Sr. Cloud Platform Architect

Relha LLC

Milpitas (CA)

On-site

USD 138,000 - 234,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

KLA seeks a Cloud Architect to design, secure, and govern cloud solutions across AWS, Azure, and GCP. You will drive migration, modernization, and risk reduction while partnering with engineering, security, and operations teams.

The role emphasizes IAM, zero‑trust, IaC, DevSecOps, and cloud governance to deliver scalable, resilient infrastructure with strong security posture. A Bachelor's degree and extensive cloud experience are required; primary location is Milpitas, CA.

Qualifications

  • Bachelor’s degree in Computer Science, Computer Engineering or related field with eight (8) years of related experience.
  • Seven (7) years of hands‑on cloud architecture or engineering experience, including ownership of secure production environments.
  • Proficient in at least one major cloud platform such as Microsoft Azure, AWS, or GCP, with strong cross‑cloud security fundamentals.
  • In‑depth understanding of cloud networking, cloud security, containers, Kubernetes, serverless technologies, and microservices.
  • Confirmed experience with cloud security controls, including IAM, encryption, key management, network security, and zero‑trust principles.
  • Extensive knowledge of cloud governance, monitoring, observability, FinOps, and cost management.
  • Strong understanding of compliance and regulatory frameworks (e.g., NIST, ISO, SOC, CIS, PCI, or similar).
  • Experience embedding security into architecture design, IaC, and CI/CD pipelines (DevSecOps).
  • Exceptional communication, leadership, and customer‑management skills, with the ability to influence engineering, security, and executive stakeholders.]

Responsibilities

  • Design and architect scalable, highly available, resilient, and secure cloud solutions leveraging IaaS and PaaS services across AWS, Azure, and Google Cloud Platform (GCP).
  • Lead cloud migration initiatives, including re‑hosting, re‑platforming, refactoring, and re‑architecting legacy and on‑premises workloads with a strong emphasis on security posture improvement and risk reduction.
  • Drive application and infrastructure modernization programs to improve scalability, performance, security, and operational efficiency.
  • Partner with engineering, platform, and security teams to define cloud‑native reference architectures, security guardrails, and modernization roadmaps.
  • Optimize cloud infrastructure for performance, availability, reliability, security hardening, and cost efficiency.
  • Establish and manage cloud security architectures and governance frameworks, aligned with industry standards and internal security policies.
  • Design and enforce identity‑first security, including IAM strategies, least‑privilege access controls, role‑based access, identity federation, and secrets management.
  • Design and implement secure cloud networking architectures, including VPN, Direct Connect, ExpressRoute, and Cloud Interconnect.
  • Configure and enforce network segmentation, micro‑segmentation, zero‑trust architectures, and advanced network security controls.
  • Secure containers, Kubernetes, serverless, and microservices environments, including image scanning, runtime protection, and policy enforcement.
  • Implement Infrastructure as Code (IaC) using Terraform, AWS CloudFormation, and Azure ARM/Bicep templates with built‑in security, policy, and compliance controls.
  • Design and evolve DevSecOps CI/CD pipelines, integrating security scanning, policy enforcement, and automated compliance validation.
  • Define and implement cloud security observability, including logging, monitoring, alerting, and incident response integration.
  • Evaluate emerging cloud and security technologies, driving continuous improvement of platform security and resilience.
  • Develop, document, and present architecture diagrams, security models, threat assessments, technical documentation, roadmaps, and executive‑level presentations.
  • Define and operate cloud operating models, including security governance, FinOps, tagging standards, resource governance, and operational excellence frameworks

Skills

Cloud architecture
IAM
Zero-trust
DevSecOps
Security by design
FinOps
Network security
Governance

