experience designing for high availability, disaster recovery, and scalability.
- Excellent troubleshooting and problem-solving skills including root cause analysis and failover design.
- Strong communication and interpersonal skills.
- Ability to work effectively in a fast-paced, high-pressure environment.
Preferred Qualifications:
- Professional-level cloud architect certification (e.g., AWS Solutions Architect Professional, Microsoft Azure Solutions Architect Expert, or Google Professional Cloud Architect).
- Experience with multi-cloud or hybrid cloud architectures.
- Experience operating container platforms at scale (e.g., Kubernetes) and applying platform engineering practices.
- Working knowledge of distributed systems fundamentals including scalability, availability, latency, and fault tolerance.
- Experience designing cloud landing zones and governance frameworks.
- Exposure to security and compliance frameworks (e.g., SOC 2, ISO 27001, FedRAMP).
- Familiarity with zero-trust security models and identity federation.
- Experience with configuration management, monitoring, and application performance monitoring (APM) tools.
- Scripting and automation experience (e.g., Python, PowerShell, Bash, JSON, or Go).
- Additional cloud, IAM, or networking certifications (e.g., Microsoft Identity and Access Administrator (SC-300), Certified Kubernetes Administrator, Okta Certified Professional, or Cisco CCNA).