Cloud Architect - Senior Cloud Migration Architect
Occupations:
Computer Systems Engineers/ArchitectsSoftware DevelopersNetwork and Computer Systems AdministratorsComputer Systems AnalystsComputer and Information Systems ManagersIndustries:
Software PublishersComputing Infrastructure Providers, Data Processing, Web Hosting, and Related ServicesWeb Search Portals, Libraries, Archives, and Other Information ServicesContinuing Care Retirement Communities and Assisted Living Facilities for the ElderlyComputer Systems Design and Related ServicesTitle: Cloud Architect - Senior Cloud Migration Architect Location: Lansing, MI (Hybrid Locals Only) Duration: 6 Months Interview Type: In-person Senior Cloud Migration Architect Position Overview We are seeking a Senior Cloud Migration Architect to embed with our development team and lead the AWS platform configuration and CI/CD automation for a large-scale enterprise cloud migration program. The program covers 30+ applications across migration approaches such as Elastic Beanstalk, Amazon EKS, EC2/Cloud VM - to be delivered across multiple sprints. The contractor will own the technical configuration of AWS services for each migration pattern, design and build Azure DevOps (ADO) pipelines that integrate with ArgoCD or Flux for GitOps-driven deployments to EKS, and partner closely with application teams, the AWS Infrastructure Team, and the DBA team to deliver production-ready environments sprint by sprint. This is a hands-on, deeply technical role for someone who can move fast, write production-grade IaC, debug across the stack, and mentor application developers and administrators on cloud-native patterns. Key Responsibilities AWS Platform Configuration Configure and tune AWS Elastic Beanstalk environments for applications across Dev, Test, and Prod, including platform versions, scaling policies, environment variables, and rolling deployment configurationStand up and operate Amazon EKS clusters across Dev/Test/Prod for containerized workloads, including node groups, cluster autoscaling, ingress controllers, and namespace strategyProvision and harden EC2/Cloud VM environments, including AMI selection, instance sizing, OS-level configuration, and patching strategyPartner with the DBA team on Amazon RDS setup for SQL Server and PostgreSQL including parameter groups, subnet groups, backup policies, and Multi-AZ configurationDesign VPC networking, security groups, IAM roles/policies, KMS keys, and Secrets Manager integration following least-privilege principlesBuild infrastructure-as-code (Terraform preferred; CloudFormation acceptable) so every environment is reproducible and auditable CI/CD & GitOps Design and build Azure DevOps build and release pipelines tailored to each migration pattern: EB pattern: source build → artifact → eb deploy to environment per stageEKS pattern: Docker build → ECR push → manifest/Helm chart update → GitOps sync via ArgoCD or FluxEC2 pattern: build → AMI bake or aws-deploy → blue/green or rolling releaseIn-place upgrade pattern: validation, packaging, and controlled deployment to existing servers Implement GitOps using ArgoCD or Flux for EKS workloads - pull-based deployments, automated drift detection, app-of-apps or kustomize/helm patterns, multi-cluster or multi-namespace promotionEstablish promotion strategy across Dev to Test to Prod with appropriate gates, approvals, and rollback mechanismsStandardize pipeline templates (YAML) so application teams can self-onboard new services consistentlyIntegrate static analysis, container scanning (Trivy/ECR scan), SAST/DAST hooks, and artifact provenance into the pipeline Observability & Reliability Configure CloudWatch logs, metrics, alarms, and dashboards for each workloadDefine SLOs, alerting thresholds, and incident response runbooks for production cutover events Documentation & Hand-off Produce architecture decision records (ADRs), runbooks, and operational procedures so workloads can be supported by the long-term operations teamMaintain a clean, versioned IaC repository as the source of truth for all environments Collaboration Work daily with application development teams, AWS Infrastructure Team, DBA Team, and Tech LeadsPair with developers to debug cloud-specific issues (cold starts, container OOMs, RDS connectivity, IAM denials) Required Qualifications 5-6+ years hands-on experience building and operating production workloads on AWS, with deep knowledge of Elastic Beanstalk, EKS, EC2, RDS, VPC, IAM, S3, CloudWatch, and Secrets Manager3+ years hands-on with Kubernetes - production EKS preferred, including Helm, kubectl, ingress (ALB/NGINX), HPA, and troubleshooting pods/services/networkingProduction experience with ArgoCD or Flux - designed app-of-apps structure, managed multi-environment promotion, and resolved GitOps drift in real workloads. This is non-negotiable.Strong Azure DevOps Pipelines (YAML) experience - build pipelines, multi- stage release pipelines, variable groups, service connections, and self- hosted/Microsoft-hosted agents. Equivalent strong experience in another major CI/CD tool (GitHub Actions, GitLab CI, Jenkins) is acceptable if Azure DevOps can be picked up quicklySolid Docker skills - multi-stage builds, image hardening, ECRInfrastructure-as-Code in production: Terraform (preferred) or CloudFormation/CDKDatabase familiarity - comfortable working with DBA teams on RDS (SQL Server and PostgreSQL), connection strings, secrets rotation, and migration cutoverLinux administration (RHEL/Amazon Linux/Ubuntu) and shell scripting (bash)Source control with Git - branching strategies, pull requests, code review disciplineStrong written communication - must produce clear runbooks, architecture diagrams, and PR descriptions Preferred Qualifications AWS certifications: AWS Certified Solutions Architect - Professional or DevOps Engineer - ProfessionalCKA / CKAD (Certified Kubernetes Administrator/Developer)Experience migrating .NET and Java applications from on-premises to AWSExperience operating COTS products in containerized or cloud environmentsExperience with service mesh (Istio, App Mesh) or API gatewaysExposure to HashiCorp Vault, secrets rotation, and certificate managementFamiliarity with DataDog, New Relic, or Splunk in addition to native AWS observabilityExperience with blue/green and canary deployment patterns