06 Sep
|
Arminus
|
Bengaluru
Key Responsibilities
1) Cloud & Platform Architecture
- Design and maintain enterprise cloud reference architectures for AWS and/or Azure (optionally GCP), aligned to banking compliance, client constraints, and regional requirements.
- Architect secure landing zones (multi-account/subscription strategies), network segmentation, identity boundaries, and governance guardrails.
- Define platform patterns for Kubernetes/container platforms (EKS/AKS), microservices, event-driven architectures, and multi-tenant SaaS deployments.
- Create standardized "golden paths" and reusable templates for product teams to onboard rapidly.
2) DevOps Architecture & CI/CD Standardization
- Architect end-to-end CI/CD with quality gates (build, test, security scans, artifact management, deployment, rollback).
- Drive adoption of GitOps for declarative deployments and environment parity.
- Define strategies for branching, environment promotion, release governance, and deployment patterns (blue/green, canary, progressive delivery).
- Integrate CI/CD with change management and audit requirements typical of BFSI.
3) Infrastructure as Code (IaC) & Automation
- Establish and enforce IaC standards using Terraform and/or native cloud IaC (CloudFormation, ARM/Bicep).
- Standardize configuration and automation across environments using Ansible and scripting (Python/Bash/PowerShell).
- Create reusable modules, libraries, and pipelines enabling consistent provisioning, policy enforcement, and compliance reporting.
4) DevSecOps & Compliance-by-Design (BFSI Ready)
- Embed security controls into the SDLC: SAST/DAST, dependency scanning, container scanning, secrets management, and policy-as-code.
- Architect solutions for IAM, encryption, key management, secure network patterns (WAF), and least-privilege access.
- Ensure audit readiness: immutable logs, evidence generation, segregation of duties, and traceable releases.
5) Observability, SRE & Operational Readiness
- Define and implement observability architecture using logs/metrics/traces and standard ing practices.
- Introduce SRE principles: SLIs/SLOs, error budgets, incident response, runbooks, and postmortems.
- Drive resilience engineering: DR strategy, HA patterns, backup/restore, chaos testing (where relevant), and performance tuning.
6) FinOps & Cloud Cost Architecture
- Design cost-aware architectures and introduce FinOps guardrails: tagging, showback/chargeback, budget controls,
and cost anomaly detection.
- Optimize cloud spend through autoscaling, right-sizing, storage lifecycle policies, and reserved capacity strategies.
7) Architecture Governance & Stakeholder Leadership
- Participate in architecture reviews; influence engineering standards and guardrails across product lines.
- Collaborate with global stakeholders (US/Europe) for solutioning, technical workshops, and architecture sign-offs.
- Mentor engineers/architects and contribute to practice assets (playbooks, patterns, accelerators).
Mandatory Skills & Qualifications
Experience & Leadership
- 15+ years in software/platform engineering with strong architecture experience across cloud, DevOps, and operations.
- Proven delivery of large-scale cloud transformations and DevOps modernization in product/platform environments.
- Ability to lead architecture discussions, document decisions (ADRs), and guide teams through implementation.
Cloud Architecture (AWS/Azure)
- Strong architectural depth in AWS and/or Azure:
- Networking: VPC/VNet design, routing, private connectivity, segmentation
- Identity: IAM, federation, RBAC, service principals
- Security: KMS/Key Vault, WAF, private endpoints, encryption patterns
- Governance: policies, guardrails, resource organization, landing zones
- Experience designing HA/DR, multi-region (or active-active) architectures for critical platforms.
Containers, Kubernetes & Microservices
- Expertise with Kubernetes and ecosystem tools:
- EKS/AKS, Helm/Kustomize, ingress controllers, autoscaling
- Container security and registry patterns
- Deep understanding of microservices design and distributed system patterns, including service-to-service security.
DevOps & CI/CD
- Strong experience designing CI/CD using tools such as:
- Azure DevOps / Jenkins / GitHub Actions / GitLab CI (one or more)
- Solid Git practices: branching strategies, trunk-based development concepts, PR governance.
- Experience with artifact and dependency management: Nexus/Artifactory, package repositories.
Infrastructure as Code & Automation
- Expertise in Terraform and one native cloud IaC:
- CloudFormation or ARM/Bicep
- Automation scripting: Python/Bash/PowerShell.
- Configuration management: Ansible (preferred) or equivalent.
DevSecOps & Supply Chain Security
- Hands-on understanding of security scanning and enforcement:
- SAST, DAST, dependency scanning, container scanning
- Secrets management: Vault/AWS Secrets Manager/Azure Key Vault
- Policy-as-code: OPA/Gatekeeper or cloud-native policies
- Strong familiarity with secure SDLC, audit trails, and evidence generation.
Observability & Reliability (SRE)
- Experience implementing observability stacks:
- Prometheus/Grafana, ELK/OpenSearch, Splunk, Datadog, New Relic, OpenTelemetry
- Strong knowledge of incident management, ing strategy, and operational playbooks.
Banking / FinTech Domain Exposure
- Experience in BFSI/FinTech environments with regulated delivery expectations:
- Security, compliance, auditability, resilience, data protection
- Solid communication skills for collaborating with globally distributed teams and clients.
Good-to-Have Skills
Advanced Architecture & Cloud-Native
- Multi-cloud and hybrid patterns: Direct Connect/ExpressRoute, on-prem integration, private connectivity.
- Serverless patterns: AWS Lambda / Azure Functions; managed services modernization.
- Service mesh exposure (Istio/Linkerd) and zero-trust service-to-service patterns.
- Event-driven platforms: Kafka, MSK/Event Hubs, streaming architectures.
Security & Compliance Framework Awareness
- Familiarity with security/compliance frameworks relevant for regulated environments:
- ISO 27001, SOC 2, PCI DSS, GDPR, NIST-aligned controls
- Software supply chain practices:
- SBOM, artifact signing (e.g., Cosign), provenance, SLSA-aligned thinking
SRE/Resilience Engineering
- Chaos engineering tools/practices and performance engineering.
- Strong DR testing automation and resilience validation approaches.
FinOps & Governance
- FinOps maturity: forecasting, budgeting, unit economics, chargeback models.
- Experience implementing cloud governance tooling and enterprise guardrails at scale.
Platform Engineering & Developer Experience
- Internal developer platforms (IDP) and portals (e.g., Backstage).
- Standardized golden paths, templates, and self-service catalog enablement.
📌 Cloud Infra Devops Architect (Bengaluru)
🏢 Arminus
📍 Bengaluru