Sovereign Cloud Architect

Il y a 3 semaines

Kirchberg, LU MEERAB GROUP Temps plein

- Capture and analyse functional and non-functional requirements, including accounts, network topology, identity, logging, cost, data residency and security.
- Translate sovereignty and compliance requirements into concrete test cases.
- Define compliance and security requirements aligned with Sovereign Cloud features.
- Start the configuration of the Landing Zone / EP tenant based on priorities given by the European Parliament.
- Configure network components, including VPCs, subnets, routing and firewall/security groups.
- Configure IAM, role-based access control, multi-factor authentication and least-privilege policies.
- Configure centralized logging and alerting integrated with EP native services such as Splunk and Pulse.
- Configure encryption at rest and in transit, vulnerability scanning and required security/compliance controls.
- Review and adjust business continuity, disaster recovery, backup and high-availability configurations.
- Adjust Infrastructure-as-Code modules where required, using Terraform, ARM and/or Bicep.
- Store customised IaC in EP repositories together with version-control metadata.
- Connect CI/CD tooling to source-code management and artifact repositories.
- Configure pipeline stages that automatically deploy test workloads into the Landing Zone.
- Support the identification of workloads suitable for migration.
- Onboard pilot workloads using containerization, cloud-provider migration tools or manual transfer.
- Conduct functionality, security and performance testing.
- Validate compliance through audit trails and data residency.
- Test observability and exit strategies.
- Validate disaster recovery and backup.
- Collect actual consumption data from migrated workloads.
- Document test cases with pass/fail results and supporting evidence.
- Produce gap analysis identifying which sovereignty controls work, which are missing and which require customisation.
- Consolidate the outcomes of the PoC and document challenges, platform limitations, workarounds and risks.
- Assess the cost model for running workloads in a sovereign cloud environment at scale.
- Produce PoC findings, documentation, run-books, operational playbooks, lessons learned and recommendations. Requirements
- Proven experience with cloud implementations.
- Experience with open-source technologies.
- Experience with containerization technologies.
- Experience integrating with DevSecOps platforms, particularly CI/CD pipelines in cloud and on-premises environments.
- Experience with Infrastructure-as-Code, including Terraform, ARM and/or Bicep.
- Experience with cloud networking, IAM, security, logging and monitoring.
- Experience with backup, disaster recovery and high availability.
- Experience with workload migration, onboarding and testing.
- Ability to translate business strategy into technical architecture.
- Ability to make pragmatic trade-offs between cost, risk, performance and speed.
- Experience leading architecture workshops and engaging stakeholders at all levels.
- Experience defining cloud governance and operating models.
- Ability to produce clear, decision-oriented documentation and presentations.
- Understanding of project delivery approaches, risk management, change management, planning and coordinating successful project execution.
- Experience with cloud providers such as OVH, Scaleway or STACKIT is a strong asset.