OCI Architect
Prefers WFO in MKE, but open to remote
• Design and architect OCI Landing Zone aligned to enterprise, security, and governance requirements
• Define tenancy wide architecture including compartment hierarchy for PROD, NON PROD, and shared services
• Design prescriptive landing zone frameworks with security by design and governance first principles
• Architect hub and spoke network topology using OCI VCNs, subnets, DRG, and centralized ingress/egress
• Define and implement OCI Identity and Access Management (IAM) strategy with least privilege access
• Design OCI native security architecture using Cloud Guard, Security Zones, Vault, and IAM policies
• Establish centralized logging and monitoring using OCI Audit Logs, Service Logs, Logging Analytics, and Monitoring
• Define network security architecture using NSGs, Security Lists, OCI Network Firewall, and Bastion service
• Architect encryption strategy leveraging OCI Vault, customer managed keys, and encryption by default services
• Design governance guardrails including tagging strategy, budget controls, and policy enforcement
• Define multi environment and multi tenancy landing zone patterns where applicable
• Ensure landing zone alignment with CIS OCI Foundations Benchmark and OCI security best practices
• Provide architectural guidance for workload onboarding, migration, and expansion on the landing zone
• Define Infrastructure as Code (IaC) approach for landing zone provisioning using Terraform and OCI Resource Manager
• Collaborate with security, network, platform, and application teams to ensure consistent adoption of the landing zone
• Produce architecture diagrams, design documents, and reference patterns for enterprise consumption