# Cloud Infrastructure Architect, Okta Federal

**Company**: Okta Federal, Inc.
**Location**: Washington, DC
**Work arrangement**: hybrid
**Experience**: senior
**Job type**: full-time
**Salary**: $244,000-$336,000 USD
**Category**: Engineering
**Industry**: Technology

**Apply**: https://job-boards.greenhouse.io/okta/jobs/8004104?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_049e5151-670

## Description

Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era.

Technology, Data, and Insights (TDI) is on a mission to accelerate Okta's scale and growth. We bring world-class business acumen and technology expertise to every interaction. We also drive cross-functional collaboration and are focused on delivering measurable business outcomes.

The TDI Infrastructure Engineering team owns the foundational platforms that power Okta's business , from cloud infrastructure and AI platform delivery to network engineering, developer productivity, observability, and client platforms.

## The Cloud Platform Architect Opportunity

Okta Federal, Inc. is looking for a dedicated Cloud Platform Architect for TDI Infrastructure Engineering , the technical authority for how we design, build, and evolve the cloud infrastructure that underpins our AI platform and the broader workloads running across the business.

You will define the architectural standards, patterns, and strategies that the Cloud Platform Engineering team builds to, and you will serve as a key partner to AI, security, and productivity architects as we scale Okta's cloud capabilities to meet increasing business demand.

This is a hands-on builder role. We are not looking for someone who advises from a distance , we need someone who has shipped cloud infrastructure at scale and brings the credibility and depth to make sound architectural decisions in a fast-moving environment.

## What You'll Be Doing

- Define and own Okta's Cloud Platform architecture , establish reference architectures, design standards, and guardrails that bring consistency, security, and reliability to workloads running across the business

- Lead the architecture for Kubernetes and EKS , design and evolve our cluster strategy, multi-tenancy model, networking topology, and security posture as the platform scales to support AI agent workloads and diverse business unit deployments

- Elevate Okta's AI platform , partner with AI architects and platform engineers to evolve our agent and model-serving infrastructure from its current state to a production-grade, scalable platform capable of supporting broad business adoption

- Drive multi-cloud strategy , build the evaluation framework and decision criteria for when and how Okta leverages AWS, Azure, and Google Cloud; ensure workload placement is intentional and optimized for performance, cost, and capability

- Serve as the technical anchor for the Cloud Platform Engineering team , raise the architectural quality of everything the team designs and builds as we complete the transformation from account vending to a managed platform model

- Partner cross-functionally with AI, security, and productivity architects, product managers, and business unit stakeholders to ensure cloud infrastructure decisions align with Okta's product, compliance, and operational requirements , including support for federal programs and FedRAMP environments

- Partner cross-functionally to design cloud-native solutions that can be effectively adapted for air-gapped, self-hosted environments like US Secret (SIPRNet) and US Top Secret (JWICS).

- Help architect and validate foundational Kubernetes and infrastructure designs within unclassified AWS GovCloud sandboxes.

## What You'll Bring to the Role

- 10+ years of hands-on cloud infrastructure experience with deep, demonstrated expertise in one or more major cloud providers (AWS, GCP, or Azure) , including compute, networking, storage, IAM, and managed services at enterprise scale; AWS experience is preferred given our current environment, but strong multi-cloud or GCP backgrounds are equally valued

- Proven experience designing and operating Kubernetes and EKS at scale , cluster architecture, multi-tenancy patterns, networking (CNI, service mesh), security hardening, and day-2 operations

- Experience architecting infrastructure for AI and machine learning workloads , GPU compute, model serving, data pipeline infrastructure, and the security and access patterns that go with them

- Demonstrated experience making intentional cloud provider placement decisions , evaluating workloads against provider capabilities, cost profiles, compliance requirements, and existing organizational footprint rather than defaulting to a single cloud

- Strong cloud security background , IAM design, network segmentation, secrets management, policy-as-code, and experience with compliance frameworks (SOC 2, FedRAMP, or equivalent)

- Solid understanding of enterprise identity and access management patterns , including federated identity, SSO, and SCIM , and experience integrating cloud workloads and platform services with identity providers such as Okta

- Infrastructure-as-code fluency , Terraform, AWS CDK, or equivalent; experience building and maintaining reusable, modular IaC at enterprise scale

- Demonstrated ability to influence without authority , experience driving architectural alignment across engineering, security, product, and business stakeholders in a fast-moving organization

- Security Clearance: Active U.S. TS/SCI with polygraph.

## Extra Credit If You Have Experience In Any of the Following

- Experience designing or operating cloud infrastructure for FedRAMP authorized environments or federal programs

- Designing infrastructure for completely air-gapped networks, Sovereign Clouds, or DoD Impact Level 6/7 environments.

- Hands-on experience building or operating AI agent platforms , orchestration frameworks, vector databases, model routing, or inference optimization

- FinOps experience , cloud cost governance, chargeback models, commitment-based discount strategies, and rightsizing at scale

- Platform engineering for internal developer platforms (IDP) , developer self-service, golden paths, and guardrails

- Service mesh technologies such as Istio or Linkerd in production Kubernetes environments

- Kubernetes certifications (CKA, CKS, CKAD) or AWS certifications (Solutions Architect Professional, Security Specialty)

- Familiarity with cloud-native security operations platforms such as Google SecOps (Chronicle) , including log ingestion architecture, data residency considerations, and GCP IAM integration patterns

- Familiarity with DoD/IC DevSecOps reference architectures and networking, specifically traversing boundaries via cross-domain solution (CDS) and deploying DevOps tools like "Big Bang" via Iron Bank hardened containers.

## Location

This is a US-based role. Candidates must be located in the United States. Okta operates a flexible hybrid work model; specific in-office expectations will be discussed during the hiring process.

## Benefits

Okta offers equity (where applicable), bonus, and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies.

## Skills

### Required
- cloud infrastructure
- Kubernetes
- EKS
- AI
- machine learning
- cloud security
- IAM
- Terraform
- AWS
- GCP
- Azure

### Nice to have
- FedRAMP
- DoD Impact Level 6/7
- air-gapped networks
- Sovereign Clouds
- AI agent platforms
- FinOps
- platform engineering
- service mesh technologies
- Kubernetes certifications
- AWS certifications

---

Source: [Apply at job-boards.greenhouse.io](https://job-boards.greenhouse.io/okta/jobs/8004104?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
