{"id":1296679,"url":"https://alion.io/job/xtium-cloud-architect","title":"Cloud Architect","company":{"id":2771594,"name":"XTIUM","domain":"xtium.com","url":"https://alion.io/company/xtium","size_band":"501-1000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":{"grade":"B","score":75,"open_postings":5,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-10-01T05:45:00Z"}},"role":"DevOps","role_family":"DevOps","seniority":"staff","employment_type":"full_time","work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"board_field","remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Islamabad, Pakistan"],"countries":["PK"],"hiring_countries":["PK"],"hiring_countries_total":1,"salary":null,"salary_estimate":{"min_usd":41000,"max_usd":96000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":603},"experience_years_min":8,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"ArgoCD","optional":false},{"name":"Azure","optional":false},{"name":"Azure AKS","optional":false},{"name":"Azure DevOps","optional":false},{"name":"Bicep","optional":false},{"name":"Chaos Engineering","optional":false},{"name":"CI/CD","optional":false},{"name":"Cilium","optional":false},{"name":"Configuration Management","optional":false},{"name":"DNS","optional":false},{"name":"FluxCD","optional":false},{"name":"GitHub","optional":false},{"name":"GitHub Actions","optional":false},{"name":"GitOps","optional":false},{"name":"Grafana","optional":false},{"name":"Helm","optional":false},{"name":"Kubernetes","optional":false},{"name":"Microsoft Defender for Cloud","optional":false},{"name":"Microsoft Entra ID","optional":false},{"name":"Nginx","optional":false},{"name":"OpenTelemetry","optional":false},{"name":"OpenTofu","optional":false},{"name":"Platform Engineering","optional":false},{"name":"Prometheus","optional":false},{"name":"Terraform","optional":false},{"name":"Velero","optional":false},{"name":"VPN","optional":false},{"name":"Zero Trust","optional":true}],"status":"live","first_seen_at":"2026-06-23T00:00:00Z","employer_posted_date":"2026-06-23","last_verified_at":"2026-10-01T10:03:13Z","board_verified":true,"closed_at":null,"days_open":100,"trust":{"level":"stale","repost_count":0,"flags":["stale"],"days_open":100},"description":"The XTIUM global team is made up of a group of diverse and talented professionals who are all driven by the same goal: excellence and continuous improvement. We are all about embracing challenges, keeping the lines of communication open and working together. We take ownership of our work, focus on learning and growing and hold ourselves accountable to our colleagues and customers. Together, we strive to push boundaries, make an impact and inspire each other to reach our full potential.\nJob Description:\nKey Responsibilities\nAzure Landing Zone & Governance\nDesign and evolve Azure landing zones aligned with the Microsoft Cloud Adoption Framework and Azure Well-Architected Framework.\nOwn subscription, management group, resource group, naming, tagging, RBAC, and governance standards.\nEstablish Azure Policy, Defender for Cloud, Sentinel, Log Analytics, and diagnostic standards.\nReview current cloud architecture and produce prioritized remediation plans\nDesign highly available, secure, multi-region, and zone-redundant architectures for AI platform.\nArchitect and deploy scalable Azure PaaS-including managed kubernetes and databases to meet enterprise performance, data integration and security requirements\nDesign and manage enterprise Azure API Management (APIM) instances to securely expose, govern, and scale microservices and PaaS endpoints.\n\nAzure Kubernetes Service (AKS)\nDesign and operate production-grade AKS clusters, including node pool strategies, autoscaling, and node image upgrade pipelines.\nConfigure AKS networking: Azure CNI or Overlay/Cilium, private cluster endpoints, egress controls via Azure Firewall, and ingress via AGIC or NGINX with WAF.\nImplement AKS security hardening: Entra workload identity federation, Azure RBAC for Kubernetes, admission controllers (Azure Policy / Gatekeeper), and Key Vault secrets injection via CSI driver.\nEstablish GitOps-based cluster configuration management using Flux CD or Argo CD; define cluster upgrade and patching cadence.\nSet up AKS observability: Container Insights, Prometheus/Grafana, and distributed tracing via Application Insights or OpenTelemetry.\nDefine AKS backup and disaster recovery using Velero, and integrate AKS cost governance into overall cloud cost management practices.\nNetworking & Connectivity\nDesign secure Azure networking: hub-spoke topology, private endpoints, private DNS zones, ingress, and egress controls.\nDefine peering, ExpressRoute, and VPN patterns for hybrid and multi-region connectivity.\nGovern DNS resolution for AKS private clusters, including CoreDNS customization and Azure Private DNS integration.