{"id":1330379,"url":"https://alion.io/job/mhk-cloud-architect","title":"Cloud Architect","company":{"id":3783710,"name":"MHK","domain":"mhk.com","url":"https://alion.io/company/mhk-3","size_band":"501-1000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Oracle","truth_index":null},"role":"DevOps","role_family":"DevOps","seniority":"staff","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Tampa, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":118000,"max_usd":235000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":394},"experience_years_min":7,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Amazon Aurora","optional":false},{"name":"Amazon CloudWatch","optional":false},{"name":"Amazon EC2","optional":false},{"name":"Amazon ECS","optional":false},{"name":"API Gateway","optional":false},{"name":"AWS","optional":false},{"name":"AWS Fargate","optional":false},{"name":"AWS Lambda","optional":false},{"name":"Bash","optional":false},{"name":"CI/CD","optional":false},{"name":"Datadog","optional":false},{"name":"DynamoDB","optional":false},{"name":"GitHub Actions","optional":false},{"name":"HIPAA","optional":false},{"name":"IAM","optional":false},{"name":"Least Privilege","optional":false},{"name":"Linux","optional":false},{"name":"MySQL","optional":false},{"name":"Platform Engineering","optional":false},{"name":"Python","optional":false},{"name":"SOC 2","optional":false},{"name":"Terraform","optional":false},{"name":"VPN","optional":false},{"name":"CIS Benchmarks","optional":true}],"status":"live","first_seen_at":"2026-09-15T16:17:23Z","employer_posted_date":"2026-09-15","last_verified_at":"2026-09-28T16:13:57Z","board_verified":false,"closed_at":null,"days_open":15,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":15},"description":"The Cloud Architect is a hands-on technical role within the Cloud Platform Engineering organization. You will define and evolve the architecture of a secure, highly available, multi-account AWS platform supporting regulated SaaS applications. This role leads cloud platform modernization and transformation initiatives, owning architecture standards, reference designs, resilience patterns, and technical direction across platform and application engineering teams. You will assess existing systems, define pragmatic migration and modernization paths, turn business and product needs into target-state AWS architectures, and guide implementation so the platform becomes more scalable, secure, reliable, operable, cost-aware, and compliant.\nArchitecture ownership is central to this role: you will set platform standards and make architecture recommendations within the cloud domain, while implementation is delivered in partnership with platform engineering, security, operations, data, and application teams.\nPosition Responsibilities:\nCloud Architecture and Technical Strategy\nDefine target-state AWS architectures, reference architectures, and decision records for secure, scalable, cloud-native SaaS platforms.\n\nLead architecture reviews and translate product, engineering, and enterprise technology roadmaps into implementable cloud designs.\n\nDesign modernization strategies spanning serverless services, Amazon ECS and AWS Fargate, EC2 Linux workloads, APIs, and event-driven components.\n\nEstablish architectural standards for availability, scalability, performance, capacity, service boundaries, tenant isolation, and operational readiness.\n\nGuide to multi-region resilience and disaster-recovery architecture, including backup ownership, RTO and RPO targets, failover approaches, and restore testing.\n\nSecurity, Compliance, and Risk Architecture\nDesign cloud controls that support HIPAA regulatory requirements, SOC 2 attestation commitments, and HITRUST certification requirements.\n\nPartner with security and compliance teams to implement controls, maintain control-to-code mappings, produce audit evidence, support control walkthroughs, and remediate penetration-test findings.\n\nDefine patterns for IAM, permission boundaries, AWS Organizations service control policies, KMS encryption, Secrets Manager, Parameter Store, and least-privilege access.\n\nEstablish cloud security posture and vulnerability-management patterns using services such as AWS Config, Security Hub, Inspector, GuardDuty, CloudTrail, and centralized audit-log retention, as applicable to the environment.\n\nEnsure architecture decisions address data protection, secure tenant isolation, key management, secrets handling, and customer security requirements.\n\nNetworking, Data, and Platform Governance\nDefine enterprise AWS networking patterns using Transit Gateway, Site-to-Site VPN, Direct Connect, PrivateLink, routing controls, and private service access.\n\nSet architectural direction for Amazon RDS for MySQL and Aurora, DynamoDB, ElastiCache, data durability, backup, recovery, replication, and performance tradeoffs.\n\nOwn cloud landing-zone standards and multi-account governance across AWS Organizations and Control Tower, including account vending, guardrails, centralized logging, and policy enforcement.\n\nCreate reusable Terraform module standards covering versioning, remote state, code review, drift detection, testing, and safe change management.\n\nModernization, Transformation, and Platform Enablement\nAssess current-state application and infrastructure environments, identify modernization opportunities, and create phased transformation roadmaps with clear business and technical outcomes.\n\nDevelop migration and modernization patterns for rehosting, replatforming, refactoring, containerization, serverless adoption, and retirement of legacy services.