Education

Bachelor’s degree in Computer Science/Engineering or related field

Tools

Terraform
AWS CloudFormation
Azure ARM/Bicep
Kubernetes

Job description

KLA is a global leader in diversified electronics for the semiconductor manufacturing ecosystem. Virtually every electronic device in the world is produced using our technologies. No laptop, smartphone, wearable device, voice-controlled gadget, flexible screen, VR device or smart car would have made it into your hands without us. KLA invents systems and solutions for the manufacturing of wafers and reticles, integrated circuits, packaging, printed circuit boards and flat panel displays. The innovative ideas and devices that are advancing humanity all begin with inspiration, research and development. KLA focuses more than average on innovation and we invest 15% of sales back into R&D. Our expert teams of physicists, engineers, data scientists and problem-solvers work together with the world’s leading technology providers to accelerate the delivery of tomorrow’s electronic devices. Life here is exciting and our teams thrive on tackling really hard problems. There is never a dull moment with us.

Group/Division

The Information Technology (IT) group at KLA is involved in every aspect of the global business. IT’s mission is to enable business growth and productivity by connecting people, process, and technology. It focuses not only on enhancing the technology that enables our business to thrive but also on how employees use and are empowered by technology. This integrated approach to customer service, creativity and technological excellence enables employee productivity, business analytics, and process excellence.

Job Description/Preferred Qualifications

The Cloud Architect will be responsible for designing, implementing, securing, and governing cloud based solutions across multiple cloud platforms, including AWS, Microsoft Azure, and Google Cloud Platform (GCP). This role requires a strong understanding of cloud security architecture, identity and access management, networking, and secure by design architecture principles, in addition to IaaS and PaaS best practices.

Responsibilities:

Design and architect scalable, highly available, resilient, and secure cloud solutions leveraging IaaS and PaaS services across AWS, Azure, and Google Cloud Platform (GCP).

Lead cloud migration initiatives, including re‑hosting, re‑platforming, refactoring, and re‑architecting legacy and on‑premises workloads with a strong emphasis on security posture improvement and risk reduction.

Drive application and infrastructure modernization programs to improve scalability, performance, security, and operational efficiency.

Partner with engineering, platform, and security teams to define cloud‑native reference architectures, security guardrails, and modernization roadmaps.

Optimize cloud infrastructure for performance, availability, reliability, security hardening, and cost efficiency.

Establish and manage cloud security architectures and governance frameworks, aligned with industry standards and internal security policies.

Design and enforce identity‑first security, including IAM strategies, least‑privilege access controls, role‑based access, identity federation, and secrets management.

Design and implement secure cloud networking architectures, including VPN, Direct Connect, ExpressRoute, and Cloud Interconnect.

Configure and enforce network segmentation, micro‑segmentation, zero‑trust architectures, and advanced network security controls.

Secure containers, Kubernetes, serverless, and microservices environments, including image scanning, runtime protection, and policy enforcement.

Implement Infrastructure as Code (IaC) using Terraform, AWS CloudFormation, and Azure ARM/Bicep templates with built‑in security, policy, and compliance controls.

Design and evolve DevSecOps CI/CD pipelines, integrating security scanning, policy enforcement, and automated compliance validation.

Define and implement cloud security observability, including logging, monitoring, alerting, and incident response integration.

Evaluate emerging cloud and security technologies, driving continuous improvement of platform security and resilience.

Develop, document, and present architecture diagrams, security models, threat assessments, technical documentation, roadmaps, and executive‑level presentations.

Define and operate cloud operating models, including security governance, FinOps, tagging standards, resource governance, and operational excellence frameworks

Minimum Qualifications

Bachelor’s level degree in Computer Science, Computer Engineering or related field with eight (8) years of related experience.

Seven (7) years of hands‑on cloud architecture or engineering experience, including ownership of secure production environments.

Proficient in at least one major cloud platform such as Microsoft Azure, AWS, or GCP, with strong cross‑cloud security fundamentals.

In‑depth understanding of cloud networking, cloud security, containers, Kubernetes, serverless technologies, and microservices.

Confirmed experience with cloud security controls, including IAM, encryption, key management, network security, and zero‑trust principles.

Extensive knowledge of cloud governance, monitoring, observability, FinOps, and cost management.

