08 Aug
|
SourceFuse Technologies
|
Mumbai
08 Aug
SourceFuse Technologies
Mumbai
Role Overview:
The candidate will serve as a senior cloud consultant/architect embedded within a large FSI customer s technology organization, supporting cloud transformation journey. The role demands:
- Deep technical execution capability, not just advisory.
- Ability to operate independently in complex, regulated environments.
- Cross-functional collaboration across customer s DevOps, Infrastructure, IAM, Security, Network, and Application teams.
- Proactive identification and resolution of technical and operational challenges.
- Representing AWS as One Team - understanding AWS scope, stakeholder responsibilities, and driving outcomes collaboratively.
Skills Abilities:
Must-Have Technical Requirements:
AWS Cloud Services Implementation:
- Hands-on AWS service implementation with strong feature-level knowledge.
- AWS best practices implementation (Well-Architected Framework, all pillars).
- Multi-Account strategy - AWS Organizations, Control Tower, Landing Zones, SCPs.
- AWS Storage services - S3, EBS, EFS, FSx, Storage Gateway, Backup, lifecycle management.
- Security-by-design - embedded in every solution as a non-negotiable principle.
Infrastructure as Code Automation:
- Terraform (Open Source + Enterprise) - module development, state management, workspaces, multi-env deployments, secret/variable management.
- Automation-first mindset - scripting (Python, Bash), operational automation.
- CI/CD pipeline design and implementation (Jenkins, GitLab CI, Helm).
- Sound automation and solution-driven skills - build repeatable, scalable solutions.
Containers Kubernetes (EKS):
- EKS cluster provisioning, configuration, and lifecycle management using IaC (Terraform).
- EKS cluster upgrades - in-place and blue/green with zero-downtime strategies.
- Container troubleshooting - pod failures, resource limits, networking, image issues.
- Container security - image scanning, ECR policies, runtime security, Pod Security Standards.
- Karpenter - node provisioning, consolidation, workload-aware scaling.
- Regulatory frameworks awareness for containerized workloads - RBI IT guidelines, outsourcing norms, cloud adoption directives, data localization as applicable to EKS/container platforms.
Networking (Depth Required for NetBanking):
- VPC architecture - multi-AZ, subnets, Security Groups, NACLs, flow logs; integration with customer-managed Microsoft AD and on-prem DNS.
- Hybrid connectivity - Direct Connect, Site-to-Site VPN, Transit Gateway.
- DNS - integration with customer on-prem DNS servers, Route 53 resolver endpoints, conditional forwarding.
- Network segmentation, PrivateLink, VPC Endpoints, peering strategies.
Security Compliance (Security-by-Design):
- AWS Security services - IAM, KMS, Secrets Manager, ACM, WAF.
- Collaboration with customer IAM, Security, and Network teams.
- FSI compliance frameworks - RBI guidelines, PCI-DSS, SOC 2, ISO 27001.
- Data encryption (at rest + in transit) Data Residency.
- Sovereignty (RBI localization mandate).
- Threat detection continuous compliance monitoring.
- Secrets key management - KMS key policies, Secrets Manager rotation, certificate lifecycle (ACM).
Database, Caching Data Pipelines:
- AWS databases - RDS (MySQL, PostgreSQL), Aurora, DynamoDB.
- Caching solutions - ElastiCache (Redis, Valkey).
- Data pipelines - MSK (Kafka), SQS, SNS, EventBridge.
- Application integration - AWS native services + open-source tooling (Kafka, Redis).
Migration:
- Migration strategy execution (6R framework) - particularly Rehost, Replatform, Refactor.
- Migration tooling - DataSync, Transfer Family, SnapMirror for NetApp FSx.
- Wave planning, dependency mapping, cutover coordination, rollback strategies.
- Cloud readiness evaluation.
Disaster Recovery (FSI-Grade - Mandatory):
- DR strategy design for FSI - Pilot Light, Warm Standby, Multi-Site Active-Active.
- RPO/RTO definition aligned with banking regulatory requirements.
- Cross-region DR - Global Datastore, Aurora Global DB, S3 CRR, DynamoDB Global Tables.
- DR drill planning, execution, documentation, and continuous improvement.
- Business Continuity Planning (BCP) alignment with compliance mandates.
Observability, Monitoring Incident Management:
- Monitoring alerting - CloudWatch, Prometheus, Grafana, ELK/OpenSearch.
- Centralized logging audit trail architecture (immutable logs for FSI audit).
- Incident management, root cause analysis (RCA), and corrective action implementation.
- Performance engineering - load testing, capacity planning, bottleneck analysis.
High Availability Resilience:
- Multi-AZ architecture, auto-scaling, fault isolation.
- Backup data lifecycle management - retention/archival policies (regulatory compliance).
- Resilience testing approaches (game days,
chaos engineering awareness).
Requirements:
Must-Have Behavioral Leadership Requirements:
- Supports customer DevOps Infra teams - Embeds with teams, participates in sprint ceremonies, provides hands-on guidance, unblocks issues.
- Collaborates with IAM, Security, Network teams - Drives security architecture discussions, negotiates solutions that meet compliance without blocking delivery.
- Proactive pain-point identification - Doesn t wait for escalation - identifies technical debt, operational gaps, and proposes fixes independently.
- Strong troubleshooting skills - Systematic approach - isolates layer-by-layer, documents findings, prevents recurrence.
- Patience Ownership - Navigates complex bank processes, CAB approvals, and lengthy decision cycles without disengagement; treats customer problems as their own.
- Understands AWS scope stakeholder responsibilities - Clearly delineates shared responsibility, escalates appropriately, sets realistic expectations.
- Works as One AWS - Collaborates across AWS teams (SA, TAM, CSM, Service Teams, Support); leverages internal resources effectively.
- Leadership solution-driven attitude - Drives toward outcomes, influences without authority, guides customer tech leadership, mentors juniors.
- Stakeholder escalation management - Communicates effectively with CXO-level stakeholders, manages escalations with calm and structure.
- Change release management discipline - Understands CAB processes, controlled deployments, rollback strategies, approval workflows in regulated environments.
- Documentation discipline - Produces HLDs, LLDs, runbooks, ADRs, SOPs as standard practice; audit-ready documentation.
- Mentoring knowledge sharing - Actively upskills customer teams, conducts knowledge transfer sessions, creates enablement material.
Certifications (Preferred):
Must-Have (any 1):
- AWS Certified Solutions Architect - Professional.
- AWS Certified Solutions Architect - Associate.
Strongly Preferred:
- Certified Kubernetes Administrator (CKA).
- HashiCorp Terraform Associate.
Good-to-Have:
- AWS Certified DevOps Engineer - Skilled.
- AWS Certified Security - Specialty.
- CKS (Certified Kubernetes Security Specialist).
Interview Process
- Assessment
- 2 Technical Rounds
Disclaimer : This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Senior Cloud Consultant (Mumbai)
🏢 SourceFuse Technologies
📍 Mumbai