\n\nEstablish platform golden paths and self-service provisioning patterns that help engineering teams adopt approved AWS architectures consistently and securely.\n\nDefine observability architecture across CloudWatch and Datadog, including service-level objectives, telemetry standards, alert quality, dashboards, and operational ownership.\n\nImprove operational readiness by defining patching, maintenance-window, change-management, exception, and customer-notification patterns for hosted environments.\n\nLead or facilitate complex incident reviews and ensure that corrective actions result in durable architectural improvements.\n\nHelp evaluate and pilot AI-assisted SRE or DevOps capabilities where they can safely improve incident triage, diagnosis, or remediation.\n\nIncorporate cost, performance, reliability, and security tradeoffs into architecture decisions and contribute to rightsizing, savings-plan, reservation, and tag-based cost-attribution initiatives.\n\nCommunicate architecture decisions clearly to technical and non-technical stakeholders and build alignment across teams.\n\nImplementation Partnership\nGuide platform and application teams as they implement approved architectures, resolve design issues, and transition modernized services into production.\n\nUse Terraform, Python, Bash, and lightweight delivery automation as needed to prove patterns, accelerate adoption, and remove implementation barriers; this is not primarily a CI/CD administration role.\n\nProvide architectural input to GitHub Actions or other delivery pipelines where deployment safety, testing, security validation, and traceability are required.\n\nPosition Requirements:\n7+ years of experience in AWS cloud architecture, cloud engineering, platform engineering, or a related discipline, including substantial production AWS experience.\n\nDemonstrated ability to define and communicate AWS architectures for highly available, secure, scalable applications or SaaS platforms.\n\nDemonstrated experience leading cloud modernization or transformation programs from current-state assessment through migration, implementation, and operational adoption.\n\nProduction experience with Terraform and Infrastructure as Code, including reusable modules, state management, versioning, testing, and drift control.\n\nStrong understanding of AWS networking, identity and access management, encryption, logging, monitoring, and multi-account architecture.\n\nHands-on familiarity with AWS compute and application patterns, including ECS, Fargate, EC2 Linux, Lambda, and API Gateway.\n\nExperience designing or operating cloud environments subject to regulated or audited security requirements.\n\nAbility to influence engineering teams, lead architecture discussions, and make sound tradeoffs among security, reliability, performance, delivery speed, and cost.\n\nEducation/Certification Requirement:\nBachelor’s degree in Computer Science, Engineering, Information Systems, or a related field, or equivalent practical experience.\n\nAWS Certified Solutions Architect Associate, AWS Certified Solutions Architect Professional, or AWS Certified DevOps Engineer Professional; equivalent experience will be considered.\n\nPreferred Qualifications\nExperience with healthcare software, medical technology, regulated technology, or multi-tenant SaaS platforms.\n\nExperience with compliance-as-code tools or practices such as AWS Config rules, OPA or Conftest, CIS benchmark hardening, or equivalent mechanisms.\n\nAdditional Requirements:\nMust reside in or be willing to relocate to the Tampa, FL area within 90 days of start for hybrid collaboration.\n\nAt MHK we help health plans and pharmacy benefit managers deliver optimal care management across every member’s health journey. We do this through state-of-the-art technology that provides critical insights from member enrollment and maintenance through every stage of care and compliance. We believe that long-term partnerships are built on trust. Our team members are expected to build trusted advisory relationships - with MHK clients and one another - through responsive, transparent communication, while honoring commitments, and tying that trust to outcomes.\nBenefits Snapshot:\nMedical, vision, and dental plans for full time employees\n\n401(k) offered with a generous match\n\nBenefits begin on first day of the month following employment\n\nExercise/Health Club reimbursement opportunity\n\nMonthly dependent care reimbursement opportunity\n\nShort Term and Long-Term disability\n\nBasic Term Life and AD&D Insurance\n\nGenerous Paid Time Off and Holiday Schedule\n\nEQUAL OPPORTUNITY EMPLOYER - VETERANS/DISABLED.","description_format":"text","description_chars":8446,"description_truncated":false,"requirements":{"experience_years_min":7,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":true},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":true,"industries":["Health Care","Pharmacies","Health Insurance & Benefits"],"lifecycle":[{"event":"open","at":"2026-09-27T09:28:15Z"}],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":14,"expected_fill_days":55,"reasons":["conf:37","win:early"],"computed_at":"2026-09-30T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/mhk-cloud-architect","json_url":"https://alion.io/job/mhk-cloud-architect.json","meta":{"generated_at":"2026-10-01T04:04:28Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3313,"day_limit":5000,"remaining_today":1687,"minute_limit":60,"resets_at":"2026-10-02T00:00:00Z"}}}