Strong understanding of compliance and regulatory frameworks (e.g., NIST, ISO, SOC, CIS, PCI, or similar).

Experience embedding security into architecture design, IaC, and CI/CD pipelines (DevSecOps).

Exceptional communication, leadership, and customer‑management skills, with the ability to influence engineering, security, and executive stakeholders.

Base Pay Range: $137,800.00 - $234,300.00 Annually
Primary Location: USA-CA-Milpitas-KLA

KLA’s total rewards package for employees may also include participation in performance incentive programs and eligibility for additional benefits including but not limited to: medical, dental, vision, life, and other voluntary benefits, 401(K) including company matching, employee stock purchase program (ESPP), student debt assistance, tuition reimbursement program, development and career growth opportunities and programs, financial planning benefits, wellness benefits including an employee assistance program (EAP), paid time off and paid company holidays, and family care and bonding leave.

Interns are eligible for some of the benefits listed. Our pay ranges are determined by role, level, and location. The range displayed reflects the pay for this position in the primary location identified in this posting. Actual pay depends on several factors, including state minimum pay wage rates, location, job-related skills, experience, and relevant education level or training. We are committed to complying with all applicable federal and state minimum wage requirements where applicable. If applicable, your recruiter can share more about the specific pay range for your preferred location during the hiring process.

KLA is proud to be an Equal Opportunity Employer. We will ensure that qualified individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us at talent.acquisition@kla.com or at +1-408-352-2808 to request accommodation.

Be aware of potentially fraudulent job postings or suspicious recruiting activity by persons that are currently posing as KLA employees. KLA never asks for any financial compensation to be considered for an interview, to become an employee, or for equipment. Further, KLA does not work with any recruiters or third parties who charge such fees either directly or on behalf of KLA. Please ensure that you have searched KLA’s Careers website for legitimate job postings. KLA follows a recruiting process that involves multiple interviews in person or on video conferencing with our hiring managers. If you are concerned that a communication, an interview, an offer of employment, or that an employee is not legitimate, please send an email to talent.acquisition@kla.com to confirm the person you are communicating with is an employee. We take your privacy very seriously and confidentially handle your information.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Cloud Platform Architect
Sr. Cloud Platform Architect

KLA-Belgium • Milpitas (CA)

On-site
USD 138,000 - 234,000
Medical benefits
401(k) with company match
Employee stock purchase program
Sr. Cloud Platform Architect
Sr. Cloud Platform Architect

KLA • Milpitas (CA)

On-site
USD 138,000 - 234,000
Cloud Platform Engineer
Cloud Platform Engineer

Relha LLC • Milpitas (CA)

On-site
USD 110,000 - 187,000
Medical benefits
401(k) matching
ESPP
+1
Forward Deployed Engineer
Forward Deployed Engineer

KLA • Ann Arbor Charter Township (MI)

On-site
USD 111,000 - 191,000
Full-Stack Software Engineer - Remote Services
Full-Stack Software Engineer - Remote Services

KLA-Belgium • Ann Arbor (MI)

Remote
USD 106,000 - 180,000
Medical
Dental
Vision
+3
Principal HPC Architect
Principal HPC Architect

KLA • Milpitas (CA)

On-site
USD 162,000 - 285,000
Medical/dental/vision
401(k) matching
Employee stock purchase plan
HPC Systems Engineer
HPC Systems Engineer

KLA-Belgium • Milpitas (CA)

On-site
USD 136,000 - 232,000
Medical benefits
401(k) matching
Employee stock purchase program
+1
Software Engineering Manager – Remote Services
Software Engineering Manager – Remote Services

KLA-Belgium • Ann Arbor (MI)

Remote
USD 153,000 - 261,000
401(K) including company match
Employee stock purchase plan (ESPP)
Tuition reimbursement
HPC Software Engineer
HPC Software Engineer

KLA • Milpitas (CA)

On-site
Applications Development Manager
Applications Development Manager

KLA • Hillsboro (OR)

On-site
USD 147,000 - 250,000