\nImplement robust Azure load balancing solutions using Traffic Manager, Application Gateway, and Azure Load Balancer to optimize traffic distribution, performance, and high availability.\nIdentity, Security & Compliance\nPartner with security and engineering teams to strengthen identity, access, secrets management, monitoring, and compliance controls.\nDesign Entra ID integration, RBAC, managed identities, service principals, workload identity federation, and privileged access patterns.\nCo-implement high-priority security, reliability, and governance improvements.\nInfrastructure as Code & CI/CD\nDevelop and maintain Terraform / OpenTofu IaC modules for AKS clusters, node pools, networking, RBAC, and add-on configuration.\nEstablish GitOps workflows for Kubernetes manifests and Helm chart promotion across environments.\nIntegrate cluster provisioning and application deployment into GitHub Actions or Azure DevOps pipelines.\nReliability, DR & Operations\nDefine backup, disaster recovery, RTO/RPO, and restore validation practices for AKS and supporting infrastructure.\nEstablish and validate enterprise-grade backup, disaster recovery, and data retention policies to guarantee business continuity and strict RPO/RTO compliance.\nImplement chaos engineering and failure injection practices to validate cluster resilience.\nBuild documentation, architecture diagrams, runbooks, and operational standards.\nMentor DevOps, platform, and engineering teams on Azure and AKS best practices.\nInitial Focus (Phase 1)\nIn the first engagement phase, this person will:\nReview the current Azure environment, AKS footprint, and deployment approach.\nIdentify security, reliability, governance, and operational gaps - including AKS cluster configuration, node security, and workload identity posture.\nDesign a target-state Azure landing zone with AKS as a first-class platform component.\nEstablish IaC standards for AKS cluster lifecycle, node pool management, and add-on configuration.\nImplement or guide deployment of foundational AKS and Azure networking infrastructure.\nCreate documentation and knowledge-transfer materials for internal teams.\nRequired Qualifications\n8+ years of experience in cloud infrastructure, platform engineering, DevOps, or security architecture.\n5+ years of hands-on Microsoft Azure experience.\n3+ years of production AKS experience - cluster networking, security, GitOps, and workload operations.\nStrong experience designing Azure landing zones or enterprise Azure environments.\nHands-on experience with Terraform, OpenTofu, Bicep, or similar IaC tooling.\nStrong knowledge of Azure networking, private connectivity, DNS, routing, and ingress patterns.\nExperience with Entra workload identity, managed identities, Azure RBAC for Kubernetes, and admission control.\nExperience with Azure Policy, Defender for Cloud (including Defender for Containers), Sentinel, and Log Analytics.\nExperience designing backup, restore, resiliency, and disaster recovery practices.\nAbility to create clear technical documentation, diagrams, standards, and runbooks.\nStrong communication skills across engineering, security, and leadership teams.\nPreferred Qualifications\nAzure Solutions Architect Expert certification.\nAzure Security Engineer or Cybersecurity Architect certification.\nCertified Kubernetes Administrator (CKA) or equivalent hands-on AKS experience.\nTerraform Associate or equivalent IaC experience.\nExperience with GitHub Enterprise, GitHub Actions, or Azure DevOps for CI/CD pipelines.\nExperience in regulated, SaaS, multi-tenant, or enterprise production environments.\nFamiliarity with CIS Azure Benchmarks, CIS Kubernetes Benchmark, Microsoft Cloud Security Benchmark, and Zero Trust principles.\nExperience mentoring platform or DevOps engineers on Azure and Kubernetes best practices.\nRemote","description_format":"text","description_chars":6421,"description_truncated":false,"requirements":{"experience_years_min":8,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"phd","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"Pakistan","iso":"PK","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Artificial Intelligence","Cybersecurity","Information Technology"],"lifecycle":[{"event":"open","at":"2026-09-26T09:32:10Z"}],"liveness":{"score":9,"band":"cold","label":"Long shot","p_open":1,"p_active":0.338,"p_room":0.28,"age_days":100,"expected_fill_days":24,"reasons":["conf:27","velocity","win:tail","crowd:"],"computed_at":"2026-10-01T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/xtium-cloud-architect","json_url":"https://alion.io/job/xtium-cloud-architect.json","meta":{"generated_at":"2026-10-01T10:47:44Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2025,"day_limit":5000,"remaining_today":2975,"minute_limit":60,"resets_at":"2026-10-02T00:00:00Z"}}}