Senior Azure Cloud Architect with AZ-305, AZ-104, and AZ-500 certifications
Listed on 2026-08-18
-
IT/Tech
Cloud Computing: Infrastructure & Operations, Systems Engineer, Azure
Senior Azure Cloud Architect
Project Identifier NEA
Project Name Cloud Infrastructure & Modernization
Client National Endowment for the Arts
Agency NEA
Location Hybrid (1 day per week on-site at NEA Washington DC)
Interview Type MS Teams
Contract Duration 2 years with Possible extension
Tentative Start Date Immediate
Deadline Immediate
Project OverviewThe National Endowment for the Arts (NEA), Office of Information & Technology Management, operates
and continues to modernize its enterprise environment on Microsoft Azure. The agency requires a Senior
Azure Cloud Architect to own the design, governance, security posture, and migration of workloads across
Azure compute, storage, networking, identity, data, and integration services.
This position specifically requires both deep hands-on Azure engineering and architecture-level design in
a single individual. The Architect will produce reference architectures, diagrams, and architecture decision
records that engineering teams can implement directly; define infrastructure as code standards for the
team; lead architecture review boards and design authority meetings; and drive enterprise-scale landing
zone design and governance aligned to the Microsoft Cloud Adoption Framework and the Azure Well-Architected Framework.
The Architect shall be adept at interpersonal communications, teamwork, goal setting, and business
process improvement, and shall be comfortable translating business requirements into technical designs
and presenting solution designs and tradeoffs to CIOs, CTOs, and senior leadership.
Duties/ResponsibilitiesWork effectively with federal and contractor personnel to execute the project tasks;
Collaborate with NEA and other federal staff and contractors to refine and elaborate requirements;
Design enterprise-scale Azure solutions across compute services including Virtual Machines, VM
Scale Sets, App Services, Azure Functions, Container Apps, AKS, and Azure Batch, selecting the right
option for a given workload;
Architect advanced Azure networking spanning Virtual Networks, NSGs, UDRs, Private Endpoints,
Load Balancer, Application Gateway, Azure Firewall, Front Door, Virtual WAN, Express Route, and
VPN Gateway, including hub and spoke topologies and enterprise DNS strategy;
Design identity architecture using Microsoft Entra , including Conditional Access, Privileged
Identity Management, B2B and B2C scenarios, federation with on-premises Active Directory,
managed identities, and RBAC;
Innosoft is an Equal Opportunity/Affirmative Action employer
Apply the Azure Well-Architected Framework across reliability, security, cost optimization,
operational excellence, and performance efficiency;
Implement Cloud Adoption Framework practices, including enterprise scale landing zone design and
governance blueprints;
Design multi region, highly available, and disaster resilient solutions with defined recovery time and
recovery point objectives;
Produce reference architectures, diagrams, and architecture decision records that an engineering
team can implement directly;
Lead workload assessments using Azure Migrate and map applications to the five Rs of rehost,
refactor, rearchitect, rebuild, and replace;
Perform wave planning for large scale datacenter exits, including dependency mapping and cutover
planning;
Define infrastructure as code standards and repository structure for the team, and review and
validate Bicep or Terraform code written by others;
Build and maintain CI/CD pipelines in Azure Dev Ops or Git Hub Actions, including artifact
management, secret scanning, and pipeline security hardening;
Implement release strategies including blue and green, canary, and ring based deployments;
Operate production AKS clusters, including upgrades, node pool management, and networking
through Azure CNI or Calico, with Helm chart authoring and Git Ops workflows using Flux or ArgoCD;
Implement security, compliance, and governance using Microsoft Defender for Cloud, Microsoft
Sentinel, and Key Vault with secret rotation, together with Azure Policy, Management Groups, and
Blueprints, applying Zero Trust principles across identity, network, and data layers;
Configure Azure Monitor, Log Analytics, and Application…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).